UniFi Gateway MCP Server
by pete-buildsio.github.pete-builds/unifiv0.25.0
Safe-by-default UniFi MCP: Network + Protect + Access, multi-site, dry-run, audit log.
context tax
queued
security
queued
cold start
queued
freshness
Active8d ago
Install UniFi Gateway MCP server
No published package or hosted endpoint yet — see the repository README for build-from-source instructions.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| STUB_MODE | — | — | When true, the server returns realistic mock data and requires no UniFi hardware. Defaults to true so the image is functional out of the box. |
| UNIFI_HOST | — | — | IP address or hostname of the UniFi OS gateway (UCG-Fiber, UDM Pro, etc). Required when STUB_MODE=false and MCP_UNIFI_CONTROLLERS_FILE is unset. |
| UNIFI_API_KEY | — | yes | Local API key generated under Settings -> Control Plane -> Integrations on the gateway. Required when STUB_MODE=false and MCP_UNIFI_CONTROLLERS_FILE is unset. |
| UNIFI_SITE | — | — | UniFi controller site name. Defaults to 'default'. |
| UNIFI_VERIFY_SSL | — | — | Whether to verify the gateway's TLS certificate. Defaults to false because most home gateways use a self-signed cert. |
| MCP_UNIFI_CONTROLLERS_FILE | — | — | Path to a YAML file describing multiple named controllers for multi-site management. When set, the legacy UNIFI_HOST / UNIFI_API_KEY env vars are ignored. Each entry needs name, host, api_key, and optionally port, site, verify_ssl. |
| MCP_UNIFI_MODULES_ENABLED | — | — | Comma-separated list of modules to load. Known values: 'network', 'protect', 'access'. Defaults to 'network'. Set to 'network,protect,access' to enable Protect and Access tools alongside Network. Access currently ships read-only; door unlocks and credential issuance require session-token auth and are deferred. |
| UNIFI_ACCESS_HOST | — | — | UniFi Access hub IP or hostname. Required when the access module is enabled and STUB_MODE=false. Often the same host as UNIFI_HOST. |
| UNIFI_ACCESS_API_KEY | — | yes | UniFi Access API key. Separate from the Network API key; generated on the Access controller's developer settings. Required when the access module is enabled and STUB_MODE=false. |
| UNIFI_ACCESS_PORT | — | — | HTTPS port for the Access hub. Defaults to 12445 (the direct Access app port). |
| MCP_UNIFI_AUDIT_SINK | — | — | Audit log sink. One of 'file' (default), 'stdout', or 'syslog'. Every tool call is recorded to a JSONL stream with secrets scrubbed. |
| MCP_UNIFI_AUDIT_PATH | — | — | Path for the audit log file when MCP_UNIFI_AUDIT_SINK=file. Defaults to audit.jsonl in the process CWD. |
Freshness
Active — last maintenance signal 8d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-10-02 · 8d ago · GitHub
Latest release
2026-10-02 · 8d ago · GitHub · v0.25.0
Package published
no data · npm/PyPI
Registry entry updated
2026-10-02 · 8d ago · official registry · v0.25.0
FAQ
›Does UniFi Gateway require an API key?
Yes. It expects UNIFI_API_KEY, UNIFI_ACCESS_API_KEY, of which 2 are secrets.
›Can I use UniFi Gateway as a remote (hosted) MCP server?
Yes. It is a hosted MCP server; connect to its URL with any client that supports remote MCP.
›Is UniFi Gateway in the official MCP registry?
Yes, as io.github.pete-builds/unifi.