unifi-mcp-server
UniFi semantic-analysis MCP — 54 tools on Site Manager API and Cloud Connector. 8 workflow Prompts (4 fleet-ops + 4 MSP). Read-only.
README
UniFi MCP Server
The MSP-style UniFi MCP — built around the official Site Manager API + Cloud Connector with cross-site analytics no other UniFi MCP exposes.
54 tools split across 7 semantic-analysis aggregations, 9 raw Site Manager, and 35 Cloud Connector. Severity verdicts (
healthy/info/warning/critical) on top of curated thresholds. 8 MCP Prompts (4 fleet-wide ops + 4 MSP workflows). Read-only — Ubiquiti's API keys don't ship write yet.
Pre-flight diagnostic
npx -y @us-all/unifi-mcp --doctor
Validates env vars, pings Site Manager API, probes Cloud Connector (if owner key set), and checks category toggles before starting. Exits non-zero on critical issues so it works in CI / pre-deploy scripts.
What it does that others don't
- Site Manager analytics —
site-health-timeline,summarize-site,firmware-inventory,compare-sites,wan-uptime-trend,top-clients-by-bandwidth,list-sites-overview. No other UniFi MCP exposes these. - Severity verdicts, not just numbers — every analysis tool returns
healthy / info / warning / critical / unknownwith a curated reason. Curated thresholds (e.g. WAN uptime <90% =critical, startupTime <1h =criticalpost-reboot). - Cloud Connector first-class — 35 tools through the official
/v1/connector/consoles/{id}/...proxy.connectorAvailable(capability) vsconnectorResolved(this-call) split. - Aggregation tools — fold 3–7 sequential calls into 1 with
caveatsarray surfacing partial failures (e.g. Site Manager API can't window-bound WAN uptime — that's surfaced explicitly). - MCP Prompts (8) — fleet ops:
triage-site-degradation,firmware-rollout-audit,wan-uptime-report,cross-site-anomaly-detection. MSP workflows:msp-onboard-site-checklist,msp-monthly-client-report,msp-fleet-firmware-plan,msp-bandwidth-complaint-investigation. - Token-efficient by design — smallest schema footprint of all
@us-all/*MCPs (default ~5K tokens with owner key). Fleet of 200+ devices analyzable inside a single session. - Apps SDK card —
summarize-siterenders as a fleet-status card on ChatGPT clients (online %, WAN uptime, gateway, devices) via_meta["openai/outputTemplate"]. Claude clients receive the same JSON content. - stdio + Streamable HTTP — defaults to stdio. Set
MCP_TRANSPORT=httpfor ChatGPT Apps SDK or remote clients (Bearer auth viaMCP_HTTP_TOKEN).
Try this — 5 prompts
Connect the server to Claude Desktop or Claude Code, then paste any of these:
- MSP morning check — "Fleet health check across all my UniFi sites. Flag anything not
healthywith severity, top 3 issues." - Firmware rollout audit — "Find devices on outdated firmware across every site. Group by site, show current vs latest version, prioritize by criticality."
- Site degradation triage — "USM site has WiFi complaints. Pull the last 24h: device statuses, WAN uptime, recent reboots, top-bandwidth clients. Anything anomalous?"
- WAN SLA report — "Generate a monthly WAN uptime report for all sites. Surface outages > 5 minutes, dual-WAN failover events, sites below 99.5% target."
- Cross-site anomaly — "Compare USS to my other sites — clients per AP, traffic patterns, device firmware mix. Flag outliers and suggest the most likely cause."
When to use this vs other UniFi MCPs
| sirkirby/unifi-mcp | enuno/unifi-mcp-server | @us-all/unifi-mcp (this) |
|
|---|---|---|---|
| GitHub stars | 291 | 117 | — |
| Tool count | 224 | 74 | 51 |
| Scope | Network + Protect + Access + Drive | Network + multi-site + QoS + backup | Site Manager + Cloud Connector + analytics |
| Site Manager API | ❌ | partial | ✅ deep + analytics |
| Cloud Connector | ❌ | partial (3 modes) | ✅ avail/resolved split |
| UniFi Protect (cameras) | ✅ | ❌ | ❌ (out of scope) |
| UniFi Access (doors) | ✅ | ❌ | ❌ (out of scope) |
| Aggregation tools | ❌ | ❌ | ✅ 7 |
| Severity verdicts | ❌ | ❌ | ✅ curated thresholds |
| MCP Prompts | ❌ | ❌ | ✅ 8 (incl. 4 MSP workflows) |
Use sirkirby when you need cameras (Protect) or door access. Use enuno if you want raw Network API breadth. Use this server for MSP-style multi-site analytics, fleet triage, and any "is something off?" question across many consoles.
Install
Claude Desktop
{
"mcpServers": {
"unifi": {
"command": "npx",
"args": ["-y", "@us-all/unifi-mcp"],
"env": {
"UNIFI_API_KEY": "<your-key>",
"UNIFI_API_KEY_OWNER": "<owner-key-or-same-key-if-role=owner>"
}
}
}
}
Claude Code
claude mcp add unifi -s user \
-e UNIFI_API_KEY=<your-key> \
-e UNIFI_API_KEY_OWNER=<owner-key> \
-- npx -y @us-all/unifi-mcp
Build from source
git clone https://github.com/us-all/unifi-mcp-server.git
cd unifi-mcp-server && pnpm install && pnpm build
node dist/index.js
API keys — which one and where
The most common onboarding friction. UniFi has two surfaces through the same https://api.ui.com/v1:
| Surface | What it gives | Path | Env var |
|---|---|---|---|
| Site Manager | hosts, sites, devices summary, ISP metrics, SD-WAN configs (aggregated, console-wide) | /v1/hosts, /v1/sites, /v1/devices, /v1/sd-wan-configs |
UNIFI_API_KEY |
| Cloud Connector | per-device, per-client, networks, firewall, WiFi (proxies to local controller) | /v1/connector/consoles/{hostId}/... |
UNIFI_API_KEY_OWNER |
API key permissions inherit from the role of the account that created them.
| Account role | Site Manager | Cloud Connector |
|---|---|---|
| Admin (non-owner) | ✅ | ❌ 403 |
| Owner | ✅ | ✅ |
If you have the owner role, set both env vars to the same key. That's the most common case for @us-all operators.
Get the key: unifi.ui.com → Settings → API → Generate. View Only is the only option in GA today (Full Access greyed out — Early Access program needed for write).
Cloud Connector requirements
- Console firmware ≥ 5.0.3
- API path:
https://api.ui.com/v1/connector/consoles/{hostId}/{appPath} - Local
siteIdis a UUID, not the literal stringdefault - Available endpoints: Network integration API (
/network/integration/v1/sites, devices, clients, networks). Legacy paths (/api/s/{site}/stat/event) return 404. Event logs / syslog not exposed.
Configuration
| Variable | Required | Default | Description |
|---|---|---|---|
UNIFI_API_KEY |
✅ | — | API key from unifi.ui.com (any admin role) |
UNIFI_API_KEY_OWNER |
❌ | — | Owner-role API key — enables 35 Cloud Connector tools. If your key has owner role, set this to the same value. |
UNIFI_API_URL |
❌ | https://api.ui.com/v1 |
API base URL |
UNIFI_TOOLS |
❌ | — | Comma-sep allowlist of categories. |
UNIFI_DISABLE |
❌ | — | Comma-sep denylist. Ignored when UNIFI_TOOLS is set. |
MCP_TRANSPORT |
❌ | stdio |
http to enable Streamable HTTP transport |
MCP_HTTP_TOKEN |
conditional | — | Bearer token. Required when MCP_TRANSPORT=http |
MCP_HTTP_PORT |
❌ | 3000 |
HTTP listen port |
MCP_HTTP_HOST |
❌ | 127.0.0.1 |
HTTP bind host (DNS rebinding protection auto-enabled for localhost) |
MCP_HTTP_SKIP_AUTH |
❌ | false |
Skip Bearer auth — e.g. behind a reverse proxy that handles it |
Categories (8): analysis, raw, devices, clients, networks, firewall, wan, reference.
When MCP_TRANSPORT=http: POST /mcp (Bearer-auth JSON-RPC) + GET /health (public liveness).
Token efficiency
Smallest schema footprint of all @us-all/* MCPs.
| Scenario | Tools | Schema tokens |
|---|---|---|
| default no-owner | 17 | 1,700 |
UNIFI_TOOLS=analysis |
8 | 1,000 (−42%) |
| default with owner key | 52 | ~5,000 |
UNIFI_TOOLS=analysis + owner |
8 | 1,000 (−80%) |
Severity & thresholds
Every analysis tool returns one of:
healthy— no issuesinfo— informational, no actionwarning— needs attentioncritical— immediate actionunknown— API failure or incomplete data
Curated thresholds:
| Condition | Severity |
|---|---|
| Device offline | critical |
startupTime < 1h |
critical (just rebooted) |
startupTime < 24h |
warning (recent reboot) |
startupTime < 72h |
info (monitor) |
| WAN uptime < 90% | critical |
| WAN uptime < 95% | warning |
MCP Prompts (8)
Workflow templates available via MCP prompts/list. Four are fleet-ops; four are MSP-specific (managed-service-provider workflows).
Fleet ops:
triage-site-degradation— site complaints workflow: device + WAN + reboots + clients in sequence.firmware-rollout-audit— fleet-wide firmware diff and rollout safety check.wan-uptime-report— monthly WAN SLA-style report across sites.cross-site-anomaly-detection— compare a site to fleet baseline; flag outliers.
MSP workflows:
msp-onboard-site-checklist— pass/fail readiness checklist for a newly added customer site (firmware floor, console connectivity, uptime trend, connector availability, firewall sanity, recent reboots, pending devices).msp-monthly-client-report— customer-facing monthly health report (one site → headline, network availability, devices, top users, recommendations) with non-technical phrasing.msp-fleet-firmware-plan— staggered N-wave rollout plan to a target firmware version, ordered by risk-tolerance with maintenance windows + rollback triggers.msp-bandwidth-complaint-investigation— triage 'internet is slow at site X' via WAN trend + ISP metrics + top clients + DPI categories + recent reboots.
MCP Resources
unifi://site/{hostName}/devices— site's devices snapshotunifi://reboots/recent— recently rebooted devices fleet-wide
Tools (54)
8 categories. Use search-tools to discover at runtime; full list collapsed below. Cloud Connector tools (33) only register when UNIFI_API_KEY_OWNER is set; without it the surface is 21 tools.
| Group | Tools |
|---|---|
| Semantic analysis (incl. aggregations) | 9 |
| Site Manager raw | 9 |
| Cloud Connector (devices/clients/networks/wifi/firewall/wan/reference) | 33 |
Sites local (list-local-sites, get-app-info) |
2 |
Meta (search-tools) |
1 |
<details> <summary>Full tool list</summary>
Semantic analysis (9)
list-sites-overview, analyze-site-health, detect-recent-reboots, compare-sites, firmware-inventory, wan-uptime-trend, top-clients-by-bandwidth, summarize-site (aggregation), site-health-timeline (aggregation)
Site Manager API (9)
list-hosts, get-host, list-sites, list-devices, get-isp-metrics (optional), query-isp-metrics (optional), list-sdwan-configs, get-sdwan-config, get-sdwan-config-status
Cloud Connector — devices (4)
get-device-details, get-device-by-id, get-device-statistics, list-pending-devices
Cloud Connector — clients (2)
list-site-clients, get-client-details
Cloud Connector — networks (3)
list-networks, get-network-details, get-network-references
Cloud Connector — WiFi (2)
list-wifi-broadcasts, get-wifi-broadcast-details
Cloud Connector — firewall / ACL / DNS (10)
list-firewall-zones, get-firewall-zone, list-firewall-policies, get-firewall-policy, get-firewall-policy-ordering, list-acl-rules, get-acl-rule, get-acl-rule-ordering, list-dns-policies, get-dns-policy
Cloud Connector — traffic / WAN / VPN (5)
list-traffic-matching-lists, get-traffic-matching-list, list-wans, list-vpn-tunnels, list-vpn-servers
Cloud Connector — hotspot / reference (7)
list-vouchers, get-voucher-details, list-radius-profiles, list-device-tags, list-dpi-categories, list-dpi-applications, list-countries
Sites local (2)
list-local-sites, get-app-info
Meta
search-tools — query other tools by keyword; always enabled.
</details>
Architecture
Claude → MCP stdio → src/index.ts
├── tools/analysis.ts → Site Manager API (UNIFI_API_KEY)
├── tools/*.ts (raw) → Site Manager API (UNIFI_API_KEY)
└── tools/connector.ts → Cloud Connector (UNIFI_API_KEY_OWNER)
helpers/resolver.ts → hostName ↔ ID mapping
Built on @us-all/mcp-toolkit:
extractFields— token-efficient response projectionsaggregate(fetchers, caveats)— fan-out helper forsummarize-site/site-health-timelinecreateWrapToolHandler—X-API-KEYredaction +ConnectorError/UniFiErrorextraction- Retry: 3 attempts, exponential backoff (1s → 2s → 4s) + jitter, 30s Cloud Connector timeout
Limitations
- Read-only — UniFi API keys don't support write yet (Full Access role greyed out in GA).
- Rate limit — 10,000 req/min on stable v1; 100 req/min on Early Access.
- Cloud Connector partial proxy — Network integration API works; legacy paths return 404; event logs/syslog not exposed.
- ISP Metrics — may return 404 depending on account/plan.
Tech stack
Node.js 18+ • TypeScript strict ESM • pnpm • @modelcontextprotocol/sdk • zod v4 • dotenv.
License
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。