Search by

mdrbx / nova-mcp

mdrbx

Expose Laravel Nova resources to MCP clients through Nova's existing permissions and OAuth.

Package info

github.com/mdrbx/nova-mcp

pkg:composer/mdrbx/nova-mcp

Statistics

Installs: 3

Dependents: 0

Suggesters: 0

Stars: 0

Open Issues: 1

v0.2.0 2026-09-29 13:18 UTC

This package is auto-updated.

Last update: 2026-09-29 16:37:55 UTC


README

Nova MCP β€” Your Nova resources, ready for AI

Latest version Tests License: MIT

Nova MCP

Give your AI client access to the Laravel Nova resources you already use. ✨

Nova MCP exposes your resources through Laravel MCP, using Nova's existing policies, field visibility, validation and operations. Users connect with their Nova account over OAuth and manage access from MCP connections in Nova.

  • πŸ”Œ Start with your existing resources. Browse, search, edit, manage relationships and run synchronous actions through MCP tools.
  • πŸ” Keep Nova in charge. Every operation respects the user's Nova permissions and the client's approved OAuth scopes.
  • πŸͺΆ Keep setup light. Blade pages, no frontend build, worker or scheduler required.

πŸš€ Quick start

Start in an application with PHP 8.3+, Laravel 12.41.1+ or 13.x, and Nova 5.11+. You'll need a valid Nova license. Composer installs Laravel MCP and Passport as dependencies. See full requirements.

1. Install

composer require mdrbx/nova-mcp
php artisan nova-mcp:install

Review the published migrations, then run:

php artisan migrate

Using UUID or ULID user IDs? Adapt Passport's published user_id columns before migrating. Existing Passport installations should keep their compatible schema. The installation guide covers the details.

2. Add the Nova Tool

Add new NovaMcp to your existing NovaServiceProvider::tools() return array:

use Mdrbx\NovaMcp\NovaMcp;

public function tools(): array
{
    return [
        // Keep your other tools here.
        new NovaMcp,
    ];
}

Using a custom Nova::mainMenu? Add the tool's menu entry.

3. Connect your client

Set APP_URL to your public application URL. Open MCP connections in Nova, copy the server URL, then add it to your MCP client with OAuth authentication. Sign in, approve the permissions, and try: β€œWhich resources can I access?”

Cloud clients need a publicly reachable HTTPS endpoint. The connection guide explains scopes, consent and revocation.

Manage MCP connections from Nova

πŸŽ›οΈ Make it yours

Writes require both Nova's permission and an approved nova:write scope. To make the whole MCP read-only, set this in .env:

NOVA_MCP_READ_ONLY=true

You can also set the instructions sent to MCP clients:

NOVA_MCP_GUARDRAILS="Ask for confirmation before destructive changes. Never export personal data."

Read-only mode blocks writes even for existing tokens. Guardrails guide the AI client; they are not permission checks. Rebuild the configuration cache after changes if your deployment uses it. See all configuration options β†’

πŸ“š Go a little further

Guide What's inside
Installation Requirements, Passport keys and migrations, custom Nova menus.
Configuration Resource selection, read-only mode, guardrails, URLs and token lifetimes.
Connecting clients OAuth, consent, permissions, revocation and troubleshooting.
Operations Available tools, forms, relationships, actions and compatibility limits.
Architecture How the adapter reuses Nova and isolates OAuth from your application.

πŸ’› Help make it better

Found a bug or have a concrete use case to share? Open an issue, or have a look at the contributing guide to get started locally.

See the changelog for releases and security policy for reporting vulnerabilities privately.

Made by Matthieu Deroubaix. Released under the MIT license. Laravel Nova requires its own commercial license; Nova MCP is an independent community package.