Drupal is a registered trademark of Dries Buytaert
Release: Leaflet 10.4.11 Minor update available for module leaflet (10.4.11). Release: Session Inspector 1.0.8 Minor update available for module session_inspector (1.0.8). Release: Migrate QA 2.0.4 Minor update available for module migrate_qa (2.0.4). Release: CKEditor Description List 3.0.0 Major update available for module ckeditor_descriptionlist (3.0.0). Release: FlowDrop 2.4.0 Minor update available for module flowdrop (2.4.0). Release: JWT Token Refresh 1.0.4 Minor update available for module jwt_token_refresh (1.0.4). Release: ConReg 1.0.0-beta1 First beta version released for module conreg (1.0.0-beta1). Release: AI Image Studio 1.0.0-beta8 New beta version released for module ai_image_studio (1.0.0-beta8). Usage Milestone: Statistics Counter Module statistics_counter crossed 1,000 active installs. Module Revived: Decoupled Router 2.0.7 Module decoupled_router updated after 11 months of inactivity (2.0.7).

Agent Access

No security coverage
View on drupal.org

Agent Access allows an external AI agent to securely connect to a Drupal site using a user's existing Drupal account. It leverages existing Drupal modules and standards to ensure the agent only performs actions permitted by the site's existing user roles and permissions, without introducing new code or AI models. This project facilitates external AI agent integration with Drupal by utilizing standard authentication and Drupal's built-in access control systems.

What this is

Agent Access for Drupal lets an external AI agent connect to a Drupal site through a person's existing Drupal account. The connection is standards-based (MCP + OAuth, no Drupal-specific client code), and the agent can only do what that person can already do - the site's own permissions, workflows, and revision history stay in charge. It's a recipe: it assembles existing contrib modules and ships no code of its own.

Status: experimental - read this first

  • Early v0.1 candidate. Not covered by Drupal's security advisory policy.
  • Not composer-installable yet — two required modules have broken drupal.org packaging (fixes are upstream). REVIEWING.md in the repository has a working local setup.

What it installs

simple_oauth, Tool API (tool, tool_belt), and the MCP server stack (mcp_server, mcp_server_tool_bridge, mcp_server_oauth), plus two read-only OAuth scopes mapped to permissions every site already has. It creates no roles, no accounts, no content types - and installs no AI model, provider key, or chatbot.

Get involved

Review the recipe and the evidence from the first conformance run (REVIEWING.md is the guide), try it on a throwaway site and report what differs, or pick up an issue in the queue. This is a contribution to the Drupal AI Initiative's "Outside AI" work - external agents using Drupal - alongside #3576908: [META] 2026 Innovation Roadmap (draft).

Activity

Tracked releases
1
Tracked since
Aug 2026
Latest release
1 week ago
Releases (12 mo)
1 ▲ from 0
Maintenance
Active

Releases

Version Type Release date
1.0.x-dev Dev Aug 10, 2026