ClaudeCodeMod

All shelves / MCP servers

UniFi Network MCP

io.github.sirkirby/unifi-network-mcp · 420 stars · Python · MIT

MCP server Manage UniFi Network devices, clients, firewall, VLANs, VPNs, and more via MCP.

Install

The repo has no one-line install. Follow its README.

Published as

  • PyPIunifi-network-mcpstdio

From the server's entry in the official MCP Registry.

Configuration

NameSet asWhat it is
UNIFI_HOSTRequiredEnv varController IP/hostname
UNIFI_USERNAMERequired · SecretEnv varAdmin username
UNIFI_PASSWORDRequired · SecretEnv varAdmin password
UNIFI_API_KEYOptional · SecretEnv varAPI key (optional, experimental)
UNIFI_PORTOptionalEnv varController HTTPS port
UNIFI_VERIFY_SSLOptionalEnv varSSL certificate verification
UNIFI_SITEOptionalEnv varUniFi site name

Files

README.md

UniFi Network MCP Server

MCP server exposing 209 UniFi Network Controller tools for AI assistants and other MCP-capable clients. Query clients, devices, firewall rules, VLANs, VPNs, Traffic Flows, stats, and more with safe-by-default permissions and preview-before-confirm for all mutations.

Use this server when an existing AI assistant or other MCP-capable client needs UniFi Network tools. Software integrating over HTTP, including automation services, code-execution runtimes, and MCP adapters, should use unifi-api-server for REST and GraphQL reads, actions, and SSE events. The calling application must sandbox generated code and enforce its resource limits.

Install

Claude Code (recommended)

The plugin installs the MCP server, an agent skill for tool discovery, and a guided setup command:

/plugin marketplace add sirkirby/unifi-mcp
/plugin install unifi-network@unifi-plugins

Then run the interactive setup to configure your controller connection:

/unifi-network:setup

This walks you through entering your controller host, credentials, and permission preferences — then writes everything to .claude/settings.local.json so it persists across sessions. Restart Claude Code after setup to connect.

Codex

Register the marketplace, then install unifi-network from Codex's /plugins UI:

codex plugin marketplace add sirkirby/unifi-mcp

After installing, ask Codex to use the UniFi Network setup skill. The setup flow registers the MCP server with codex mcp add, stores your controller environment values in Codex's MCP configuration, and prompts you to restart Codex.

PyPI / Docker

# PyPI
uvx unifi-network-mcp@latest
# or: pip install unifi-network-mcp

# Docker
docker pull ghcr.io/sirkirby/unifi-network-mcp:latest

# From source
git clone https://github.com/sirkirby/unifi-mcp.git
cd unifi-mcp && uv sync

Usage Examples

For the approved breaking MAC argument rename in the next minor release, see the MAC parameter migration guide.

Once connected, just ask your AI agent in natural language:

"Show me all clients on the Guest VLAN with their signal strength and data usage"

"Create a firewall rule that blocks IoT devices from reaching the internet between midnight and 6 AM"

"Which access points have the most client disconnections this week?"

"Audit my firewall policies — are there any redundant or conflicting rules?"

"Rename the device at 192.168.1.45 to 'Living Room TV' and show me its traffic stats"

"What changed on my network in the last 24 hours? Show me new clients and config changes."

"Show me the largest traffic flows from the last hour and summarize who talked to what."

All mutations (firewall rules, device changes, client blocking) use a preview-then-confirm flow — you see exactly what will change before anything is applied.

V2 NAT rules

unifi_list_nat_rules and unifi_get_nat_rule read V2 NAT rules. The create, update, delete, and toggle tools require Network session credentials and use V2 NAT rule IDs; port-forward and Integration API IDs are different. Public writes cover DNAT, SNAT, and MASQUERADE with IPv4, tcp_udp or all, and NONE or ADDRESS_AND_PORT filters. Creates default to enabled=false. Created rules are marked manual and non-predefined, and both values are checked on readback. Existing rules with missing or non-manual origin are not editable through these tools. SNAT rules with a translated port require source_filter.port; the controller validates port correspondence. Existing rules missing that source port must be corrected in the same update before they can be edited through these tools. Toggle takes an explicit enabled boolean, so repeating the same request is a no-op. IPv6, PPPoE, inverted/excluded matching, and other filter variants are not verified for public writes. Selector edits on a stored rule with an unverified type are refused, even when the same request changes its type to a verified one.

The MCP update preview shows a fresh before/after merge. Confirmation reads fresh state again, sends at most one full replacement, then checks persistence; delete checks fresh absence. If the controller reply or readback is uncertain, list rules before retrying. A concurrent controller edit between fetch and PUT can be overwritten because V2 NAT has no conditional replacement. These checks prove stored configuration, not packet-level enforcement. Existing Core NAT methods retain their return shapes; controller mutation exceptions now carry safe fixed guidance instead of raw response text.

For an approved packet test, use the IPv4 DNS redirect recipe. It covers a single client and synthetic destination, including same-subnet return traffic and cleanup.

Configure

Set these variables in the server's process environment. If you used /unifi-network:setup, this is already done. The server does not automatically load .env or working-directory YAML files; load a trusted env file explicitly in your launcher (Docker env_file: is supported), or select custom YAML with an absolute CONFIG_PATH. See configuration for migration examples.

# Server-specific variables (recommended)
UNIFI_NETWORK_HOST=192.168.1.1      # Controller IP or hostname
UNIFI_NETWORK_USERNAME=admin         # Local admin username
UNIFI_NETWORK_PASSWORD=your-password # Admin password
# Optional:
# UNIFI_NETWORK_API_KEY=             # UniFi API key (inventory and explicit Integration API tools)
# UNIFI_NETWORK_PORT=443             # Controller HTTPS port
# UNIFI_NETWORK_SITE=default         # UniFi site name
# UNIFI_NETWORK_VERIFY_SSL=false     # SSL certificate verification
# UNIFI_NETWORK_WEBSOCKET_ENABLED=true   # Real-time event listener feeding unifi_recent_events
# UNIFI_NETWORK_EVENT_BUFFER_SIZE=100    # Positive ring buffer capacity; invalid values prevent startup
# UNIFI_NETWORK_EVENT_BUFFER_TTL=300     # Positive lifetime in seconds; invalid values prevent startup

Fallback: Existing UNIFI_ variables (e.g., UNIFI_HOST) continue to work. The server checks for UNIFI_NETWORK_ first and falls back to UNIFI_* if the server-specific variable is not set. For single-controller setups, the shared variables are all you need.

API-key inventory and session authentication

Configure UNIFI_NETWORK_API_KEY without a username/password for device, active-client, network, and WLAN lists. The same tools select the available read path; no duplicate API-key tools are needed. When valid session credentials are also configured, the existing session path remains preferred.

On controllers accepting API keys on legacy inventory endpoints, the usual IDs and fields are preserved. This was verified on Network 10.6.106 with a UniFi OS proxy; the minimum supported firmware is not established. Other controllers can use the public Integration inventory fallback when that API is available. Public inventory has narrower fields and network coverage (for example, WAN/VPN networks may be absent). Results identify source_api=integration and expose the public UUID as integration_id, never as a legacy resource ID. Do not pass these UUIDs to legacy details/update tools. Missing legacy fields are unknown. API GraphQL projections therefore allow null for unavailable enabled, wired, and guest flags; clients must handle those nulls.

Historical clients (include_offline=true), full details, legacy mutations, and the Network websocket still require their supported legacy/session paths. API-key legacy transport is restricted to verified inventory GET requests; successful reads do not imply permission to write. Explicit Integration tools such as DPI lookup and firewall ordering retain their own API-key contracts (legacy zone-ID resolution also needs a session). Protect still requires session bootstrap, with an additional API key for public setters; Access retains its independent API-token and proxy-session paths. Discovery reports local_only, api_key_only, either, or both; these describe requirements, not proof that a configured credential has authenticated successfully.

MCP response size

Facts

Kind
MCP server
Repo
io.github.sirkirby/unifi-network-mcp
Group
Uncategorized
Stars
420
License
MIT
Language
Python
Last push
2026-10-08
Forks
117
MCP Registry
io.github.sirkirby/unifi-network-mcp
Homepage
unifimcp.com
Topics
agentic-ai, home-automation, mcp-server, unifi, unifi-access, unifi-controller, unifi-network, unifi-protect

More on this shelf

  1. 1Everythingmodelcontextprotocol/serversThis MCP server attempts to exercise all the features of the MCP protocol. It is not intended to be a useful server, but rather a test server for builders of MCP clients. It implements prompts, tools, resources, sampling, and more to showcase MCP capabilities.85.8k
  2. 2Fetchmodelcontextprotocol/serversA Model Context Protocol server that provides web content fetching capabilities. This server enables LLMs to retrieve and process content from web pages, converting HTML to markdown for easier consumption.85.8k
  3. 3Gitmodelcontextprotocol/serversA Model Context Protocol server for Git repository interaction and automation. This server provides tools to read, search, and manipulate Git repositories via Large Language Models.85.8k
  4. 4Memorymodelcontextprotocol/serversA basic implementation of persistent memory using a local knowledge graph. This lets Claude remember information about the user across chats.85.8k
  5. 5Sequential Thinkingmodelcontextprotocol/serversAn MCP server implementation that provides a tool for dynamic and reflective problem-solving through a structured thinking process.85.8k
  6. 6Timemodelcontextprotocol/serversA Model Context Protocol server that provides time and timezone conversion capabilities. This server enables LLMs to get current time information and perform timezone conversions using IANA timezone names, with automatic system timezone detection.85.8k