UniFiBLOCK
An MCP server that leverages official UniFi API
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/enuno/unifi-mcp-server/actions/workflows/ci.yml) [](https://github.com/enuno/unifi-mcp-server/actions/workflows/security.yml) [](https://codecov.io/github/enuno/unifi-mcp-server) [](https://pypi.org/project/unifi-mcp-server/) [](https://www.python.org/downloads/) [](LICENSE) [](https://deepwiki.com/enuno/unifi-mcp-server)
A Model Context Protocol (MCP) server that exposes the UniFi Network Controller API today and is evolving into a production-grade multi-domain platform for Protect, Access, and enterprise-scale orchestration.
See SPEC.md for the architecture target and DEVELOPMENT_PLAN.md for the phase roadmap.
Operator quick start
Objective
Give operators a fast, safe reading order for understanding what the server does today, what it is becoming, and which docs govern rollout decisions.
Prerequisites
- You know which UniFi API mode the deployment uses: local, cloud-ea, or cloud-v1.
- You know whether the runtime is stdio, HTTP, SSE, or streamable HTTP.
- You have read the phase target in
SPEC.mdand the current work item inDEVELOPMENT_PLAN.md.
Procedure
- Confirm the current stable release and current phase focus.
- Read
SPEC.mdfor architecture intent andDEVELOPMENT_PLAN.mdfor sequencing. - Use
API.mdanddocs/UNIFI_API.mdfor implementation surface details.
d542d730ae99OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add unifi-mcp-server --env UNIFI_PASSWORD=${UNIFI_PASSWORD} -- npx -y [email protected]Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
debug_api_request | read | Debug tool to query arbitrary UniFi API endpoints. |
health_check | read | Health check endpoint to verify server is running. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
- Use `--env-file` to load from `.env` file
- Use `--env-file` to load from `.env` file
✓ UniFi Host: https://192.168.2.1
api_key="abc123def456ghi789...",
.aiignore
.clinerules
.env.docker.example
.markdownlint.json
.pre-commit-config.yaml
modules.append(importlib.import_module(f"src.tools.{info.name}"))const screenshotPath = path.join(__dirname, '../../screenshots/login-page.png');
const htmlPath = path.join(__dirname, '../../screenshots/login-page.html');
const COOKIES_FILE = path.join(__dirname, '../../session-cookies.json');
const SCREENSHOT_DIR = path.join(__dirname, '../../screenshots');
const docsDir = path.join(__dirname, '../../docs');
- `UNIFI_HOST`: "<https://192.168.2.1>"
settings.base_url = "https://192.168.2.1"
== "https://192.168.2.1/proxy/network/v2/api/site/default/firewall/zone"
settings.base_url = "https://192.168.2.1:443"
anthropic, mcp
anthropic, mcp
posthog-node
puppeteer, dotenv, prompts, chalk, ora
- **Network transports now require authentication (breaking)**: the `http`, `sse`, and `streamable_http` transports expose every registered tool — including destructive ones — over a TCP listener, but
- **Every rejected sessionless request to `/mcp` leaked ~44 KiB, permanently (issue #173)**: the `mcp` SDK's `StreamableHTTPSessionManager` creates and registers a new session (transport plus server t
Gates applied: no_behavioural_pass.
d542d730ae99full audit observations/trust-audit/mcp-server/enuno__unifi-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | d542d730ae99 | BLOCK | D | 69 | first audit |
Questions
What is the UniFi MCP server?
An MCP server that leverages official UniFi API
What tools does UniFi expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is UniFi safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does UniFi need?
It reads ANTHROPIC_API_KEY, ANTHROPIC_AUTH_TOKEN, AUTH_2FA_TIMEOUT, AUTH_PASSKEY_TIMEOUT, AUTH_PASSWORD_TIMEOUT, UNIFI_API_KEY, UNIFI_CLOUD_API_KEY, UNIFI_CLOUD_EA_API_KEY, UNIFI_CLOUD_V1_API_KEY, UNIFI_HOME_API_KEY, UNIFI_LAB_API_KEY and UNIFI_LOCAL_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does UniFi run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as unifi-api-scraper at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (d542d730ae99), read on 2026-10-06. The repository is watched and re-audited when it changes.