Skip to content
Developer ToolsAuto-generatedScore: 34

Adobe Experience Manager (AEM) API MCP Server

The Adobe Experience Manager (AEM) API, defined by its Swagger/OpenAPI specification, serves as the programmatic gateway to Adobe Experience Manager, a comprehensive enterprise-grade content management solution (CMS) and digital asset management (DAM) platform.

Quick Start Summary

The Adobe Experience Manager (AEM) API MCP server is a Model Context Protocol bridge that connects AI assistants — including Claude Desktop, Cursor, Windsurf, and VS Code Copilot — to the Adobe Experience Manager (AEM) API API through natural language. It exposes 10 API endpoints as callable tools, such as postCqActions, postConfigAdobeGraniteSamlAuthenticationHandler, postConfigAemPasswordReset, and more. No authentication is required — setup takes approximately 30 seconds. The server uses STDIO transport and can be installed by running npx -y @mcp/adobe-com-aem. This integration is sourced from the auto Adobe Experience Manager (AEM) API OpenAPI specification (v3.7.1-pre.0) and has a quality score of 34/99 (fair documentation coverage).

10Endpointstools mapped
NoneAuthopen access
34/99Qualityfair
~30 secSetupno auth

Server Details

Category
Developer Tools
Authentication
None
Endpoints
10 operations
Transport
STDIO
Spec Version
v3.7.1-pre.0
Install Command
npx -y @mcp/adobe-com-aem

Environment Variables

ADOBE_EXPERIENCE_MANAGER__AEM__API_API_KEY

Example: your_adobe_experience_manager__aem__api_api_key

Top Endpoints

POST
/.cqactions.html

postCqActions

POST
/apps/system/config/com.adobe.granite.auth.saml.SamlAuthenticationHandler.config

postConfigAdobeGraniteSamlAuthenticationHandler

POST
/apps/system/config/com.shinesolutions.aem.passwordreset.Activator

postConfigAemPasswordReset

POST
/apps/system/config/com.shinesolutions.healthcheck.hc.impl.ActiveBundleHealthCheck

postConfigAemHealthCheckServlet

POST
/apps/system/config/org.apache.felix.http

postConfigApacheFelixJettyBasedHttpService

Own this API?

Verify ownership of this listing to control the description, configuration details, and documentation links. Choose between free manual verification or instant premium placement.

Option 1: Free Verification

Slow manual review. Requires creating a GitHub issue with verified documentation or domain verification.

  • • Verified badge on page
  • • Standard search sorting
  • • 2-3 business days review
Start Free Claim →
Instant & Boosted

Option 2: Featured Upgrade($9/mo)

Instant verification plus premium styling, featured badges, and directory placement boost.

  • • ★ Featured star & amber highlight border
  • • Top of directory search placement
  • • Instant activation via claim token

📖 Detailed MCP Integration Guide

A technical breakdown of capabilities, agent workflows, and security/configuration best practices.

Capabilities & Use Cases
The Adobe Experience Manager (AEM) API, defined by its Swagger/OpenAPI specification, serves as the programmatic gateway to Adobe Experience Manager, a comprehensive enterprise-grade content management solution (CMS) and digital asset management (DAM) platform. This particular subset of the API provides direct, administrative control over critical system-level configurations, moving beyond standard content CRUD operations. Its core capabilities include the programmatic manipulation of Sling OSGi configurations and the execution of specific system actions. For instance, it enables the configuration of essential security components such as the SAML Authentication Handler (com.adobe.granite.auth.saml.SamlAuthenticationHandler.config) for federated single sign-on, the Referrer Filter (org.apache.sling.security.impl.ReferrerFilter) for preventing cross-site request forgery, and proxy settings (org.apache.http.proxyconfigurator.config). It also allows for the management of core servlet configurations like the DavEx servlet for WebDAV access and the default GET servlet, as well as the deployment of specific bundles like a password reset activator or a health check implementation. This API is provided by Adobe as part of its Experience Cloud ecosystem, and its primary use cases are for DevOps engineers, AEM administrators, and backend developers tasked with automating environment provisioning, enforcing consistent security policies across multiple AEM instances, and performing health and operational checks programmatically as part of CI/CD pipelines or infrastructure-as-code deployments.
🤖AI Agent Value
When exposed as a set of tools to an AI coding assistant via the Model Context Protocol (MCP), this API transforms the assistant from a code generator into an active AEM platform operator. The value lies in bridging the gap between high-level natural language instructions and the precise, low-level HTTP POST requests required to modify OSGi configurations, which are notoriously complex and error-prone to manage manually. An AI integrated with this MCP server gains the ability to reason about the state of an AEM environment and make safe, auditable changes. It can understand a request like "Ensure our production author environment uses our corporate IDP for login and has enhanced CSRF protection," and translate it into the correct sequence of API calls: first updating the SAML handler config with the appropriate metadata, then configuring the Referrer Filter to allow necessary domains while blocking others. This turns the AI into a powerful ally for enforcing security and configuration compliance at scale, automating what would otherwise be a tedious, console-clicking exercise prone to human error.
💬Example Workflows
Practically, a developer can instruct the AI agent to perform a variety of dynamic tasks that streamline AEM operations. For example, one could issue the command: "Set up a new health check for our custom AEM bundles and configure the system to perform a password reset for a locked-out user." The AI would interpret this by first using the endpoint POST /apps/system/config/com.shinesolutions.healthcheck.hc.impl.ActiveBundleHealthCheck to deploy the health check configuration, followed by invoking POST /apps/system/config/com.shinesolutions.aem.passwordreset.Activator to trigger the reset process. Another workflow could be: "Audit and correct the servlet configurations on all publish instances to disable the DAV servlet and ensure the referrer filter is active." The AI would then generate the specific payload for POST /apps/system/config/org.apache.sling.jcr.davex.impl.servlets.SlingDavExServlet to set sling.davex.disable=true and similarly update the referrer filter configuration via its dedicated endpoint. These instructions allow the AI to act as an automated runbook, executing multi-step configuration changes with natural language guidance.
🛡️Security & Auth
Critical attention must be paid to authentication, security, and configuration best practices when deploying this MCP server. Although the current specification lists "None" for authentication, this is an absolute red flag for any production environment. In reality, all calls to these endpoints are secured by AEM's authentication mechanisms, typically requiring an authenticated session with administrative privileges (e.g., admin user or a service account with the jcr:all privilege on the relevant paths). Therefore, the MCP server implementation must securely manage credentials—preferably using short-lived tokens or service accounts with tightly scoped permissions—and inject them into the API requests. The principle of least privilege is paramount; the credentials used should only have permissions to modify the specific configuration nodes they are authorized to change, preventing catastrophic system-wide misconfigurations. Developers should also ensure all communication with the AEM instance is over HTTPS and consider implementing configuration change approval workflows, where the AI proposes changes for human review before execution, especially when operating on production systems.

Similar APIs

Other APIs in the Developer Tools category.

GitHub API

Access GitHub repositories, issues, pull requests, and more. Integrate GitHub workflows directly into your AI agent.

OAuth2

GitLab API

Manage repositories, CI/CD pipelines, and merge requests through your AI agent.

OAuth2

Box Platform API

The Box Platform API, provided by Box (box.com), is a robust and comprehensive RESTful service that enables deep integration with the Box cloud content management ecosystem. It serves as the programmatic backbone for enterprises and developers seeking to build custom applications and workflows that interact with content stored securely in Box. Its core capabilities extend far beyond basic file operations, encompassing a full spectrum of content lifecycle management. Developers can programmatically create, upload, download, search, and manage files and folders, but the API's true power lies in its enterprise-grade features. These include advanced collaboration management through invitations and permissions, granular user and group administration within an enterprise directory, and sophisticated security and compliance controls. Specific endpoint groups for managing collaboration whitelists and exempt targets allow for precise governance over external sharing policies, ensuring that content is only shared with approved domains. Furthermore, the API facilitates complex legal and compliance use cases, such as placing items on legal hold or applying retention policies, making it an indispensable tool for regulated industries and large organizations.

Asana

This API serves as the programmatic backbone for the Asana work management platform, provided by Asana, Inc. It enables developers to interact programmatically with one of the world's leading enterprise collaboration and productivity suites. The core capabilities of this interface center around the CRUD (Create, Read, Update, Delete) operations for fundamental Asana objects. Specifically, the provided endpoints grant control over project attachments—allowing for the uploading, retrieval, and management of files associated with tasks and projects—and custom fields, which are pivotal for creating structured, data-rich workflows. These custom fields allow organizations to define unique data types (like dropdown menus, text fields, or dates) to standardize information capture across projects, moving beyond basic task lists to true operational tracking. Typical use cases span from enterprise project management offices (PMOs) needing to programmatically generate status reports and audit attachments, to development teams automating the creation of bug-tracking projects with predefined custom fields for severity and status, to operational leaders building dashboards that aggregate and analyze custom field data for resource allocation insights.

Related MCP Server Integrations

GitHub API MCP Setup

Access GitHub repositories, issues, pull requests, and more. Integrate GitHub workflows directly into your AI agent.

Developer ToolsConfigure →

GitLab API MCP Setup

Manage repositories, CI/CD pipelines, and merge requests through your AI agent.

Developer ToolsConfigure →

Box Platform API MCP Setup

The Box Platform API, provided by Box (box.com), is a robust and comprehensive RESTful service that enables deep integration with the Box cloud content management ecosystem. It serves as the programmatic backbone for enterprises and developers seeking to build custom applications and workflows that interact with content stored securely in Box. Its core capabilities extend far beyond basic file operations, encompassing a full spectrum of content lifecycle management. Developers can programmatically create, upload, download, search, and manage files and folders, but the API's true power lies in its enterprise-grade features. These include advanced collaboration management through invitations and permissions, granular user and group administration within an enterprise directory, and sophisticated security and compliance controls. Specific endpoint groups for managing collaboration whitelists and exempt targets allow for precise governance over external sharing policies, ensuring that content is only shared with approved domains. Furthermore, the API facilitates complex legal and compliance use cases, such as placing items on legal hold or applying retention policies, making it an indispensable tool for regulated industries and large organizations.

Developer ToolsConfigure →

Asana MCP Setup

This API serves as the programmatic backbone for the Asana work management platform, provided by Asana, Inc. It enables developers to interact programmatically with one of the world's leading enterprise collaboration and productivity suites. The core capabilities of this interface center around the CRUD (Create, Read, Update, Delete) operations for fundamental Asana objects. Specifically, the provided endpoints grant control over project attachments—allowing for the uploading, retrieval, and management of files associated with tasks and projects—and custom fields, which are pivotal for creating structured, data-rich workflows. These custom fields allow organizations to define unique data types (like dropdown menus, text fields, or dates) to standardize information capture across projects, moving beyond basic task lists to true operational tracking. Typical use cases span from enterprise project management offices (PMOs) needing to programmatically generate status reports and audit attachments, to development teams automating the creation of bug-tracking projects with predefined custom fields for severity and status, to operational leaders building dashboards that aggregate and analyze custom field data for resource allocation insights.

Developer ToolsConfigure →

clickup20 MCP Setup

The clickup20 Polls API is a lightweight, focused web service designed to facilitate the creation and management of simple polling mechanisms. Provided by ClickUp, a platform known for its project management and productivity tools, this API serves as a specialized component for gathering quick, quantitative feedback. Its core capabilities are straightforward: it allows consumers to programmatically retrieve a list of existing poll questions and to submit new poll questions for consideration. Typical use cases span both enterprise and consumer domains. In an enterprise setting, a development team might integrate this API to run quick polls during sprint retrospectives, gauge internal sentiment on a new tool, or gather binary feedback on proposed technical designs within a project management workflow. For consumer applications, it could power simple feedback widgets within a mobile app or website, enabling users to vote on feature priorities or content topics. The API’s simplicity, requiring no authentication, makes it highly accessible for rapid prototyping and integration into internal tools where complex credential management is unnecessary.

Developer ToolsConfigure →