miwifi-mcp
Allows management of Xiaomi/Redmi routers, providing read-only queries (connected devices, system info, IPv6, PPPoE, bandwidth, topology, WiFi details, port forward rules, DHCP reservations, blocked devices, LED status) and write operations (add/delete port forwards and DHCP reservations, block devices, reboot).
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@miwifi-mcplist all devices currently connected to my router"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
miwifi-mcp
小米 / 红米路由器 MCP Server —— 让 AI 助手(Claude Desktop、Reasonix、Cursor 等支持 MCP 的客户端)直接管理你的小米路由器。
Xiaomi / Redmi router MCP server — manage your router from any MCP-capable AI assistant.
✨ 功能
读(只读查询)
工具 | 说明 |
| 列出所有在线设备(名称 / IP / MAC / 上下行速度 / 累计流量) |
| 型号、固件、运行状态、WAN / LAN 概况 |
| IPv6 状态(模式、地址、前缀、DNS) |
| PPPoE 拨号状态(密码自动脱敏) |
| 带宽历史 / WAN 统计 |
| 网络拓扑(Mesh 节点、连接关系) |
| WiFi 详情(信道、频宽、功率、SSID)+ 可用信道 |
| 端口转发规则列表 |
| DHCP 静态绑定列表 |
| LAN / DHCP 服务配置 |
| 黑名单 / MAC 过滤 / DMZ / QoS |
| 路由器 LED 灯状态 |
写(会改变路由器状态)
工具 | 说明 |
| 添加端口转发 |
| 删除端口转发 |
| 添加 DHCP 静态绑定 |
| 删除 DHCP 静态绑定 |
| 拉黑设备(禁止上网) |
| 重启路由器(断网十几秒后自动恢复) |
逃生口
工具 | 说明 |
| 只读透传任意 LuCI API 路径(内置黑名单拦截 |
❌ 故意不提供
shutdown—— 远程执行后必须物理拔插电源才能重启,断网自毁reset—— 恢复出厂设置修改管理密码
Related MCP server: AsusWRT MCP Server
📦 安装
git clone https://github.com/2670321532/miwifi-mcp.git
cd miwifi-mcp
pip install -r requirements.txt国内建议加 pip 镜像:
-i https://pypi.tuna.tsinghua.edu.cn/simple
⚙️ 配置
复制模板并填入你的信息:
cp config.example.json config.local.json{
"host": "192.168.31.1",
"user": "admin",
"password": "你的路由器后台管理密码"
}优先级:环境变量 > config.local.json > 内置默认值
环境变量 | 对应字段 |
|
|
|
|
|
|
config.local.json不要提交到 Git(已在.gitignore中)。
🔌 接入 MCP 客户端
Claude Desktop(claude_desktop_config.json):
{
"mcpServers": {
"miwifi": {
"command": "python",
"args": ["/absolute/path/to/miwifi-mcp/server.py"]
}
}
}Reasonix(config.toml):
[[plugins]]
name = "miwifi"
command = "python"
args = ["/absolute/path/to/miwifi-mcp/server.py"]重启客户端即可看到 miwifi_* 工具。
🔑 登录算法(重点)
小米路由器的登录是 challenge-response,而且新旧固件算法不同。 本项目的实现基于对路由器管理页面 JS 的逆向,已适配两种模式:
// 路由器页面里决定用哪种算法的变量
var newEncryptMode = parseInt('1') // 1 → SHA256,0 → SHA1
nonce = [0, deviceId, 时间戳, 随机数].join('_') // deviceId = 路由器 MAC(带冒号)
// newEncryptMode == 1
password = SHA256( nonce + SHA256(明文密码 + key) )
// newEncryptMode == 0
password = SHA1( nonce + SHA1(明文密码 + key) )其中 key 从管理页面抓取(每个固件可能不同),然后:
POST /cgi-bin/luci/api/xqsystem/login
Content-Type: application/x-www-form-urlencoded ← ⚠️ 必须是 form-data,不能用 JSON
body: username=admin&password=<hash>&logtype=2&nonce=<nonce>成功返回 {"code":0,"token":"<stok>"},之后所有请求带上:
GET /cgi-bin/luci/;stok=<token>/<api路径>⚠️ 错误响应速判
响应 | 含义 |
| 请求格式对,但密码或算法错 |
| 请求格式错(连验证都没进,通常是用了 JSON 而非 form-data) |
| ✅ 成功 |
登录速率限制:连续 4 次失败会被临时锁定,请勿盲目重试。
📌 端点差异
部分固件改了 API 路径,本项目已做兼容:
端点 | 结果 |
| ❌ 404(部分固件不存在) |
| ✅ 200 |
🧪 实测环境
项 | 值 |
路由器 | 小米路由器 RP02 |
固件 | 1.0.46 |
加密模式 |
|
特性 | Wi-Fi 7(MLO)、2.5G 网口 |
Python | 3.11 |
理论兼容:所有使用 LuCI HTTP API 的小米 / 红米路由器(本项目会自动识别 newEncryptMode)。
如果你的型号不行,欢迎提 issue 附上固件版本和错误响应。
🔒 安全说明
密码只存本地 ——
config.local.json(已 gitignore)或环境变量;代码里不含任何凭据只读优先 ——
miwifi_luci_get有黑名单,无法通过它触发修改操作不提供危险操作 ——
shutdown/reset/ 改密码被刻意排除PPPoE 密码脱敏 —— 路由器原始返回的宽带账号密码会被替换为
<已脱敏>建议 —— 路由器后台密码不要与其他服务共用
🛠️ 排错
login key not found on web page
→ 路由器管理页面结构不同。手动访问 http://<路由器IP>/cgi-bin/luci/web,
查看源码里是否有 key: '...' 和 deviceId = '...'。
login failed: {'code': 401, 'msg': 'not auth'}
→ 密码错,或固件的加密模式判断有误。确认 newEncryptMode 的值。
login failed: {'code': 401, 'msg': 'Invalid token'}
→ 请求不是 form-data。检查 Content-Type。
工具返回 404 / bad JSON
→ 该固件的端点路径不同,用 miwifi_luci_get 试探正确路径。
📄 License
🙏 致谢
python-xiaomi-miwifi—— 提供了 LuCI API 的封装与端点映射Model Context Protocol —— MCP 协议与 SDK
本项目与小米公司无关联,为第三方非官方工具。使用风险自负。
This server cannot be deployed
Maintenance
Related MCP Connectors
Zero-setup MCP gateway securely connecting AI to your tools with authentication and workflows
- mytesla.ioOAuthio.mytesla
Control your Tesla from your AI assistant - climate, charging, access, and security.
- mcpOAuthcom.vibgrate
Query your team's drift, vulnerability, and upgrade data from any AI assistant. OAuth 2.1, 51 tools.
Provides capabilities that let LLM agents perform a range of infrastructure management tasks.
Related MCP Servers
- AlicenseAqualityCmaintenanceEnables AI assistants to interact with Ubiquiti UniFi network infrastructure for monitoring devices, managing clients, and performing configuration tasks like blocking/unblocking devices and viewing network health.101GPL 3.0
- AlicenseBqualityDmaintenanceEnables AI assistants to monitor and securely manage AsusWRT and AsusWRT-Merlin routers via SSH with allowlisted commands, supporting read-only monitoring and controlled mutations.472MIT
- AlicenseNot gradedqualityDmaintenanceEnables AI assistants to control Xiaomi Mi Home smart devices through natural language, supporting device listing, property control, actions, and scenes.7MIT
- AlicenseAqualityDmaintenanceEnables AI assistants to read-only monitor iStoreOS/OpenWRT routers via SSH or HTTP/ubus API, providing 31 tools for system status, network info, logs, and plugin status (OpenClash, Passwall, AdGuardHome, etc.).31MIT