# Total CMS – Flat-File PHP CMS with a Built-In MCP Server

> Source: <https://totalcms.co/ai>
> Published: 2026-10-07 12:49:50+00:00

# The CMS your coding agent already knows how to use.

⏺ totalcms · **built-in MCP server**

⎿ your schemas, your content, this install’s docs

MCP is the standard plug that lets AI agents use real tools. Total CMS ships one, and your client edits only what you allow — by hand in the admin, or through their own agent.

The hand-off

## Two agents, one set of guardrails.

The hand-off the demo video records, step by step. You build with your agent, your client works with theirs, and neither gets further than you allowed.

Illustrative session · real tool names and error text · scroll to play it · tap a step

> Add testimonials the client can manage herself

⏺ totalcms · **create_schema**

id: "testimonial"

properties: author · quote · photo · company

⎿ schema testimonial saved

⏺ totalcms · **create_collection**

id: "testimonials", schema: "testimonial"

mcp: { access: "authenticated" }

⎿ collection testimonials saved

> Add the quote from Maria’s email to the site

⏺ totalcms · **create_object**

collection: "testimonials"

```
{
  "id": "maria-lopez",
  "author": "Maria Lopez",
  "quote": "<p>I can finally update the site myself.</p>",
  "company": "Lopez Bakery"
}
```

Added. The photo field takes an upload, so that one’s yours to add in the admin.

> While you’re in there, swap the homepage hero for a video

⏺ totalcms · **patch_object**

collection: "builder-pages", id: "home"

Error: Your account’s groups do not grant update on ‘builder-pages’.

I can’t change the homepage. Your Editor access covers content like testimonials, not site pages — that one’s for your designer.

$ ls tcms-data/testimonials/

maria-lopez.json

$ cat tcms-data/testimonials/maria-lopez.json

{

  "id": "maria-lopez",

  "author": "Maria Lopez",

  "quote": "<p>I can finally update the site myself.</p>",

  "company": "Lopez Bakery"

}

One file on your server. Copy it, back it up, open it in any editor.

An illustrative session: the tool names, arguments and error message are the real ones from Total CMS. Maria and the bakery are made up.

- 4,500+
- licensed sites
- 2015
- first shipped
- MCP built in
- in Standard and Pro, not a plugin you install and keep patched

Guardrails

## Agents get the same permissions as people.

Letting an agent into a site is a decision you make where you make every other permission decision. Access groups govern agents exactly as they govern people — the same system, not a parallel one bolted on.

- Nothing exposed by default
- Collections default to admin-only over MCP, and a field can be hidden from agents entirely. A public agent sees what you deliberately published.
- Same limits, with or without an agent
- Your client editing by hand in the admin gets exactly the limits their agent gets. An agent authorised by an editor sees and writes what that editor can, and nothing further.
- The same save path as the admin
- An agent’s write goes through the same save as the admin form: every field is built from your schema’s types and processed the same way.

## The technical detail: personas, OAuth and tokens

**Three personas.** Anonymous public read, API-key admin, and per-user OAuth 2.1 with scopes. A caller is resolved to exactly one of them before a single tool runs.

**A real OAuth server.** PKCE, refresh tokens, a consent screen, revocation and an audit log — not an API key wearing an OAuth costume.

**Bearer tokens.** A token gets the checks a signed-in user gets, resolved against that user’s access groups on every call.

| Collection | Create | Read | Update | Delete | 
|---|---|---|---|---|
| blog | Allowed | Allowed | Allowed | Allowed | 
| testimonials | Allowed | Allowed | Allowed | Allowed | 
| gallery | Allowed | Allowed | Allowed | Allowed | 
| builder-pages | Not allowed | Allowed | Not allowed | Not allowed | 

Version-matched docs

## It reads your install, not its training data.

An agent working on a Total CMS site gets that install’s documentation — real field names, real Twig signatures, real schema definitions. Not documentation from two years ago, and not an invented API.

- Signatures it can’t invent
- The reference ships with each release and is built from that release’s own code, so what the agent reads is what your version actually exposes.
- Your schemas, not a guess
- An agent asks the site for its collections and fields and gets the real definitions back, including custom schemas that exist nowhere but your install.
- Ships enabled
- The documentation tools are a bundled extension turned on by default. There is no separate docs server to run and nothing to keep in sync.

Try it now

## It’s already live. Connect to it.

The Total CMS documentation is served over MCP by Total CMS itself. Paste the config into your MCP client and ask it anything about Total CMS — no install, no signup.

This connects to our documentation, not to a site of yours. To connect your own, point the same client at `yoursite.com/mcp`; the [connection guide](https://docs.totalcms.co/mcp/connect/) covers both.

Pricing

## What it doesn’t do, and what it costs.

- Standard’s MCP is public and read-only
- Standard gets anonymous read access to content you have published publicly. OAuth, API keys and agent writes are Pro, so on Standard no remote agent can reach a private client site.
- PHP 8.2+, your own server
- There is no hosted tier to sign up for. You run it, which is the point, but it does mean you need somewhere to run it.
- Flat files have a ceiling
- Excellent to a point and honest past it: this is not the right store for millions of records. Filtering large collections is done in memory.
- Others have MCP through plugins
- Craft, Statamic and Kirby each have a capable community-built MCP server; none ships one of its own. In Total CMS it is part of the product: same release cycle, same licence, same access groups. Accurate as of September 2026.

### Standard

$195

- The full CMS your clients edit
- Public MCP, read-only
- Agents answer questions about your public content

[Buy Standard](https://totalcms.co/store)

### Pro

$395

- API keys and OAuth 2.1
- Private content and agent writes
- Everything the hand-off shows: build, edit, refuse

[Buy Pro](https://totalcms.co/store)

[Start Free Trial](https://totalcms.co/trial)

45 days with every Pro feature, no credit card. Both licenses are one-time, per domain, with two years of updates; the software keeps running after that. [Compare every feature](https://totalcms.co/pricing)

## Agents on your pages, too. Experimental

AI is moving into the browser itself. The [WebMCP extension](https://docs.totalcms.co/extensions/webmcp) hands the agent in a visitor’s browser real tools instead of making it scrape your HTML.

- Forms an agent can call
- One Twig call renders a form an agent can fill and submit. It saves exactly the way a person’s submit does: the same validation, the same schema checks, the same form actions afterwards.
- The visitor’s own permissions
- Reads run as whoever is at the keyboard, always read-only, and another site can’t borrow the session.
- Experimental, and says so
- Off by default. It needs Chrome’s WebMCP origin trial and tracks a spec that’s still moving. Browsers without it just get a normal page.

## Hand the agent the keys you choose.

Install it on any PHP host, connect your agent, and decide what your client’s agent can touch. 45 days, every Pro feature, no credit card.

[Start Free Trial](https://totalcms.co/trial)

```
composer create-project totalcms/totalcms
```

Using Claude Code? Run `tcms skill:install` and your agent picks up the Total CMS conventions, the CLI and the way schemas are meant to be written.
