UniFi MCP
A set of MCP servers for UniFi: the agent works with Ubiquiti Network, Protect and Access controllers
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Works with network infrastructure and access systems
- Requires UniFi controller credentials
- Mutating operations affect a live network
Install
Manual install
uvx unifi-network-mcp@latestRun the Network server directly from PyPI. For Protect and Access use unifi-protect-mcp and unifi-access-mcp.
This is third-party code. Review the repository files before installing.
What it does
The project bundles separate MCP servers per UniFi application: Network, Protect and Access. Each server exposes its application's features as MCP tools that are queryable and composable, with safe defaults. Read-only tools support fan-out across multiple locations, while writes require an explicit target location. Servers install via uvx from PyPI or as marketplace plugins, with a stdio transport and optional HTTP for trusted local clients. For remote access there is a cloud relay via a worker and sidecar.
Who it is for. For network and devops engineers who operate Ubiquiti UniFi gear.
Good fit when
- You need to query a UniFi Network controller from an agent
- You need to work with UniFi Protect cameras and events
- You need to manage access via UniFi Access
Not a fit when
- You have no UniFi controller credentials
- You do not want to give an agent access to network infrastructure
- You need remote access without setting up a secured relay
Example request
Show connected clients on the UniFi network and list access points with their statusLimitations
You need the UniFi controller address and credentials, usually a username and password in environment variables. Python 3.13 or newer is required. The HTTP transport is off by default and unauthenticated, meant for trusted local clients; for external access use a secured proxy or the cloud relay. The Protect, Access and relay pieces are marked beta.
How to disable. Remove the unifi server entries from your MCP client config or uninstall the plugins via /plugin. For a uvx setup, removing the config entries is enough.
MCP
- Transport
- stdio, http
- Authentication
- API key
| Environment variables | |
|---|---|
| UNIFI_NETWORK_HOST required | UniFi Network controller address |
| UNIFI_NETWORK_USERNAME required | Username for the UniFi controller |
| UNIFI_NETWORK_PASSWORD required, secret | Password for the UniFi controller |
Security check
- Works with network infrastructure and access systems
- Requires UniFi controller credentials
- Mutating operations affect a live network
README in short
The README describes a collection of UniFi MCP servers per application, Network, Protect and Access, each with its own PyPI package. It shows marketplace plugin installs for Claude Code, Codex and OpenClaw, plus direct uvx runs with UNIFI_NETWORK_HOST, USERNAME and PASSWORD. It details the transport security model, response modes keyed to the MCP protocol version, and a cloud relay built on a Cloudflare worker and a local sidecar. It also documents a standalone HTTP API service. MIT licensed.
FAQ
Is it one server or several?
Several. Separate servers for Network, Protect and Access, each installed by its own PyPI package.
How do I enable remote access?
Through the cloud relay: a worker as the secured entry point and a local sidecar holding an outbound connection. Direct HTTP is only for trusted local clients.
Related
An MCP server built into the Netdata agent: metrics, logs, alerts and live process, service and container data for an AI assistant
GitHub's official MCP server: code, issues, pull requests, Actions and security alerts straight from the agent
Agent Skills for Google products
Agent Skills for Google products and technologies
Official Google skill collection for working with Google Cloud, BigQuery, GKE, ads and analytics from an agent
AWS's official MCP server suite: docs, IaC, containers, serverless, databases, cost and monitoring