ADT Security MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| ADT_PASSWORD | No | Account password. | |
| ADT_USERNAME | No | ADT Control / Alarm.com account username. Must be set with ADT_PASSWORD. | |
| ADT_DEMO_MODE | No | Set to 'true' to force the stateful demo provider. Demo is also selected when no username/password are configured. | |
| ADT_MFA_TOKEN | No | Optional token supported by the upstream client. | |
| ADT_SYSTEM_ID | No | Required when the account exposes more than one system. | |
| ADT_AUDIT_LOG_PATH | No | Optional audit path. Default: ~/.adt-mcp/audit.jsonl. | |
| ADT_ALLOW_MUTATIONS | No | Real accounts are read-only unless set to 'true'. | |
| ADT_STANDALONE_PORT | No | Optional loopback dashboard port. Default: an available ephemeral port on 127.0.0.1. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| resources | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| adt-dashboardB | Read the current ADT security system and device state. Credentials come only from the server environment. |
| open-standalone-dashboardA | Create an expiring, loopback-only URL for the full interactive ADT dashboard. Use this when the MCP client cannot render MCP Apps or constrains the app inside a frame. |
| prepare-security-actionA | Validate and preview one security-system mutation. Returns a short-lived, one-use token required by the matching mutation tool. Show the summary to the user before continuing. |
| arm-systemA | Arm one exact panel after prepare-security-action returned a matching confirmation token. |
| disarm-systemA | Disarm one exact panel after prepare-security-action returned a matching confirmation token. This reduces physical security and requires explicit user approval. |
| control-lockA | Lock or unlock one exact lock after prepare-security-action returned a matching confirmation token. Unlocking requires explicit user approval. |
| control-lightA | Turn a light on or off, optionally setting dimmer brightness, after prepare-security-action returned a matching confirmation token. |
| set-thermostatA | Change thermostat mode and bounded Fahrenheit setpoints after prepare-security-action returned a matching confirmation token. |
| get-alertsA | Derive current actionable alerts from live device state, including triggered sensors, offline devices, and battery warnings. This is not provider event history. |
| get-event-historyA | Read the redacted local audit history of mutation attempts made through this MCP server. It is not Alarm.com provider history. |
| get-camera-snapshotA | Fetch a current camera snapshot through the server. Signed provider URLs are never returned. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| adt-security-dashboard | Interactive ADT security dashboard |
TDQS
Scored across 11 tools
Each tool targets a clearly distinct resource or action: dashboard read, standalone URL creation, action preparation, arm, disarm, lock, light, thermostat, alerts, audit history, and camera snapshot. The descriptions differentiate similar-sounding tools like adt-dashboard and open-standalone-dashboard, and the prepare-security-action gating makes mutation tools unambiguous.
All names are kebab-case and mostly follow a verb_noun pattern (arm-system, control-lock, get-alerts, set-thermostat). Minor deviations include adt-dashboard (noun-only) and open-standalone-dashboard (extra adjective), but the overall convention is predictable.
11 tools are well-scoped for an ADT security server: they cover state reading, action preparation, and mutations across panels, locks, lights, and thermostat, plus alerts, history, and camera. No obvious redundancy or missing tool class.
Core security operations (arm/disarm, lock, light, thermostat, alerts, camera, state read) are covered, with a safe prepare-then-mutate workflow. Minor gaps include no explicit device list, user management, or provider event history beyond current alerts, but adt-dashboard and get-alerts provide reasonable workarounds.