{"slug": "total-cms-flat-file-php-cms-with-a-built-in-mcp-server", "title": "Total CMS – Flat-File PHP CMS with a Built-In MCP Server", "summary": "Total CMS, a flat-file PHP content management system first shipped in 2015 and now licensed on more than 4,500 sites, ships a built-in MCP server in its Standard and Pro tiers rather than as a separately installed plugin. The MCP server resolves every caller to one of three personas — anonymous public read, API-key admin, or per-user OAuth 2.1 with scopes — and applies the same access groups to agents as to human users, with collections defaulting to admin-only over MCP and fields hideable from agents entirely. Agent writes go through the same schema-driven save path as the admin form, and the server serves version-matched documentation from the install itself rather than the agent's training data.", "body_md": "# The CMS your coding agent already knows how to use.\n\n⏺ totalcms · **built-in MCP server**\n\n⎿ your schemas, your content, this install’s docs\n\nMCP is the standard plug that lets AI agents use real tools. Total CMS ships one, and your client edits only what you allow — by hand in the admin, or through their own agent.\n\nThe hand-off\n\n## Two agents, one set of guardrails.\n\nThe hand-off the demo video records, step by step. You build with your agent, your client works with theirs, and neither gets further than you allowed.\n\nIllustrative session · real tool names and error text · scroll to play it · tap a step\n\n> Add testimonials the client can manage herself\n\n⏺ totalcms · **create_schema**\n\nid: \"testimonial\"\n\nproperties: author · quote · photo · company\n\n⎿ schema testimonial saved\n\n⏺ totalcms · **create_collection**\n\nid: \"testimonials\", schema: \"testimonial\"\n\nmcp: { access: \"authenticated\" }\n\n⎿ collection testimonials saved\n\n> Add the quote from Maria’s email to the site\n\n⏺ totalcms · **create_object**\n\ncollection: \"testimonials\"\n\n```\n{\n  \"id\": \"maria-lopez\",\n  \"author\": \"Maria Lopez\",\n  \"quote\": \"<p>I can finally update the site myself.</p>\",\n  \"company\": \"Lopez Bakery\"\n}\n```\n\nAdded. The photo field takes an upload, so that one’s yours to add in the admin.\n\n> While you’re in there, swap the homepage hero for a video\n\n⏺ totalcms · **patch_object**\n\ncollection: \"builder-pages\", id: \"home\"\n\nError: Your account’s groups do not grant update on ‘builder-pages’.\n\nI can’t change the homepage. Your Editor access covers content like testimonials, not site pages — that one’s for your designer.\n\n$ ls tcms-data/testimonials/\n\nmaria-lopez.json\n\n$ cat tcms-data/testimonials/maria-lopez.json\n\n{\n\n  \"id\": \"maria-lopez\",\n\n  \"author\": \"Maria Lopez\",\n\n  \"quote\": \"<p>I can finally update the site myself.</p>\",\n\n  \"company\": \"Lopez Bakery\"\n\n}\n\nOne file on your server. Copy it, back it up, open it in any editor.\n\nAn illustrative session: the tool names, arguments and error message are the real ones from Total CMS. Maria and the bakery are made up.\n\n- 4,500+\n- licensed sites\n- 2015\n- first shipped\n- MCP built in\n- in Standard and Pro, not a plugin you install and keep patched\n\nGuardrails\n\n## Agents get the same permissions as people.\n\nLetting an agent into a site is a decision you make where you make every other permission decision. Access groups govern agents exactly as they govern people — the same system, not a parallel one bolted on.\n\n- Nothing exposed by default\n- Collections default to admin-only over MCP, and a field can be hidden from agents entirely. A public agent sees what you deliberately published.\n- Same limits, with or without an agent\n- Your client editing by hand in the admin gets exactly the limits their agent gets. An agent authorised by an editor sees and writes what that editor can, and nothing further.\n- The same save path as the admin\n- An agent’s write goes through the same save as the admin form: every field is built from your schema’s types and processed the same way.\n\n## The technical detail: personas, OAuth and tokens\n\n**Three personas.** Anonymous public read, API-key admin, and per-user OAuth 2.1 with scopes. A caller is resolved to exactly one of them before a single tool runs.\n\n**A real OAuth server.** PKCE, refresh tokens, a consent screen, revocation and an audit log — not an API key wearing an OAuth costume.\n\n**Bearer tokens.** A token gets the checks a signed-in user gets, resolved against that user’s access groups on every call.\n\n| Collection | Create | Read | Update | Delete | \n|---|---|---|---|---|\n| blog | Allowed | Allowed | Allowed | Allowed | \n| testimonials | Allowed | Allowed | Allowed | Allowed | \n| gallery | Allowed | Allowed | Allowed | Allowed | \n| builder-pages | Not allowed | Allowed | Not allowed | Not allowed | \n\nVersion-matched docs\n\n## It reads your install, not its training data.\n\nAn agent working on a Total CMS site gets that install’s documentation — real field names, real Twig signatures, real schema definitions. Not documentation from two years ago, and not an invented API.\n\n- Signatures it can’t invent\n- The reference ships with each release and is built from that release’s own code, so what the agent reads is what your version actually exposes.\n- Your schemas, not a guess\n- An agent asks the site for its collections and fields and gets the real definitions back, including custom schemas that exist nowhere but your install.\n- Ships enabled\n- The documentation tools are a bundled extension turned on by default. There is no separate docs server to run and nothing to keep in sync.\n\nTry it now\n\n## It’s already live. Connect to it.\n\nThe Total CMS documentation is served over MCP by Total CMS itself. Paste the config into your MCP client and ask it anything about Total CMS — no install, no signup.\n\nThis connects to our documentation, not to a site of yours. To connect your own, point the same client at `yoursite.com/mcp`; the [connection guide](https://docs.totalcms.co/mcp/connect/) covers both.\n\nPricing\n\n## What it doesn’t do, and what it costs.\n\n- Standard’s MCP is public and read-only\n- Standard gets anonymous read access to content you have published publicly. OAuth, API keys and agent writes are Pro, so on Standard no remote agent can reach a private client site.\n- PHP 8.2+, your own server\n- There is no hosted tier to sign up for. You run it, which is the point, but it does mean you need somewhere to run it.\n- Flat files have a ceiling\n- Excellent to a point and honest past it: this is not the right store for millions of records. Filtering large collections is done in memory.\n- Others have MCP through plugins\n- Craft, Statamic and Kirby each have a capable community-built MCP server; none ships one of its own. In Total CMS it is part of the product: same release cycle, same licence, same access groups. Accurate as of September 2026.\n\n### Standard\n\n$195\n\n- The full CMS your clients edit\n- Public MCP, read-only\n- Agents answer questions about your public content\n\n[Buy Standard](https://totalcms.co/store)\n\n### Pro\n\n$395\n\n- API keys and OAuth 2.1\n- Private content and agent writes\n- Everything the hand-off shows: build, edit, refuse\n\n[Buy Pro](https://totalcms.co/store)\n\n[Start Free Trial](https://totalcms.co/trial)\n\n45 days with every Pro feature, no credit card. Both licenses are one-time, per domain, with two years of updates; the software keeps running after that. [Compare every feature](https://totalcms.co/pricing)\n\n## Agents on your pages, too. Experimental\n\nAI is moving into the browser itself. The [WebMCP extension](https://docs.totalcms.co/extensions/webmcp) hands the agent in a visitor’s browser real tools instead of making it scrape your HTML.\n\n- Forms an agent can call\n- One Twig call renders a form an agent can fill and submit. It saves exactly the way a person’s submit does: the same validation, the same schema checks, the same form actions afterwards.\n- The visitor’s own permissions\n- Reads run as whoever is at the keyboard, always read-only, and another site can’t borrow the session.\n- Experimental, and says so\n- Off by default. It needs Chrome’s WebMCP origin trial and tracks a spec that’s still moving. Browsers without it just get a normal page.\n\n## Hand the agent the keys you choose.\n\nInstall it on any PHP host, connect your agent, and decide what your client’s agent can touch. 45 days, every Pro feature, no credit card.\n\n[Start Free Trial](https://totalcms.co/trial)\n\n```\ncomposer create-project totalcms/totalcms\n```\n\nUsing Claude Code? Run `tcms skill:install` and your agent picks up the Total CMS conventions, the CLI and the way schemas are meant to be written.", "url": "https://wpnews.pro/news/total-cms-flat-file-php-cms-with-a-built-in-mcp-server", "canonical_source": "https://totalcms.co/ai", "published_at": "2026-10-07 12:49:50+00:00", "updated_at": "2026-10-07 13:20:49.462299+00:00", "lang": "en", "topics": ["ai-agents", "agent-protocols", "developer-tools", "ai-tools"], "entities": ["Total CMS", "MCP", "OAuth 2.1", "PKCE", "Twig"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/total-cms-flat-file-php-cms-with-a-built-in-mcp-server", "markdown": "https://wpnews.pro/news/total-cms-flat-file-php-cms-with-a-built-in-mcp-server.md", "text": "https://wpnews.pro/news/total-cms-flat-file-php-cms-with-a-built-in-mcp-server.txt", "jsonld": "https://wpnews.pro/news/total-cms-flat-file-php-cms-with-a-built-in-mcp-server.jsonld"}}