“Give me a health check of the network.”
get_site_healthlist_deviceslist_alarmsOpen source · MIT · Model Context Protocol
unifi-mcp connects Claude and other AI assistants to your UniFi controller. Ask about devices, clients, WiFi and firewall in plain English, and let the assistant make changes when you allow it.
docker pull ghcr.io/mattoddie/unifi-mcpAsk anything
The assistant picks the right tools, runs them against your controller and explains what it found. No dashboards to dig through.
“Give me a health check of the network.”
get_site_healthlist_deviceslist_alarms“Which clients have a weak WiFi signal right now?”
list_clientsget_device“Review my port forwards and firewall for anything risky.”
list_port_forwardslist_firewall_policies“Which devices have firmware updates waiting?”
get_firmware_statusrolling_upgrade“Create 10 one-day guest vouchers limited to 5 Mbps.”
create_vouchers“Block 'kids-tablet' until I say otherwise.”
list_clientsblock_clientBroad coverage
Grouped into 14 toolsets you can switch on and off, so the assistant only sees what you need:54 read, 55 write and 23 delete tools.
overview3Sites, controller information and site health.
devices19UniFi devices (gateways, switches, access points, PDUs): status, firmware, radios, adoption and maintenance.
clients8Connected and known clients: lookup, blocking, reconnecting and naming.
switching7Switch ports and port profiles, including PoE.
wifi4WiFi networks (WLANs) and join QR codes.
networks13Networks/VLANs, WAN links, local DNS records, bandwidth profiles and dynamic DNS.
firewall20Port forwards, legacy firewall rules and groups, zone-based firewall policies and zones, and traffic rules.
routing6Static routes and policy-based traffic routes.
security7Threat management (IDS/IPS), country blocking and content filtering.
vpn9VPN servers and site-to-site VPNs, RADIUS profiles and RADIUS accounts.
hotspot10Hotspot vouchers, operators, guest authorization and the guest portal.
monitoring13Events, alarms, traffic and DPI statistics, speed tests, logs and dashboards.
admin12Site settings, administrators, backups, controller updates and site management.
raw1A raw API escape hatch for anything the other tools don't cover. It is limited to GET requests unless writes are enabled.
read write delete · Full tool reference →
Safe by default
Tools that aren't allowed aren't registered at all. The assistant can't see them, so it can't call them or be talked into calling them.
54 tools, always on
list_devices · get_site_health · list_threats …55 tools with UNIFI_ALLOW_WRITES=true
restart_device · block_client · save_wlan …23 tools with UNIFI_ALLOW_DELETES=true as well
delete_network · delete_firewall_rule …Works with your controller
API key or local account. UniFi OS is detected automatically. Compatibility →
Works with your assistant
Run it once and share it, or start it per session with docker run -i. Client setup →
Quick start
In UniFi Network, open Settings → Control Plane → Integrations → Create API Key. On older controllers, use a local account instead.
curl -fsSLO https://raw.githubusercontent.com/mattoddie/unifi-mcp/main/compose.yaml
curl -fsSL https://raw.githubusercontent.com/mattoddie/unifi-mcp/main/example.env -o .env
# set UNIFI_URL, UNIFI_API_KEY and MCP_AUTH_TOKEN in .env
docker compose up -dclaude mcp add --transport http unifi \
http://<docker-host>:8080/mcp \
--header "Authorization: Bearer <token>"Then ask: “How's my network doing?”
Free, open source and MIT licensed. Contributions and compatibility reports are welcome.