MikroMCP

by alikarami

424 downloads Not rated yet
GitHub

About

AI-native network automation for MikroTik RouterOS. MikroMCP exposes RouterOS as a typed, auditable Model Context Protocol server so Claude, Cursor, Codex, and other MCP clients can inspect, diagnose, and safely operate MikroTik routers in natural language.

Explore

- RouterOS operational inspection
- Firewall and security auditing
- Interface and routing analysis
- DHCP, WireGuard, and BGP workflows
- AI-assisted troubleshooting
- Natural-language operational workflows
- Docker support and npm distribution
- Claude, Cursor, and Codex compatibility
- Production-oriented architecture

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name MikroMCP
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

Install via npm using npx -y mikromcp or deploy using Docker. Once running, configure your MCP-compatible AI client to connect to the MikroMCP server.

get_system_status

Retrieve system status information from a MikroTik router including resource usage, identity, license, routerboard details, health sensors, and clock.

list_interfaces

List network interfaces on a MikroTik router with optional filtering by type and status. Supports pagination and optional traffic counters.

manage_ip_address

Add, update, or remove an IP address on a MikroTik router interface. Performs idempotency checks for add operations and supports dry-run mode for all actions.

list_dhcp_leases

List DHCP leases on a MikroTik router with optional filtering by server, status, lease type (dynamic/static), and MAC address. Supports pagination.

manage_dhcp_lease

Convert a dynamic DHCP lease to static (make-static) or remove a lease. Idempotent by MAC address.

list_routes

List static routes on a MikroTik router with optional filtering by active status and dynamic status. Supports pagination.

manage_route

Add or remove a static route on a MikroTik router. Performs idempotency checks for add operations and supports dry-run mode for all actions.

list_firewall_rules

List firewall rules from the filter or nat table on a MikroTik router. Supports filtering by chain and disabled state, with pagination.

manage_firewall_rule

Add, remove, disable, or enable a firewall rule on a MikroTik router. Uses comment as idempotency key for deduplication and identification. Supports dry-run mode.

ping

Send ICMP echo requests from the router to a target address. Returns per-packet RTT and summary statistics. 100% packet loss is a valid result, not an error.

traceroute

Trace the network path from the router to a target address. Returns an ordered hop list with RTT per hop. Timeouts and partial results are valid responses.

torch

Capture a real-time traffic snapshot on a router interface. The tool call blocks for the duration (seconds) and returns top flows by bytes. readOnlyHint true — auto-retry enabled.

get_log

Read and filter the system log from a MikroTik router. Supports filtering by topic, message prefix, and a time window (last N minutes) measured against the router's own clock. Entries with unparseable timestamps are included conservatively.

get_system_clock

Read the current date, time, and timezone from a MikroTik router. Focused single-purpose alternative to the clock section in get_system_status.

set_system_clock

Set the system date, time, and/or timezone on a MikroTik router. Idempotent: returns already_set if the values already match. Supports dry-run.

reboot

Trigger a controlled router reboot with an optional delay. Supports dry-run. Use this tool instead of run_command for reboots — run_command's deny list blocks /system reboot*.

run_command

Execute an arbitrary RouterOS console command via SSH. Guarded by an allow/deny policy (built-in deny list blocks destructive commands; tighten via cmdAllow in routers.yaml or MIKROMCP_CMD_ALLOW). Prefer dedicated tools (reboot, etc.) where available. Output capped at 4000 characters.

list_bridges

List bridge interfaces and their port members on a MikroTik router.

manage_bridge

Create or remove a bridge interface on a MikroTik router. Idempotent: create returns already_exists if bridge with same name exists.

manage_bridge_port

Add or remove an interface from a bridge on a MikroTik router. Idempotent: add returns already_exists if the port assignment already exists.

list_wifi_interfaces

List WiFi/wireless interfaces on a MikroTik router. Uses /interface/wifi on ROS 7.x, /interface/wireless on older versions.

list_wifi_clients

List currently connected WiFi clients (stations) with signal strength and transfer rates.

manage_wifi_interface

Enable, disable, or update SSID settings on a WiFi interface. At least one of disabled or ssid must be provided.

list_wireguard_interfaces

List WireGuard interfaces and their status on a MikroTik router.

list_wireguard_peers

List WireGuard peers with last handshake time and transfer statistics.

manage_wireguard_peer

Add or remove a WireGuard peer. Idempotent by public key: add returns already_exists if a peer with the same public key already exists on the interface.

manage_wireguard_interface

Add, remove, enable, or disable a WireGuard interface. Idempotent by name. RouterOS generates the private key on create — it is never passed in. The public key is returned after creation.

list_dns_entries

List static DNS entries on a MikroTik router with optional filtering by name and type.

manage_dns_entry

Add or remove a static DNS entry. Idempotent by name+type: add returns already_exists if the same record already exists.

get_dns_settings

Read DNS resolver configuration: upstream servers, cache size, cache TTL, and whether remote DNS requests are allowed.

manage_dns_settings

Update DNS resolver settings (upstream servers, cache size, cache TTL, allow-remote-requests). Idempotent: returns no_change if nothing differs.

list_mangle_rules

List firewall mangle rules on a MikroTik router in evaluation order. Supports filtering by chain, action, and disabled state.

manage_mangle_rule

Add, remove, enable, or disable a firewall mangle rule. Uses comment as idempotency key. Supports dry-run mode.

list_address_list_entries

List firewall address list entries on a MikroTik router. Supports filtering by list name and address.

manage_address_list_entry

Add or remove a firewall address list entry. Idempotent by list name + address. Supports dry-run mode.

list_routing_rules

List policy routing rules on a MikroTik router in evaluation order. Supports filtering by table and disabled state.

manage_routing_rule

Add, remove, enable, or disable a policy routing rule. Idempotent by srcAddress+dstAddress+interface+table composite key. Supports dry-run mode.

list_routing_tables

List custom routing tables on a MikroTik router.

manage_routing_table

Create or remove a custom routing table. Idempotent by table name. Supports dry-run mode.

list_bgp_peers

List BGP sessions on a MikroTik router (RouterOS 7+). Returns state, remote AS, prefix counts, and uptime.

list_ospf_neighbors

List OSPF neighbors on a MikroTik router (RouterOS 7+). Returns neighbor state, interface, DR/BDR, and uptime.

list_scripts

List RouterOS scripts on a MikroTik router. Supports optional name filter.

manage_script

Add, update, or remove a RouterOS script. Idempotent by name. add throws CONFLICT if the name already exists; update throws NOT_FOUND if it does not. Supports dry-run.

run_script

Execute a named RouterOS script. Fire-and-forget — the script runs asynchronously and its output is written to the router system log. Use get_log after calling this tool to see results.

list_scheduled_jobs

List RouterOS scheduler entries on a MikroTik router with next-run time, interval, and disabled state.

manage_scheduled_job

Add, update, remove, enable, or disable a RouterOS scheduler entry. Idempotent by name. add throws CONFLICT if name exists; update throws NOT_FOUND if it does not. Supports dry-run.

list_packages

List installed RouterOS packages with version and enabled status.

manage_package

Enable or disable a RouterOS package. Changes take effect only after a router reboot — use the reboot tool to apply. Idempotent: no-op if already in the target state.

list_files

List files on a MikroTik router filesystem. Supports filtering by name and type.

get_file_content

Read a text file's contents from a MikroTik router. Only suitable for text files — binary files will return garbled content.

upload_file

Upload a text file to a router, overwriting any existing file of the same name. Prefers SFTP (encrypted, over SSH) and falls back to plaintext FTP if SFTP is unavailable. Requires SSH (or FTP) access for the router user. Dry-run tests connectivity only.

delete_file

Delete a file from the router filesystem by name. Idempotent: returns not_found gracefully if the file does not exist.

list_containers

List RouterOS container instances with status, image, and network information.

manage_container

Create, start, stop, or remove a RouterOS container. create needs a pre-configured veth interface; start/stop are no-ops when already in the target state; remove throws NOT_FOUND when absent. Supports dry-run.

list_ipsec_peers

List IPSec peers on a MikroTik router.

list_ipsec_policies

List IPSec policies on a MikroTik router.

manage_ipsec_peer

Add, remove, enable, or disable an IPSec peer. Idempotent by name: add returns already_exists if a peer with the same name and address already exists.

manage_ipsec_policy

Add, remove, enable, or disable an IPSec policy. Idempotent by composite key (srcAddress + dstAddress + tunnel).

list_certificates

List certificates on a MikroTik router.

manage_certificate

Remove, trust, or untrust a certificate. Idempotent: trust/untrust return early if already in the target state.

list_users

List local users on a MikroTik router. Passwords are never returned.

manage_user

Add, remove, enable, disable, or set the password for a local RouterOS user. Idempotent by name: add returns already_exists if a user with the same name and group already exists.

list_user_groups

List local user groups on a MikroTik router.

manage_user_group

Add, update, or remove a local RouterOS user group. Idempotent by name: add returns already_exists if a group with the same name and policy already exists.

list_dhcp_servers

List DHCP servers on a MikroTik router.

manage_dhcp_server

Add, remove, enable, or disable a DHCP server. Idempotent by name: add returns already_exists if a server with the same name, interface, and address pool already exists.

list_ip_pools

List IP address pools on a MikroTik router. Supports filtering by name and pagination.

manage_ip_pool

Add or remove an IP address pool. Idempotent by name: add returns already_exists if a pool with the same name and ranges already exists.

list_queues

List simple queues on a MikroTik router.

manage_queue

Add, remove, enable, or disable a simple queue. Idempotent by name: add returns already_exists if a queue with the same name and target already exists.

list_vrrp_instances

List VRRP instances on a MikroTik router.

manage_vrrp_instance

Add, remove, enable, or disable a VRRP instance. Idempotent by name: add returns already_exists if an instance with the same name, interface, and VRID already exists.

get_snmp_settings

Retrieve SNMP settings from a MikroTik router.

get_ntp_settings

Retrieve NTP client settings from a MikroTik router.

list_netwatch_entries

List Netwatch monitoring entries on a MikroTik router.

manage_netwatch_entry

Add, remove, enable, or disable a Netwatch monitoring entry. Idempotent by host+port: add returns already_exists if an entry with the same host and port already exists.

list_neighbors

List discovered neighbors (CDP/LLDP/MNDP) on a MikroTik router.

list_arp_entries

List ARP table entries on a MikroTik router.

manage_ntp_client

Update NTP client settings on a MikroTik router. Idempotent: returns already_set if no changes are needed.

manage_vlan

Add, remove, enable, or disable a VLAN interface. Idempotent by name: add returns already_exists when a VLAN with matching name, vlan-id, and parent interface exists. Supports dry-run mode.

list_dhcp_clients

List DHCP client configurations on a MikroTik router. Shows which interfaces obtain their IP via DHCP, current status, and assigned address.

manage_dhcp_client

Add, remove, enable, or disable a DHCP client on an interface. Idempotent by interface name: add returns already_exists if a DHCP client is already configured on the same interface.

list_ip_services

List IP services on a MikroTik router (api, api-ssl, ssh, telnet, www, www-ssl, winbox, ftp) with their port numbers and enabled/disabled status.

manage_ip_service

Enable or disable a RouterOS IP service (api, api-ssl, ssh, telnet, www, www-ssl, winbox, ftp). Port number changes are intentionally not supported to prevent accidental lockout.

list_pppoe_clients

List PPPoE client interfaces on a MikroTik router. Shows name, parent interface, ISP username, and connection status.

manage_pppoe_client

Add, update, or remove a PPPoE client interface. Idempotent by name (already_exists on matching name+interface+user; CONFLICT on differing config; no_change when an update differs in nothing). Password is always written when provided since RouterOS does not return it on GET.

list_ovpn_clients

List OpenVPN client interfaces on a MikroTik router. Shows name, remote server, and connection status.

manage_ovpn_client

Add, update, or remove an OpenVPN client interface. Idempotent by name (already_exists on matching name+connectTo; CONFLICT on differing connectTo; no_change when an update differs in nothing). Password is always written when provided since RouterOS does not return it on GET.

get_ovpn_server

Get the OpenVPN server configuration on a MikroTik router. Throws NOT_FOUND if the OpenVPN package is not installed.

manage_ovpn_server

Enable, disable, or configure the OpenVPN server (a per-router singleton). Throws NOT_FOUND if the OpenVPN package is not installed. The set action requires at least one configuration field.

list_ppp_profiles

List PPP profiles including the built-in default and default-encryption profiles.

manage_ppp_profile

Add, update, or remove a PPP profile. Idempotent by name. update returns no_change when requested values match. Built-in profiles (default, default-encryption) cannot be removed — RouterOS blocks this and the error is surfaced.

get_upgrade_status

Read the current RouterOS package upgrade status and routerboard firmware versions. Shows installed version, latest available version, update channel, and firmware upgrade availability.

manage_upgrade

Trigger a RouterOS package update check or install. 'check' queries the update server for new packages. 'install' downloads and applies the update — the router will reboot automatically. Supports dry-run.

create_backup

Create a binary configuration backup on a MikroTik router. The backup is saved as <name>.backup on the router's filesystem. Supports optional encryption via password and dry-run mode.

export_config

Export the router configuration as a RouterOS script. When no file is specified, returns the script text inline. When a file is specified, saves it as <file>.rsc on the router's filesystem. Supports compact mode to show only non-default values.

list_log_rules

List RouterOS logging rules (system/logging) with optional topic substring and action exact-match filtering.

manage_log_rule

Add, remove, enable, or disable a RouterOS logging rule. Idempotent by topics+logAction (add → already_exists on match; remove → not_found handled gracefully; enable/disable throw NOT_FOUND when absent). Supports dry-run.

list_log_actions

List RouterOS logging action targets (system/logging/action) with optional type filter.

manage_log_action

Add or remove a RouterOS logging action target. Idempotent by name. add throws VALIDATION if type is missing; returns already_exists if name found. remove returns not_found gracefully. Supports dry-run.

bandwidth_test

Run a RouterOS bandwidth test from the router to a remote host running a RouterOS btest server. Returns TX and RX throughput in Mbps. Duration capped at 20 seconds. Saturates the link — not auto-retried.

fetch_url

Send an HTTP/HTTPS request from the router using /tool/fetch. Response body is returned inline (capped at 64 KB with [TRUNCATED] marker). Use outputFile to save to router filesystem instead. Not read-only: POSTs have side effects and outputFile writes to the router.

list_connections

List active connection tracking entries from the router firewall table. Filters are applied client-side. Useful for diagnosing NAT and firewall behavior.

get_container_config

Read global container configuration: registry URL, RAM high-water mark, and veth interface.

manage_container_config

Update global container settings. Idempotent: returns no_change if nothing differs.

list_container_envs

List container environment variable entries, optionally filtered by container name.

manage_container_env

Add or remove a container environment variable. Idempotent by name+key. add returns already_exists if the entry exists with the same value; throws CONFLICT if the value differs.

list_container_mounts

List container volume mount definitions with source path, destination path, and mount name.

manage_container_mount

Add or remove a container volume mount. Idempotent by name: add returns already_exists if the mount exists with matching src/dst; throws CONFLICT if name exists with different paths.

list_interface_lists

List all interface lists defined on the router.

manage_interface_list

Add or remove an interface list. Idempotent by name. Removing a list that has members is blocked by RouterOS — the error is surfaced as-is.

manage_interface_list_member

Add or remove an interface from an interface list. Idempotent by list+interface composite key. add returns already_exists if the membership exists. remove returns not_found gracefully.

list_swos_endpoints

List the SwOS/SwOS Lite '.b' API endpoints supported by this server, with the decoded field names per endpoint. Read-only schema introspection — no device call.

get_swos_status

Retrieve status from a MikroTik SwOS switch (SwOS or SwOS Lite): identity, model, firmware, uptime, per-port link state/speed/duplex, PoE mode/state/power, and SFP modules.

get_swos_endpoint

Fetch and decode a single SwOS '.b' endpoint (link.b, sys.b, poe.b, lacp.b, rstp.b, snmp.b, fwd.b, vlan.b, stats.b, sfp.b, host.b, acl.b, ...) as structured data. Unknown keys are preserved under '_raw'.

write_swos_blob

Mutate a SwOS '.b' endpoint on a MikroTik switch. The full endpoint blob is read, the given fields are merged in, and the entire blob is written back (the firmware only accepts whole-blob writes); untouched fields are re-sent byte-for-byte, and a field this firmware does not expose is refused rather than injected. dryRun defaults to true — preview first. Every result reports whether the schema has been verified against the switch's firmware. The pre-write blob is snapshotted, so the change can be undone with rollback_change. Returns no_change when the values already match.

plan_changes

Preview a sequence of write operations: each step runs with dryRun=true against live state, returning affected paths and the predicted action per step. Use apply_plan to execute the same steps for real.

apply_plan

Execute write operations in order, stopping on first failure. Each step is snapshotted and journaled individually. Non-admin identities need a confirmationToken (same two-step flow as other destructive tools). Undo individual steps via rollback_change with the returned journal IDs.

rollback_change

Restore device state to before a write, identified by its journal ID. RouterOS: reads the before-snapshot, diffs against live state, and applies the reverse. SwOS: re-POSTs the exact pre-write '.b' blob. Use dryRun=true to preview. Requires MIKROMCP_DATA_DIR (defaults to data/).

check_router_health

Probe a device: RouterOS routers via system/resource, SwOS switches via sys.b. Returns health status, firmware version, uptime, and (RouterOS only) CPU load and memory info. Unlike other tools, this never throws — unreachable devices are reported as healthy=false.

bulk_execute

Fan out a single-router tool to many routers in parallel (up to `concurrency`), targeted by routerIds or tag. Destructive tools need two-step confirmation: call without `confirmationToken` to get a fleet token (needs MIKROMCP_CONFIRMATION_SECRET), then re-call with it. Writes snapshot+journal each router for rollback. Returns per-router results with succeeded/failed counts.

list_routers

List the routers configured in the registry (routers.yaml): id, host, port, TLS status, tags, ROS version, and which is the default. Read-only reflection of local config — no RouterOS API call, no credentials in the response. Use it to discover valid routerId values and tags for targeting other tools (including bulk_execute).

- get_system_status: Retrieve system status information from a MikroTik router including resource usage, identity, license, routerboard details, health sensors, and clock.
- list_interfaces: List network interfaces on a MikroTik router with optional filtering by type and status. Supports pagination and optional traffic counters.
- manage_ip_address: Add, update, or remove an IP address on a MikroTik router interface. Performs idempotency checks for add operations and supports dry-run mode for all actions.
- list_dhcp_leases: List DHCP leases on a MikroTik router with optional filtering by server, status, lease type (dynamic/static), and MAC address. Supports pagination.
- manage_dhcp_lease: Convert a dynamic DHCP lease to static (make-static) or remove a lease. Idempotent by MAC address.
- list_routes: List static routes on a MikroTik router with optional filtering by active status and dynamic status. Supports pagination.
- manage_route: Add or remove a static route on a MikroTik router. Performs idempotency checks for add operations and supports dry-run mode for all actions.
- list_firewall_rules: List firewall rules from the filter or nat table on a MikroTik router. Supports filtering by chain and disabled state, with pagination.
- manage_firewall_rule: Add, remove, disable, or enable a firewall rule on a MikroTik router. Uses comment as idempotency key for deduplication and identification. Supports dry-run mode.
- ping: Send ICMP echo requests from the router to a target address. Returns per-packet RTT and summary statistics. 100% packet loss is a valid result, not an error.
- traceroute: Trace the network path from the router to a target address. Returns an ordered hop list with RTT per hop. Timeouts and partial results are valid responses.
- torch: Capture a real-time traffic snapshot on a router interface. The tool call blocks for the duration (seconds) and returns top flows by bytes. readOnlyHint true — auto-retry enabled.
- get_log: Read and filter the system log from a MikroTik router. Supports filtering by topic, message prefix, and a time window (last N minutes) measured against the router's own clock. Entries with unparseable timestamps are included conservatively.
- get_system_clock: Read the current date, time, and timezone from a MikroTik router. Focused single-purpose alternative to the clock section in get_system_status.
- set_system_clock: Set the system date, time, and/or timezone on a MikroTik router. Idempotent: returns already_set if the values already match. Supports dry-run.
- reboot: Trigger a controlled router reboot with an optional delay. Supports dry-run. Use this tool instead of run_command for reboots — run_command's deny list blocks /system reboot*.
- run_command: Execute an arbitrary RouterOS console command via SSH. Guarded by an allow/deny policy (built-in deny list blocks destructive commands; tighten via cmdAllow in routers.yaml or MIKROMCP_CMD_ALLOW). Prefer dedicated tools (reboot, etc.) where available. Output capped at 4000 characters.
- list_bridges: List bridge interfaces and their port members on a MikroTik router.
- manage_bridge: Create or remove a bridge interface on a MikroTik router. Idempotent: create returns already_exists if bridge with same name exists.
- manage_bridge_port: Add or remove an interface from a bridge on a MikroTik router. Idempotent: add returns already_exists if the port assignment already exists.
- list_wifi_interfaces: List WiFi/wireless interfaces on a MikroTik router. Uses /interface/wifi on ROS 7.x, /interface/wireless on older versions.
- list_wifi_clients: List currently connected WiFi clients (stations) with signal strength and transfer rates.
- manage_wifi_interface: Enable, disable, or update SSID settings on a WiFi interface. At least one of disabled or ssid must be provided.
- list_wireguard_interfaces: List WireGuard interfaces and their status on a MikroTik router.
- list_wireguard_peers: List WireGuard peers with last handshake time and transfer statistics.
- manage_wireguard_peer: Add or remove a WireGuard peer. Idempotent by public key: add returns already_exists if a peer with the same public key already exists on the interface.
- manage_wireguard_interface: Add, remove, enable, or disable a WireGuard interface. Idempotent by name. RouterOS generates the private key on create — it is never passed in. The public key is returned after creation.
- list_dns_entries: List static DNS entries on a MikroTik router with optional filtering by name and type.
- manage_dns_entry: Add or remove a static DNS entry. Idempotent by name+type: add returns already_exists if the same record already exists.
- get_dns_settings: Read DNS resolver configuration: upstream servers, cache size, cache TTL, and whether remote DNS requests are allowed.
- manage_dns_settings: Update DNS resolver settings (upstream servers, cache size, cache TTL, allow-remote-requests). Idempotent: returns no_change if nothing differs.
- list_mangle_rules: List firewall mangle rules on a MikroTik router in evaluation order. Supports filtering by chain, action, and disabled state.
- manage_mangle_rule: Add, remove, enable, or disable a firewall mangle rule. Uses comment as idempotency key. Supports dry-run mode.
- list_address_list_entries: List firewall address list entries on a MikroTik router. Supports filtering by list name and address.
- manage_address_list_entry: Add or remove a firewall address list entry. Idempotent by list name + address. Supports dry-run mode.
- list_routing_rules: List policy routing rules on a MikroTik router in evaluation order. Supports filtering by table and disabled state.
- manage_routing_rule: Add, remove, enable, or disable a policy routing rule. Idempotent by srcAddress+dstAddress+interface+table composite key. Supports dry-run mode.
- list_routing_tables: List custom routing tables on a MikroTik router.
- manage_routing_table: Create or remove a custom routing table. Idempotent by table name. Supports dry-run mode.
- list_bgp_peers: List BGP sessions on a MikroTik router (RouterOS 7+). Returns state, remote AS, prefix counts, and uptime.
- list_ospf_neighbors: List OSPF neighbors on a MikroTik router (RouterOS 7+). Returns neighbor state, interface, DR/BDR, and uptime.
- list_scripts: List RouterOS scripts on a MikroTik router. Supports optional name filter.
- manage_script: Add, update, or remove a RouterOS script. Idempotent by name. add throws CONFLICT if the name already exists; update throws NOT_FOUND if it does not. Supports dry-run.
- run_script: Execute a named RouterOS script. Fire-and-forget — the script runs asynchronously and its output is written to the router system log. Use get_log after calling this tool to see results.
- list_scheduled_jobs: List RouterOS scheduler entries on a MikroTik router with next-run time, interval, and disabled state.
- manage_scheduled_job: Add, update, remove, enable, or disable a RouterOS scheduler entry. Idempotent by name. add throws CONFLICT if name exists; update throws NOT_FOUND if it does not. Supports dry-run.
- list_packages: List installed RouterOS packages with version and enabled status.
- manage_package: Enable or disable a RouterOS package. Changes take effect only after a router reboot — use the reboot tool to apply. Idempotent: no-op if already in the target state.
- list_files: List files on a MikroTik router filesystem. Supports filtering by name and type.
- get_file_content: Read a text file's contents from a MikroTik router. Only suitable for text files — binary files will return garbled content.
- upload_file: Upload a text file to a router, overwriting any existing file of the same name. Prefers SFTP (encrypted, over SSH) and falls back to plaintext FTP if SFTP is unavailable. Requires SSH (or FTP) access for the router user. Dry-run tests connectivity only.
- delete_file: Delete a file from the router filesystem by name. Idempotent: returns not_found gracefully if the file does not exist.
- list_containers: List RouterOS container instances with status, image, and network information.
- manage_container: Create, start, stop, or remove a RouterOS container. create needs a pre-configured veth interface; start/stop are no-ops when already in the target state; remove throws NOT_FOUND when absent. Supports dry-run.
- list_ipsec_peers: List IPSec peers on a MikroTik router.
- list_ipsec_policies: List IPSec policies on a MikroTik router.
- manage_ipsec_peer: Add, remove, enable, or disable an IPSec peer. Idempotent by name: add returns already_exists if a peer with the same name and address already exists.
- manage_ipsec_policy: Add, remove, enable, or disable an IPSec policy. Idempotent by composite key (srcAddress + dstAddress + tunnel).
- list_certificates: List certificates on a MikroTik router.
- manage_certificate: Remove, trust, or untrust a certificate. Idempotent: trust/untrust return early if already in the target state.
- list_users: List local users on a MikroTik router. Passwords are never returned.
- manage_user: Add, remove, enable, disable, or set the password for a local RouterOS user. Idempotent by name: add returns already_exists if a user with the same name and group already exists.
- list_user_groups: List local user groups on a MikroTik router.
- manage_user_group: Add, update, or remove a local RouterOS user group. Idempotent by name: add returns already_exists if a group with the same name and policy already exists.
- list_dhcp_servers: List DHCP servers on a MikroTik router.
- manage_dhcp_server: Add, remove, enable, or disable a DHCP server. Idempotent by name: add returns already_exists if a server with the same name, interface, and address pool already exists.
- list_ip_pools: List IP address pools on a MikroTik router. Supports filtering by name and pagination.
- manage_ip_pool: Add or remove an IP address pool. Idempotent by name: add returns already_exists if a pool with the same name and ranges already exists.
- list_queues: List simple queues on a MikroTik router.
- manage_queue: Add, remove, enable, or disable a simple queue. Idempotent by name: add returns already_exists if a queue with the same name and target already exists.
- list_vrrp_instances: List VRRP instances on a MikroTik router.
- manage_vrrp_instance: Add, remove, enable, or disable a VRRP instance. Idempotent by name: add returns already_exists if an instance with the same name, interface, and VRID already exists.
- get_snmp_settings: Retrieve SNMP settings from a MikroTik router.
- get_ntp_settings: Retrieve NTP client settings from a MikroTik router.
- list_netwatch_entries: List Netwatch monitoring entries on a MikroTik router.
- manage_netwatch_entry: Add, remove, enable, or disable a Netwatch monitoring entry. Idempotent by host+port: add returns already_exists if an entry with the same host and port already exists.
- list_neighbors: List discovered neighbors (CDP/LLDP/MNDP) on a MikroTik router.
- list_arp_entries: List ARP table entries on a MikroTik router.
- manage_ntp_client: Update NTP client settings on a MikroTik router. Idempotent: returns already_set if no changes are needed.
- manage_vlan: Add, remove, enable, or disable a VLAN interface. Idempotent by name: add returns already_exists when a VLAN with matching name, vlan-id, and parent interface exists. Supports dry-run mode.
- list_dhcp_clients: List DHCP client configurations on a MikroTik router. Shows which interfaces obtain their IP via DHCP, current status, and assigned address.
- manage_dhcp_client: Add, remove, enable, or disable a DHCP client on an interface. Idempotent by interface name: add returns already_exists if a DHCP client is already configured on the same interface.
- list_ip_services: List IP services on a MikroTik router (api, api-ssl, ssh, telnet, www, www-ssl, winbox, ftp) with their port numbers and enabled/disabled status.
- manage_ip_service: Enable or disable a RouterOS IP service (api, api-ssl, ssh, telnet, www, www-ssl, winbox, ftp). Port number changes are intentionally not supported to prevent accidental lockout.
- list_pppoe_clients: List PPPoE client interfaces on a MikroTik router. Shows name, parent interface, ISP username, and connection status.
- manage_pppoe_client: Add, update, or remove a PPPoE client interface. Idempotent by name (already_exists on matching name+interface+user; CONFLICT on differing config; no_change when an update differs in nothing). Password is always written when provided since RouterOS does not return it on GET.
- list_ovpn_clients: List OpenVPN client interfaces on a MikroTik router. Shows name, remote server, and connection status.
- manage_ovpn_client: Add, update, or remove an OpenVPN client interface. Idempotent by name (already_exists on matching name+connectTo; CONFLICT on differing connectTo; no_change when an update differs in nothing). Password is always written when provided since RouterOS does not return it on GET.
- get_ovpn_server: Get the OpenVPN server configuration on a MikroTik router. Throws NOT_FOUND if the OpenVPN package is not installed.
- manage_ovpn_server: Enable, disable, or configure the OpenVPN server (a per-router singleton). Throws NOT_FOUND if the OpenVPN package is not installed. The set action requires at least one configuration field.
- list_ppp_profiles: List PPP profiles including the built-in default and default-encryption profiles.
- manage_ppp_profile: Add, update, or remove a PPP profile. Idempotent by name. update returns no_change when requested values match. Built-in profiles (default, default-encryption) cannot be removed — RouterOS blocks this and the error is surfaced.
- get_upgrade_status: Read the current RouterOS package upgrade status and routerboard firmware versions. Shows installed version, latest available version, update channel, and firmware upgrade availability.
- manage_upgrade: Trigger a RouterOS package update check or install. 'check' queries the update server for new packages. 'install' downloads and applies the update — the router will reboot automatically. Supports dry-run.
- create_backup: Create a binary configuration backup on a MikroTik router. The backup is saved as <name>.backup on the router's filesystem. Supports optional encryption via password and dry-run mode.
- export_config: Export the router configuration as a RouterOS script. When no file is specified, returns the script text inline. When a file is specified, saves it as <file>.rsc on the router's filesystem. Supports compact mode to show only non-default values.
- list_log_rules: List RouterOS logging rules (system/logging) with optional topic substring and action exact-match filtering.
- manage_log_rule: Add, remove, enable, or disable a RouterOS logging rule. Idempotent by topics+logAction (add → already_exists on match; remove → not_found handled gracefully; enable/disable throw NOT_FOUND when absent). Supports dry-run.
- list_log_actions: List RouterOS logging action targets (system/logging/action) with optional type filter.
- manage_log_action: Add or remove a RouterOS logging action target. Idempotent by name. add throws VALIDATION if type is missing; returns already_exists if name found. remove returns not_found gracefully. Supports dry-run.
- bandwidth_test: Run a RouterOS bandwidth test from the router to a remote host running a RouterOS btest server. Returns TX and RX throughput in Mbps. Duration capped at 20 seconds. Saturates the link — not auto-retried.
- fetch_url: Send an HTTP/HTTPS request from the router using /tool/fetch. Response body is returned inline (capped at 64 KB with [TRUNCATED] marker). Use outputFile to save to router filesystem instead. Not read-only: POSTs have side effects and outputFile writes to the router.
- list_connections: List active connection tracking entries from the router firewall table. Filters are applied client-side. Useful for diagnosing NAT and firewall behavior.
- get_container_config: Read global container configuration: registry URL, RAM high-water mark, and veth interface.
- manage_container_config: Update global container settings. Idempotent: returns no_change if nothing differs.
- list_container_envs: List container environment variable entries, optionally filtered by container name.
- manage_container_env: Add or remove a container environment variable. Idempotent by name+key. add returns already_exists if the entry exists with the same value; throws CONFLICT if the value differs.
- list_container_mounts: List container volume mount definitions with source path, destination path, and mount name.
- manage_container_mount: Add or remove a container volume mount. Idempotent by name: add returns already_exists if the mount exists with matching src/dst; throws CONFLICT if name exists with different paths.
- list_interface_lists: List all interface lists defined on the router.
- manage_interface_list: Add or remove an interface list. Idempotent by name. Removing a list that has members is blocked by RouterOS — the error is surfaced as-is.
- manage_interface_list_member: Add or remove an interface from an interface list. Idempotent by list+interface composite key. add returns already_exists if the membership exists. remove returns not_found gracefully.
- list_swos_endpoints: List the SwOS/SwOS Lite '.b' API endpoints supported by this server, with the decoded field names per endpoint. Read-only schema introspection — no device call.
- get_swos_status: Retrieve status from a MikroTik SwOS switch (SwOS or SwOS Lite): identity, model, firmware, uptime, per-port link state/speed/duplex, PoE mode/state/power, and SFP modules.
- get_swos_endpoint: Fetch and decode a single SwOS '.b' endpoint (link.b, sys.b, poe.b, lacp.b, rstp.b, snmp.b, fwd.b, vlan.b, stats.b, sfp.b, host.b, acl.b, ...) as structured data. Unknown keys are preserved under '_raw'.
- write_swos_blob: Mutate a SwOS '.b' endpoint on a MikroTik switch. The full endpoint blob is read, the given fields are merged in, and the entire blob is written back (the firmware only accepts whole-blob writes); untouched fields are re-sent byte-for-byte, and a field this firmware does not expose is refused rather than injected. dryRun defaults to true — preview first. Every result reports whether the schema has been verified against the switch's firmware. The pre-write blob is snapshotted, so the change can be undone with rollback_change. Returns no_change when the values already match.
- plan_changes: Preview a sequence of write operations: each step runs with dryRun=true against live state, returning affected paths and the predicted action per step. Use apply_plan to execute the same steps for real.
- apply_plan: Execute write operations in order, stopping on first failure. Each step is snapshotted and journaled individually. Non-admin identities need a confirmationToken (same two-step flow as other destructive tools). Undo individual steps via rollback_change with the returned journal IDs.
- rollback_change: Restore device state to before a write, identified by its journal ID. RouterOS: reads the before-snapshot, diffs against live state, and applies the reverse. SwOS: re-POSTs the exact pre-write '.b' blob. Use dryRun=true to preview. Requires MIKROMCP_DATA_DIR (defaults to data/).
- check_router_health: Probe a device: RouterOS routers via system/resource, SwOS switches via sys.b. Returns health status, firmware version, uptime, and (RouterOS only) CPU load and memory info. Unlike other tools, this never throws — unreachable devices are reported as healthy=false.
- bulk_execute: Fan out a single-router tool to many routers in parallel (up to concurrency), targeted by routerIds or tag. Destructive tools need two-step confirmation: call without confirmationToken to get a fleet token (needs MIKROMCP_CONFIRMATION_SECRET), then re-call with it. Writes snapshot+journal each router for rollback. Returns per-router results with succeeded/failed counts.
- list_routers: List the routers configured in the registry (routers.yaml): id, host, port, TLS status, tags, ROS version, and which is the default. Read-only reflection of local config — no RouterOS API call, no credentials in the response. Use it to discover valid routerId values and tags for targeting other tools (including bulk_execute).

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "mikromcp": {
            "server": {
                "command": "npx",
                "args": [
                    "-y",
                    "mikromcp"
                ],
                "env": {
                    "MIKROMCP_CONFIG_PATH": "",
                    "MIKROMCP_STDIO_IDENTITY": "",
                    "MIKROMCP_LOG_LEVEL": ""
                }
            }
        }
    }
}

McpServers

{
    "server": {
        "command": "npx",
        "args": [
            "-y",
            "mikromcp"
        ],
        "env": {
            "MIKROMCP_CONFIG_PATH": "",
            "MIKROMCP_STDIO_IDENTITY": "",
            "MIKROMCP_LOG_LEVEL": ""
        }
    }
}

Transport

"stdio"

Package

"mikromcp"

Registry

"npm"

AI-native network automation for MikroTik RouterOS.MikroMCP exposes RouterOS as a typed, auditableModel Context Protocolserver so Claude, Cursor, Codex, and other MCP clients can inspect, diagnose, and safely operate MikroTik routers in natural language.

MikroMCP exists because raw router CLI access is the wrong abstraction for AI agents. RouterOS is powerful, but asking an LLM to improvise shell commands against production network gear is risky. MikroMCP gives agents a controlled tool surface: strict schemas, idempotent writes, dry-run previews, per-router circuit breakers, retry policies, RBAC, audit logs, snapshots, and rollback-aware change workflows.

In one sentence:MikroMCP turns MikroTik RouterOS into a production-minded MCP control plane for AI infrastructure, DevOps automation, and modern router management.

That's the whole setup for a single-router stdio deployment. For standalone binaries, Docker, HTTP/SSE mode, the RouterOS API prerequisites, and the full 15-minute walkthrough, see theGetting Started guide.

122 typed toolsin total — browse the full catalog with parameters, defaults, and copy-paste example prompts inAvailable Tools.

Use MikroMCP to inspect core-01. Summarize system resources, RouterOS version, running interfaces, active routes, DNS settings, and recent warning/error logs. Flag anything that looks operationally risky.
List firewall filter and NAT rules on edge-01. Identify disabled rules, overlapping port forwards, broad accept rules, and anything without comments. Do not change anything yet.
Dry-run a route on core-01 for 10.20.0.0/16 via 192.168.88.1 in the main table. Show the exact planned diff and tell me whether an existing route conflicts.
Show WireGuard peers on branch-02. Sort by last handshake age and flag peers that have not handshaken recently or have no transfer counters.
Check interface health on edge-01, then run ping and traceroute from the router to 1.1.1.1. If packet loss is present, use torch on the WAN interface for a short traffic snapshot.
Create a change plan that adds a DNS record and a firewall address-list entry on edge-01. Use dry-run first, explain the plan, then wait for approval before applying anything.

MCP gives LLMs a standard way to call tools. MikroMCP makes RouterOS a high-quality MCP target by turning network operations into well-described, machine-readable, permission-aware actions.

- Investigate router state without memorizing RouterOS command syntax.
- Chain tool calls across interfaces, routes, firewall rules, logs, and diagnostics.
- Return both operator-friendly summaries and structured JSON for follow-up reasoning.
- Preview changes before mutation and explain exactly what would happen.
- Respect tool-level authorization, router scoping, maintenance windows, and confirmation gates.

MikroMCP is an open-sourceModel Context Protocol(MCP) server that exposes MikroTik RouterOS as 122 typed, auditable tools — letting AI assistants inspect, diagnose, and safely operate routers in natural language instead of improvising CLI commands.

The RouterOS REST/API exposes raw endpoints. MikroMCP wraps them in schema-validated, idempotent, dry-run-able tools with RBAC, audit logging, snapshots, and rollback — the safety layer an LLM needs before it touches production gear.

Instead of brittle SSH scripts that screen-scrape CLI output, MikroMCP returns structured, typed results with confirmation gates and per-router circuit breakers. SSH is used only where REST can't reach —ping,traceroute,torch, and guardedrun_command.

MikroMCP speaks MCP over stdio and HTTP/SSE, so Claude Code and Claude Desktop drive RouterOS directly. Pair it with the bundledusage skillfor safe, guided workflows.

Codex connects to MikroMCP over the standard MCP protocol — seeConnecting to AI Assistants.

Cursor connects to MikroMCP as an MCP server (stdio or HTTP) to inspect and manage MikroTik routers without leaving the editor.

Any MCP-compatible client — OpenClaw included — can use MikroMCP; configure it as a stdio or HTTP MCP server.

Start withGetting Startedto install and connect, then use theusage skillandAvailable Toolsto automate RouterOS safely with an AI assistant.

MikroMCP is purpose-built for MikroTik/RouterOS operations with production-grade safety — dry-run, rollback, audit, and RBAC — making it a strong MCP choice for network engineers adopting AI tooling.

The README stays intentionally short. Everything below is documented in depth in thewiki:

Issues, bug reports, tool requests, documentation improvements, and pull requests are welcome.

- Add a read-only tool for an uncovered RouterOS surface.
- Add screenshots, demo GIFs, or topology diagrams.
- Expand tests around RouterOS response normalization and idempotency edge cases.
- Help validate RouterOS version compatibility across real MikroTik devices and CHR.

- TypeScript strict mode, ESM imports with.jsextensions
- Zod schemas with.strict(), idempotency anddryRunfor write tools
- MikroMCPErrorfor domain errors, focused Vitest coverage for every tool

Please open an issue before large changes so maintainers can align on scope.

- @f0086— SwOS / SwOS Lite switch support (v1.9.0), which took MikroMCP beyond RouterOS for the first time.

MikroMCP controls real network devices — treat it like an operations system: least-privilege RouterOS users, verified TLS (or pinned fingerprints), credentials only in~/.mikromcp/.env, scoped RBAC identities, and audit logging for shared use. The full hardening checklist and vulnerability-reporting process are on theSecurity page.

- ⭐ Star the repository if MikroMCP helps your MikroTik or MCP workflow.
- 🍴 Fork it to add RouterOS surfaces your network depends on.
- 🧵 Open an issue for bugs, feature requests, compatibility notes, or documentation gaps.

MikroMCP is released under theMIT License.

This is a web browser that enables your coding agent, such as Claude Code, to visit websites on your behalf and assist you in identifying bugs or creating UI test cases.

Model Context Protocol server for secure AsusWRT router administration via SSH. Provides 42+ read-only monitoring tools and guarded mutation tools for managing AsusWRT/Merlin routers.

MCP access to cluster-wide L4 and L7 network traffic, packets, APIs, and complete payloads.

Connect to, configure, and monitor Cisco network devices like routers and switches via SSH.

Production-ready MCP server for AI-driven console automation and monitoring. 40+ tools for session management, SSH, testing, and background jobs.

Retrieves essential network information from devices using gNMI and OpenConfig models.

Hetzner Cloud MCP Server — (Cloud API + SSH)

Hetzner Cloud MCP Server — two management layers (Cloud API + SSH) with 60 tools. Manage server power, snapshots, firewalls, DNS, plus SSH into servers for service control, log viewing, Nginx management, MySQL queries, and system monitoring. Self-hosted PHP, MIT licensed.

An MCP server for interacting with Juniper Junos network devices using LLMs.

Provides remote machine control capabilities, eliminating SSH overhead for token-efficient system operations.

Orchestrates remote server tasks via SSH and SFTP with a persistent queue. Ideal for DevOps and AI agents.

Securely execute remote commands and perform file operations over SSH, with support for both password and key-based authentication.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.