cd /news/ai-agents/total-cms-flat-file-php-cms-with-a-b… · home › topics › ai-agents › article
[ARTICLE · art-146816] src=totalcms.co ↗ pub= topic=ai-agents verified=true sentiment=↑ positive

Total CMS – Flat-File PHP CMS with a Built-In MCP Server

Total CMS, a flat-file PHP content management system first shipped in 2015 and now licensed on more than 4,500 sites, ships a built-in MCP server in its Standard and Pro tiers rather than as a separately installed plugin. The MCP server resolves every caller to one of three personas — anonymous public read, API-key admin, or per-user OAuth 2.1 with scopes — and applies the same access groups to agents as to human users, with collections defaulting to admin-only over MCP and fields hideable from agents entirely. Agent writes go through the same schema-driven save path as the admin form, and the server serves version-matched documentation from the install itself rather than the agent's training data.

read6 min views2 publishedOct 7, 2026
Total CMS – Flat-File PHP CMS with a Built-In MCP Server
Image: source

⏺ totalcms · built-in MCP server

⎿ your schemas, your content, this install’s docs

MCP is the standard plug that lets AI agents use real tools. Total CMS ships one, and your client edits only what you allow — by hand in the admin, or through their own agent.

The hand-off

Two agents, one set of guardrails. #

The hand-off the demo video records, step by step. You build with your agent, your client works with theirs, and neither gets further than you allowed.

Illustrative session · real tool names and error text · scroll to play it · tap a step

Add testimonials the client can manage herself

⏺ totalcms · create_schema

id: "testimonial"

properties: author · quote · photo · company

⎿ schema testimonial saved

⏺ totalcms · create_collection

id: "testimonials", schema: "testimonial"

mcp: { access: "authenticated" }

⎿ collection testimonials saved

Add the quote from Maria’s email to the site

⏺ totalcms · create_object

collection: "testimonials"

{
  "id": "maria-lopez",
  "author": "Maria Lopez",
  "quote": "<p>I can finally update the site myself.</p>",
  "company": "Lopez Bakery"
}

Added. The photo field takes an upload, so that one’s yours to add in the admin.

While you’re in there, swap the homepage hero for a video

⏺ totalcms · patch_object

collection: "builder-pages", id: "home"

Error: Your account’s groups do not grant update on ‘builder-pages’.

I can’t change the homepage. Your Editor access covers content like testimonials, not site pages — that one’s for your designer.

$ ls tcms-data/testimonials/

maria-lopez.json

$ cat tcms-data/testimonials/maria-lopez.json

{

"id": "maria-lopez",

"author": "Maria Lopez",

"quote": "<p>I can finally update the site myself.</p>",

"company": "Lopez Bakery"

}

One file on your server. Copy it, back it up, open it in any editor.

An illustrative session: the tool names, arguments and error message are the real ones from Total CMS. Maria and the bakery are made up.

  • 4,500+
  • licensed sites
  • 2015
  • first shipped
  • MCP built in
  • in Standard and Pro, not a plugin you install and keep patched

Guardrails

Agents get the same permissions as people. #

Letting an agent into a site is a decision you make where you make every other permission decision. Access groups govern agents exactly as they govern people — the same system, not a parallel one bolted on.

  • Nothing exposed by default
  • Collections default to admin-only over MCP, and a field can be hidden from agents entirely. A public agent sees what you deliberately published.
  • Same limits, with or without an agent
  • Your client editing by hand in the admin gets exactly the limits their agent gets. An agent authorised by an editor sees and writes what that editor can, and nothing further.
  • The same save path as the admin
  • An agent’s write goes through the same save as the admin form: every field is built from your schema’s types and processed the same way.

The technical detail: personas, OAuth and tokens #

Three personas. Anonymous public read, API-key admin, and per-user OAuth 2.1 with scopes. A caller is resolved to exactly one of them before a single tool runs.

A real OAuth server. PKCE, refresh tokens, a consent screen, revocation and an audit log — not an API key wearing an OAuth costume.

Bearer tokens. A token gets the checks a signed-in user gets, resolved against that user’s access groups on every call.

Collection Create Read Update Delete
blog Allowed Allowed Allowed Allowed
testimonials Allowed Allowed Allowed Allowed
gallery Allowed Allowed Allowed Allowed
builder-pages Not allowed Allowed Not allowed Not allowed

Version-matched docs

It reads your install, not its training data. #

An agent working on a Total CMS site gets that install’s documentation — real field names, real Twig signatures, real schema definitions. Not documentation from two years ago, and not an invented API.

  • Signatures it can’t invent
  • The reference ships with each release and is built from that release’s own code, so what the agent reads is what your version actually exposes.
  • Your schemas, not a guess
  • An agent asks the site for its collections and fields and gets the real definitions back, including custom schemas that exist nowhere but your install.
  • Ships enabled
  • The documentation tools are a bundled extension turned on by default. There is no separate docs server to run and nothing to keep in sync.

Try it now

It’s already live. Connect to it. #

The Total CMS documentation is served over MCP by Total CMS itself. Paste the config into your MCP client and ask it anything about Total CMS — no install, no signup.

This connects to our documentation, not to a site of yours. To connect your own, point the same client at yoursite.com/mcp; the connection guide covers both.

Pricing

What it doesn’t do, and what it costs. #

  • Standard’s MCP is public and read-only
  • Standard gets anonymous read access to content you have published publicly. OAuth, API keys and agent writes are Pro, so on Standard no remote agent can reach a private client site.
  • PHP 8.2+, your own server
  • There is no hosted tier to sign up for. You run it, which is the point, but it does mean you need somewhere to run it.
  • Flat files have a ceiling
  • Excellent to a point and honest past it: this is not the right store for millions of records. Filtering large collections is done in memory.
  • Others have MCP through plugins
  • Craft, Statamic and Kirby each have a capable community-built MCP server; none ships one of its own. In Total CMS it is part of the product: same release cycle, same licence, same access groups. Accurate as of September 2026.

Standard

$195

  • The full CMS your clients edit
  • Public MCP, read-only
  • Agents answer questions about your public content

Buy Standard

Pro

$395

  • API keys and OAuth 2.1
  • Private content and agent writes
  • Everything the hand-off shows: build, edit, refuse

Buy Pro

Start Free Trial

45 days with every Pro feature, no credit card. Both licenses are one-time, per domain, with two years of updates; the software keeps running after that. Compare every feature

Agents on your pages, too. Experimental #

AI is moving into the browser itself. The WebMCP extension hands the agent in a visitor’s browser real tools instead of making it scrape your HTML.

  • Forms an agent can call
  • One Twig call renders a form an agent can fill and submit. It saves exactly the way a person’s submit does: the same validation, the same schema checks, the same form actions afterwards.
  • The visitor’s own permissions
  • Reads run as whoever is at the keyboard, always read-only, and another site can’t borrow the session.
  • Experimental, and says so
  • Off by default. It needs Chrome’s WebMCP origin trial and tracks a spec that’s still moving. Browsers without it just get a normal page.

Hand the agent the keys you choose. #

Install it on any PHP host, connect your agent, and decide what your client’s agent can touch. 45 days, every Pro feature, no credit card.

Start Free Trial

composer create-project totalcms/totalcms

Using Claude Code? Run tcms skill:install and your agent picks up the Total CMS conventions, the CLI and the way schemas are meant to be written.

── more in #ai-agents 4 stories · sorted by recency
── more on @total cms 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/total-cms-flat-file-…] indexed:0 read:6min 2026-10-07 · —