Open source · MIT · Model Context Protocol

Talk to your UniFi network.

unifi-mcp connects Claude and other AI assistants to your UniFi controller. Ask about devices, clients, WiFi and firewall in plain English, and let the assistant make changes when you allow it.

docker pull ghcr.io/mattoddie/unifi-mcp
Claude · unifi
Why is the lounge TV buffering?
unifi_list_clientssearch: "tv"unifi_get_deviceLounge APunifi_get_rf_scan5 GHz
The TV is on Lounge AP at -78 dBm and only 12 Mbps. That AP's 5 GHz radio is 81% utilised on channel 36, shared with three neighbouring networks.

Channel 149 is clear. Want me to move the radio there?
Yes, go ahead.
unifi_set_radiona → ch 149
Done. The Lounge AP's 5 GHz radio is now on channel 149, and the TV reconnected at 433 Mbps. ✅
132tools
14toolsets
5guided prompts
1Docker container

Ask anything

Your network, in plain English.

The assistant picks the right tools, runs them against your controller and explains what it found. No dashboards to dig through.

“Give me a health check of the network.”

get_site_healthlist_deviceslist_alarms

“Which clients have a weak WiFi signal right now?”

list_clientsget_device

“Review my port forwards and firewall for anything risky.”

list_port_forwardslist_firewall_policies

“Which devices have firmware updates waiting?”

get_firmware_statusrolling_upgrade

“Create 10 one-day guest vouchers limited to 5 Mbps.”

create_vouchers

“Block 'kids-tablet' until I say otherwise.”

list_clientsblock_client

Broad coverage

132 tools across the whole network.

Grouped into 14 toolsets you can switch on and off, so the assistant only sees what you need:54 read, 55 write and 23 delete tools.

read write delete · Full tool reference →

Safe by default

It can look. It only touches when you say so.

Tools that aren't allowed aren't registered at all. The assistant can't see them, so it can't call them or be talked into calling them.

  • Read-only out of the box. Writes and deletes are two separate switches.
  • Destructive tools are labelled, so your client asks before running them.
  • Secrets are redacted. Passphrases and keys never reach the model unless asked for.
  • Bearer-token auth, a Host allow-list and a non-root container.
Read the security model →
read

54 tools, always on

list_devices · get_site_health · list_threats …
write

55 tools with UNIFI_ALLOW_WRITES=true

restart_device · block_client · save_wlan …
delete

23 tools with UNIFI_ALLOW_DELETES=true as well

delete_network · delete_firewall_rule …

Works with your controller

UniFi OS consoles and self-hosted controllers

  • UDM / UDM Pro / UDM SE
  • Cloud Gateway (UCG)
  • Dream Router
  • UniFi Express
  • Cloud Key Gen2+
  • UniFi OS Server
  • Self-hosted Network app

API key or local account. UniFi OS is detected automatically. Compatibility →

Works with your assistant

Streamable HTTP or stdio

  • Claude Code
  • Claude Desktop
  • VS Code
  • Cursor
  • Codex
  • Any MCP client

Run it once and share it, or start it per session with docker run -i. Client setup →

Quick start

Up and running in three steps.

  1. 1

    Create an API key

    In UniFi Network, open Settings → Control Plane → Integrations → Create API Key. On older controllers, use a local account instead.

  2. 2

    Start the container

    curl -fsSLO https://raw.githubusercontent.com/mattoddie/unifi-mcp/main/compose.yaml
    curl -fsSL https://raw.githubusercontent.com/mattoddie/unifi-mcp/main/example.env -o .env
    # set UNIFI_URL, UNIFI_API_KEY and MCP_AUTH_TOKEN in .env
    docker compose up -d
  3. 3

    Connect your assistant

    claude mcp add --transport http unifi \
      http://<docker-host>:8080/mcp \
      --header "Authorization: Bearer <token>"

    Then ask: “How's my network doing?”

Ready to talk to your network?

Free, open source and MIT licensed. Contributions and compatibility reports are welcome.