mcp-unifi
Run a UniFi network in plain English, with guardrails an assistant cannot talk its way past.
A safety-first MCP server that lets Claude, or any MCP client, manage a self-hosted UniFi network: VLANs, firewall rules, WiFi and switch ports. Opt-in modules add Protect for cameras and read-only Access for doors. The rules live in the server, not the prompt. Every destructive call can be previewed with a dry run, multi-step changes roll back on partial failure, and every call lands in an audit log with secrets scrubbed.
- 100+ tools across UniFi Network, Protect and Access
- Dry-run previews, composite rollback, JSONL audit log
- Read-only mode, multi-site, cosign-signed images with an SBOM
- Docker, Helm, Claude Desktop bundle, and the official MCP Registry
> put the smart speakers on their own network, away from the laptops
dry_runcreate_iot_network: 3 changes predicted
previewvlan 30 iot, wlan iot, 1 drop rule to the main LAN
applyapproved and applied by the owner, 3 of 3
auditlogged to audit.jsonl, secrets scrubbed







