# UniFi Gateway MCP server

> Manage self-hosted UniFi Network, Protect and Access with dry-run previews, multi-site support and an audit log.

- Listing: https://mcp.tc/i/unifi-gateway
- Connect: this is a local (stdio) server; install it on your machine (see Install). The listing link is a page, not an MCP endpoint.
- Type: local (stdio)
- Auth: API key
- Category: [Cloud & DevOps](https://mcp.tc/c/cloud-devops)
- Vendor: Pete Stergion
- Homepage: <https://pete-builds.github.io/mcp-unifi/>
- Docs: <https://github.com/pete-builds/mcp-unifi>
- Repository: <https://github.com/pete-builds/mcp-unifi>
- Package: oci `ghcr.io/pete-builds/mcp-unifi:0.25.0`

## About

Community server for self-hosted UniFi gateways. It covers UniFi Network (devices, VLANs, WLANs, firewall, switch ports, port forwards, DHCP reservations, observability), opt-in UniFi Protect (cameras, motion events, smart detections) and read-only UniFi Access (doors, credentials, visitors, badge events). Destructive tools accept a dry-run flag, and every call is written to a JSONL audit log with secrets scrubbed.

It runs locally as a Docker image (stdio or Streamable HTTP), a Claude Desktop bundle, a Helm chart or uvx. A local UniFi API key from the gateway is needed; no cloud account is required. A stub mode returns mock data so you can try it without hardware. One instance can manage several controllers via a YAML file.

## What it can do

- Manage VLANs, WLANs, firewall rules, DHCP reservations and port forwards
- Preview destructive changes with dry-run before applying
- Inspect devices, clients and AP radio settings
- Read UniFi Protect cameras, motion events and smart detections
- Read UniFi Access doors, credentials and badge events
- Manage multiple UniFi sites from one server
- Review a JSONL audit log of every tool call
- Try the tool surface in stub mode without hardware

## Example prompts

- "List all VLANs and WLANs on my UniFi gateway."
- "Preview creating an IoT network with dry run before applying it."
- "Audit open ports across my firewall rules and zone policies."
- "Show recent motion events from my Protect cameras."

## Install

### Claude Code

1. Run this in a terminal, in your project folder:

```bash
claude mcp add --transport stdio unifi-gateway --env "UNIFI_API_KEY=<YOUR_UNIFI_API_KEY>" --env "UNIFI_ACCESS_API_KEY=<YOUR_UNIFI_ACCESS_API_KEY>" -- docker run -i --rm ghcr.io/pete-builds/mcp-unifi:0.25.0
```

2. Start Claude Code and type `/mcp`. **unifi-gateway** should show as connected.

Add `--scope user` to make it available in every project. Replace the placeholders with your own values.

### Claude Desktop

1. Open **Settings → Developer → Edit Config**. It opens `claude_desktop_config.json`. Add:

`claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "unifi-gateway": {
      "command": "docker",
      "args": [
        "run",
        "-e",
        "UNIFI_API_KEY",
        "-e",
        "UNIFI_ACCESS_API_KEY",
        "-i",
        "--rm",
        "ghcr.io/pete-builds/mcp-unifi:0.25.0"
      ],
      "env": {
        "UNIFI_API_KEY": "<YOUR_UNIFI_API_KEY>",
        "UNIFI_ACCESS_API_KEY": "<YOUR_UNIFI_ACCESS_API_KEY>"
      }
    }
  }
}
```

2. Save the file and restart Claude Desktop. Replace the placeholders with your own values.

Needs Docker on your computer. The file lives in `~/Library/Application Support/Claude/` on macOS and `%APPDATA%\Claude\` on Windows.

### Cursor

[Add to Cursor](<https://cursor.com/install-mcp?name=unifi-gateway&config=eyJjb21tYW5kIjoiZG9ja2VyIiwiYXJncyI6WyJydW4iLCItZSIsIlVOSUZJX0FQSV9LRVkiLCItZSIsIlVOSUZJX0FDQ0VTU19BUElfS0VZIiwiLWkiLCItLXJtIiwiZ2hjci5pby9wZXRlLWJ1aWxkcy9tY3AtdW5pZmk6MC4yNS4wIl0sImVudiI6eyJVTklGSV9BUElfS0VZIjoiPFlPVVJfVU5JRklfQVBJX0tFWT4iLCJVTklGSV9BQ0NFU1NfQVBJX0tFWSI6IjxZT1VSX1VOSUZJX0FDQ0VTU19BUElfS0VZPiJ9fQ%3D%3D>) (opens Cursor)

Or add it by hand to `~/.cursor/mcp.json` (all projects) or `.cursor/mcp.json` (this project):

`mcp.json`:

```json
{
  "mcpServers": {
    "unifi-gateway": {
      "command": "docker",
      "args": [
        "run",
        "-e",
        "UNIFI_API_KEY",
        "-e",
        "UNIFI_ACCESS_API_KEY",
        "-i",
        "--rm",
        "ghcr.io/pete-builds/mcp-unifi:0.25.0"
      ],
      "env": {
        "UNIFI_API_KEY": "<YOUR_UNIFI_API_KEY>",
        "UNIFI_ACCESS_API_KEY": "<YOUR_UNIFI_ACCESS_API_KEY>"
      }
    }
  }
}
```

Needs Docker on your computer. Replace the placeholders with your own values.

### VS Code

Add it to `.vscode/mcp.json`. VS Code asks for the secret the first time and stores it securely:

`.vscode/mcp.json`:

```json
{
  "servers": {
    "unifi-gateway": {
      "type": "stdio",
      "command": "docker",
      "args": [
        "run",
        "-e",
        "UNIFI_API_KEY",
        "-e",
        "UNIFI_ACCESS_API_KEY",
        "-i",
        "--rm",
        "ghcr.io/pete-builds/mcp-unifi:0.25.0"
      ],
      "env": {
        "UNIFI_API_KEY": "${input:unifi-api-key}",
        "UNIFI_ACCESS_API_KEY": "${input:unifi-access-api-key}"
      }
    }
  },
  "inputs": [
    {
      "type": "promptString",
      "id": "unifi-api-key",
      "description": "UNIFI_API_KEY",
      "password": true
    },
    {
      "type": "promptString",
      "id": "unifi-access-api-key",
      "description": "UNIFI_ACCESS_API_KEY",
      "password": true
    }
  ]
}
```

Needs Docker on your computer.

### Devin Desktop

1. Add it to `~/.config/devin/mcp_config.json` (macOS and Linux) or `%APPDATA%\devin\mcp_config.json` (Windows):

`mcp_config.json`:

```json
{
  "mcpServers": {
    "unifi-gateway": {
      "command": "docker",
      "args": [
        "run",
        "-e",
        "UNIFI_API_KEY",
        "-e",
        "UNIFI_ACCESS_API_KEY",
        "-i",
        "--rm",
        "ghcr.io/pete-builds/mcp-unifi:0.25.0"
      ],
      "env": {
        "UNIFI_API_KEY": "<YOUR_UNIFI_API_KEY>",
        "UNIFI_ACCESS_API_KEY": "<YOUR_UNIFI_ACCESS_API_KEY>"
      }
    }
  }
}
```

2. Refresh the MCP server list in Cascade. Replace the placeholders with your own values.

Devin Desktop is the new name for Windsurf.

### Codex

```bash
codex mcp add unifi-gateway --env "UNIFI_API_KEY=<YOUR_UNIFI_API_KEY>" --env "UNIFI_ACCESS_API_KEY=<YOUR_UNIFI_ACCESS_API_KEY>" -- docker run -i --rm ghcr.io/pete-builds/mcp-unifi:0.25.0
```

Or edit `~/.codex/config.toml` directly:

`config.toml`:

```toml
[mcp_servers.unifi-gateway]
command = "docker"
args = ["run", "-i", "--rm", "ghcr.io/pete-builds/mcp-unifi:0.25.0"]
env = { UNIFI_API_KEY = "<YOUR_UNIFI_API_KEY>", UNIFI_ACCESS_API_KEY = "<YOUR_UNIFI_ACCESS_API_KEY>" }
```

Needs Docker on your computer. Replace the placeholders with your own values.

### Gemini CLI

```bash
gemini mcp add -e "UNIFI_API_KEY=<YOUR_UNIFI_API_KEY>" -e "UNIFI_ACCESS_API_KEY=<YOUR_UNIFI_ACCESS_API_KEY>" unifi-gateway docker -- run -i --rm ghcr.io/pete-builds/mcp-unifi:0.25.0
```

This adds it to the current project. Add `-s user` to use it everywhere.

### Any client

Most clients that start local servers accept this shape:

```json
{
  "mcpServers": {
    "unifi-gateway": {
      "command": "docker",
      "args": [
        "run",
        "-e",
        "UNIFI_API_KEY",
        "-e",
        "UNIFI_ACCESS_API_KEY",
        "-i",
        "--rm",
        "ghcr.io/pete-builds/mcp-unifi:0.25.0"
      ],
      "env": {
        "UNIFI_API_KEY": "<YOUR_UNIFI_API_KEY>",
        "UNIFI_ACCESS_API_KEY": "<YOUR_UNIFI_ACCESS_API_KEY>"
      }
    }
  }
}
```

Zed puts servers under `context_servers` in its settings, with the same `command`, `args` and `env` fields.

Needs Docker on your computer. Replace the placeholders with your own values.

## Details

- Server version: 0.25.0
- Last checked: 2026-10-04
- Listed: 2026-10-04
- Updated: 2026-10-04

---
Source: https://mcp.tc/i/unifi-gateway (mcp.tc is an independent directory, not affiliated with this server's publisher). Corrections: https://mcp.tc/report
