UniFi NetworkBLOCK
MCP servers & Graph API for the UniFi suite of applications, Network, Protect, and Access
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Leverage agents and agentic AI workflows to manage your UniFi deployment.
[](https://pypi.org/project/unifi-network-mcp/) [](https://pypi.org/project/unifi-protect-mcp/) [](https://pypi.org/project/unifi-access-mcp/) [](https://pypi.org/project/unifi-mcp-relay/) [](https://pypi.org/project/unifi-api-server/) [](https://www.npmjs.com/package/unifi-mcp-worker) [](LICENSE) [](https://www.python.org/downloads/)
Servers
Choose an integration
f2db13568fa0OBSERVED · 2026-09-28Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add unifi-access-mcp --env UNIFI_USERNAME=${UNIFI_USERNAME} --env UNIFI_PASSWORD=${UNIFI_PASSWORD} --env UNIFI_API_KEY=${UNIFI_API_KEY} -- None unifi-access-mcp==0.6.9Exposed tools (20)
13 read · 7 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_system_info | read | Get system information |
list_clients | read | List all clients |
list_devices | read | List all network devices |
restart_device | write | Restart a network device |
structured_inner | read | return StructuredInnerResult(**payload) |
unifi_alpha | read | Inspect client details |
unifi_batch | write | Execute multiple UniFi tools in a single request. Each call is an object with |
unifi_beta | read | Inspect client details |
unifi_exact_wall_policy | write | Apply the wall policy update workflow |
unifi_execute | write | Execute a UniFi tool by name. Use unifi_tool_index to discover available tools first. |
unifi_firewall_policy_update | write | Modify policy configuration |
unifi_get_client | read | pass |
unifi_list_clients | read | pass |
unifi_list_widgets | read | return await widget_manager.get_widgets() |
unifi_list_zebras | read | return await widget_manager.get_zebras() |
unifi_location_timeline | read | Query events across all connected UniFi products (Network, Protect, Access) |
unifi_test | read | return StructuredResult(success=True, data={ |
unifi_tool_index | read | Discover available UniFi tools. Returns names and descriptions by default. |
unifi_wall | write | Policy update settings |
unifi_wall_alpha | write | Configure policy update |
Trust audit
BLOCKgrade F · trust 33/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (9 observation(s))
- Network
- declared (9 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
As of PR #350, all plugin tool responses redact sensitive fields by default — Wi-Fi passphrases, VPN private/preshared keys, SNMP community strings, and Access credential token/PIN values are replaced
**Affected workflows:** WLAN passphrase updates, VPN key rotation, SNMP community string changes, Access credential token/PIN mutations. Plugin skills that guide agents through these workflows must ex
401/403 means the key was rejected. Use this to validate Access API key configuration:
product_pkg = importlib.import_module(f"unifi_api.serializers.{product}")importlib.import_module(f"unifi_api.serializers.{product}.{modname}")console.log(`Rotating relay token for "${location.location_name}"...`);console.log(` Relay token: ${maskToken(loc.relay_token)}`);console.log(` Agent token: ${maskToken(config.agent_token)}`);console.log(` Admin token: ${maskToken(config.admin_token)}`);secret = "private-value-192.0.2.53"
SECRET = "synthetic-controller-only-secret-mdns"
SECRET = "synthetic-controller-only-vpn-secret"
SECRET = "private-threat-canary"
SECRET = "synthetic-private-vpn-value"
comment_payload = _snapshot_payload(comments=[_comment(1, "github_pat_abcdefghijklmnopqrstuvwxyz123456")])
.nojekyll
pydantic_mod = importlib.import_module(f"unifi_core.{server}.models.{domain}")strawberry_mod = importlib.import_module(f"unifi_api.graphql.types.{server}.{domain}")module = importlib.import_module(module_name)
@if [ ! -d "../../.venv" ]; then \
@WHEEL=$$(ls ../../dist/unifi_access_mcp-*.whl | head -1); \
docker run --rm --env-file ../../.env unifi-access-mcp:latest
rm -rf ../../dist/
@if [ ! -d "../../.venv" ]; then \
assert args == ("GET", "https://192.168.1.1:12445/api/v1/developer/visitors")Gates applied: no_behavioural_pass.
f2db13568fa0full audit observations/trust-audit/mcp-server/sirkirby__unifi-network-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-28 | f2db13568fa0 | BLOCK | F | 33 | first audit |
Questions
What is the UniFi Network MCP server?
MCP servers & Graph API for the UniFi suite of applications, Network, Protect, and Access
What tools does UniFi Network expose?
20 in total: 13 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is UniFi Network safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (33/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does UniFi Network need?
It reads GH_TOKEN, GITHUB_TOKEN, UNIFI_ACCESS_API_KEY, UNIFI_API_DB_KEY, UNIFI_API_KEY, UNIFI_NETWORK_PASSWORD_COMMAND, UNIFI_PASSWORD, UNIFI_RELAY_TOKEN and UNIFI_USERNAME from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does UniFi Network run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as unifi-mcp-worker-source at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (f2db13568fa0), read on 2026-09-28. The repository is watched and re-audited when it changes.