Netbird

by aantti

28 stars
370 downloads
Not rated
GitHub

About

Integrates with Netbird's API to enable virtual private network management including peer listing, group configuration, and access policy control

Details

Author
aantti
Repository
aantti/mcp-netbird
GitHub stars
28
Downloads
370
License
Apache License 2.0
Categories
Cloud Service, Community, Other, Design, Developer Tools, AI, API, Infrastructure
Tags
#integration

This server uses the Netbird API to provide LLMs information about Netbird network. Currently it's a 1:1 mapping of select read-only Netbird API resources to tools.

- [x] Uses Netbird API to access configuration and status
- [x] Configurable API endpoint
- [x] Secure token-based authentication for Netbird API

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Netbird
    Command (node, npx, python, etc.) mcp-netbird
    Environment
    • NETBIRD_API_TOKEN <your-api-token>

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

1. Get your Netbird API token from the Netbird management console.

2. Install the mcp-netbird binary using one of the installation methods above. Make sure the binary is in your PATH.

3. Add the server configuration to your client configuration file. E.g., for Codeium Windsurf add the following to ~/.codeium/windsurf/mcp_config.json:

   {
     "mcpServers": {
       "netbird": {
         "command": "mcp-netbird",
         "args": [],
         "env": {
           "NETBIRD_API_TOKEN": "<your-api-token>"
         }
       }
     }
   }
   

For more information on how to add a similar configuration to Claude Desktop, see here.

> Note: if you see something along the lines of [netbird] [error] spawn mcp-netbird ENOENT in Claude Desktop logs, you need to specify the full path to mcp-netbird. On macOS Claude Logs are in ~/Library/Logs/Claude.

4. Try asking questions along the lines of "Can you explain my Netbird peers, groups and policies to me?"

claude-desktop-mcp-netbird

cd mcp-netbird && \
make install
go install github.com/aantti/mcp-netbird/cmd/mcp-netbird@latest

smithery badge

To install Netbird MCP Server for Claude Desktop automatically via Smithery:

npx -y @smithery/cli install @aantti/mcp-netbird --client claude

list_netbird_peers

Retrieve a list of all peers in the Netbird network.

list_netbird_port_allocations

Retrieve all ingress ports allocated for a specific peer identified by `peerId`.

list_netbird_groups

Retrieve a list of all groups in the Netbird network.

list_netbird_policies

Retrieve a list of all policies configured in the Netbird network.

list_netbird_posture_checks

Retrieve a list of all posture checks defined in the Netbird network.

list_netbird_networks

Retrieve a list of all networks in the Netbird environment.

list_netbird_nameservers

Retrieve all nameserver groups associated with the Netbird network.

| Tool | Description | Netbird API |
| --- | --- | --- |
| list_netbird_peers | All peers | List all Peers |
| list_netbird_port_allocations | All ingress ports for peerId | List all Port Allocations |
| list_netbird_groups | All groups | List all Groups |
| list_netbird_policies | All policies | List all Policies |
| list_netbird_posture_checks | All posture checks | List all Posture Checks |
| list_netbird_networks | All networks | List all Networks |
| list_netbird_nameservers | All nameserver groups | List all Nameserver Groups |

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "netbird": {
            "env": {
                "NETBIRD_API_TOKEN": "<your-api-token>"
            },
            "args": [],
            "command": "mcp-netbird"
        }
    }
}

Linux

{
    "env": {
        "NETBIRD_API_TOKEN": "<your-api-token>"
    },
    "args": [],
    "command": "mcp-netbird"
}

Macos

{
    "env": {
        "NETBIRD_API_TOKEN": "<your-api-token>"
    },
    "args": [],
    "command": "mcp-netbird"
}

Windows

{
    "env": {
        "NETBIRD_API_TOKEN": "<your-api-token>"
    },
    "args": [],
    "command": "mcp-netbird"
}

Netbird MCP Server

A Model Context Protocol (MCP) server for Netbird.

This project is derived from the MCP Server for Grafana by Grafana Labs and is licensed under the same Apache License 2.0.

It also uses MCP Go by Mark III Labs.

Note: this project is still in development.

Installing

Installing from source

Clone the repository

git clone https://github.com/aantti/mcp-netbird

Build and install

cd mcp-netbird && \
make install

Installing from GitHub

go install github.com/aantti/mcp-netbird/cmd/mcp-netbird@latest

Installing via Smithery

smithery badge

To install Netbird MCP Server for Claude Desktop automatically via Smithery:

npx -y @smithery/cli install @aantti/mcp-netbird --client claude

Configuration

The server requires the following environment variables:

- NETBIRD_API_TOKEN: Your Netbird API token
- NETBIRD_HOST (optional): The Netbird API host (default is api.netbird.io)

Features

This server uses the Netbird API to provide LLMs information about Netbird network. Currently it's a 1:1 mapping of select read-only Netbird API resources to tools.

- [x] Uses Netbird API to access configuration and status
- [x] Configurable API endpoint
- [x] Secure token-based authentication for Netbird API

Tools

| Tool | Description | Netbird API |
| --- | --- | --- |
| list_netbird_peers | All peers | List all Peers |
| list_netbird_port_allocations | All ingress ports for peerId | List all Port Allocations |
| list_netbird_groups | All groups | List all Groups |
| list_netbird_policies | All policies | List all Policies |
| list_netbird_posture_checks | All posture checks | List all Posture Checks |
| list_netbird_networks | All networks | List all Networks |
| list_netbird_nameservers | All nameserver groups | List all Nameserver Groups |

Adding tools

To add new tools:

1. Create a new file in tools (e.g., tools/users.go), possibly use existing code as a template
2. Add API route and response specifics to the new file
3. Add the tool to func newServer() in cmd/main.go

Usage

1. Get your Netbird API token from the Netbird management console.

2. Install the mcp-netbird binary using one of the installation methods above. Make sure the binary is in your PATH.

3. Add the server configuration to your client configuration file. E.g., for Codeium Windsurf add the following to ~/.codeium/windsurf/mcp_config.json:

   {
     "mcpServers": {
       "netbird": {
         "command": "mcp-netbird",
         "args": [],
         "env": {
           "NETBIRD_API_TOKEN": "<your-api-token>"
         }
       }
     }
   }
   

For more information on how to add a similar configuration to Claude Desktop, see here.

> Note: if you see something along the lines of [netbird] [error] spawn mcp-netbird ENOENT in Claude Desktop logs, you need to specify the full path to mcp-netbird. On macOS Claude Logs are in ~/Library/Logs/Claude.

4. Try asking questions along the lines of "Can you explain my Netbird peers, groups and policies to me?"

claude-desktop-mcp-netbird

Docker

Build an image and tag it:

docker build -t mcp-netbird-sse:v1 -f Dockerfile.sse .

Run the image:

docker run --name mcp-netbird -p 8001:8001 -e NETBIRD_API_TOKEN=<your-api-token> mcp-netbird-sse:v1

ToolHive

ToolHive (thv) is a lightweight utility designed to simplify the deployment and management of MCP servers.

You can use ToolHive to deploy and run Netbird MCP as follows:

1. Install thv as described in ToolHive README.

2. Add Netbird API token to thv secrets:

thv secret set netbird

3. Build an SSE image as described in the Docker section above

4. Start Netbird MCP with thv run on port 8080:

thv run --secret netbird,target=NETBIRD_API_TOKEN --transport sse --name thv-mcp-netbird --port 8080 --target-port 8001 mcp-netbird-sse:v1

5. When you want to stop the server, use:

thv stop thv-mcp-netbird

Development

Contributions are welcome! Please open an issue or submit a pull request if you have any suggestions or improvements.

This project is written in Go. Install Go following the instructions for your platform.

To run the server manually, use:

export NETBIRD_API_TOKEN=your-token && \
go run cmd/mcp-netbird/main.go

Or in SSE mode:

export NETBIRD_API_TOKEN=your-token && \
go run cmd/mcp-netbird/main.go --transport sse --sse-address :8001

Debugging

The MCP Inspector is an interactive developer tool for testing and debugging MCP servers. Read more about it here.

Here's how to start the MCP Inspector:

export NETBIRD_API_TOKEN=your-token && \
npx @modelcontextprotocol/inspector

Netbird MCP Server can then be tested with either stdio or SSE transport type. For stdio specify the full path to mcp-netbird in the UI.

Testing

TODO: add more tests

Linting

To lint the code, run:

make lint

License

This project is licensed under the Apache License, Version 2.0.

This project includes software developed at Grafana Labs (https://grafana.com/).

This project includes software developed at Mark III Labs (https://github.com/mark3labs/mcp-go).

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.