tplink-easysmart-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| EASYSMART_HOST | Yes | Switch IP or hostname. Scheme is always http. Required. | |
| EASYSMART_PORT | No | HTTP port. Default 80. | 80 |
| EASYSMART_DRY_RUN | No | A write reads the live page and returns the exact form it would send, sending nothing. Default false. | false |
| EASYSMART_MCP_HOST | No | HTTP transport bind host. Keep it on loopback; the server has no auth of its own. Default 127.0.0.1. | 127.0.0.1 |
| EASYSMART_MCP_PORT | No | HTTP transport bind port. Keep it on loopback; the server has no auth of its own. Default 8766. | 8766 |
| EASYSMART_PASSWORD | Yes | Switch password. 6–16 chars, no spaces. Validated at startup so a bad value never reaches the device and trips its lockout. Required. | |
| EASYSMART_PORT_MAP | No | Friendly names: name=port;name=port. A name must start with a letter and match [A-Za-z][A-Za-z0-9 _.-]{0,31}; purely numeric names are refused so a name can never shadow a port number. Case-insensitive, must be unique. E.g. cam_hall=1;cam_gate=2. | |
| EASYSMART_USERNAME | No | Username. 1–16 printable-ASCII chars. Default admin. | admin |
| EASYSMART_POE_PORTS | No | PoE-capable ports (ranges and commas, e.g. 1,2,5-8). A PoE write requires the port to be here and ≤ the live poe_port_num. Default 1-8. | 1-8 |
| EASYSMART_STATE_DIR | No | Where the breaker, cooldown and cycle-reservation files live. Default ~/.local/state/tplink-easysmart-mcp. | ~/.local/state/tplink-easysmart-mcp |
| EASYSMART_TIMEOUT_S | No | Per-request timeout (1–120). The web server is single-threaded; keep it short. Default 5. | 5 |
| EASYSMART_ALLOW_WRITES | No | Master write switch. Half of the write gate. Default false (read-only). | false |
| EASYSMART_MCP_TRANSPORT | No | stdio or streamable-http. Default stdio. | stdio |
| EASYSMART_LOGIN_DISABLED | No | Freezes authentication: no login attempt is ever made. Default false. | false |
| EASYSMART_CYCLE_OFF_MAX_S | No | Upper bound for a power-cycle's off_seconds (an out-of-range value is refused, not clamped). Default 120. | 120 |
| EASYSMART_CYCLE_OFF_MIN_S | No | Lower bound for a power-cycle's off_seconds (an out-of-range value is refused, not clamped). Default 5. | 5 |
| EASYSMART_PROTECTED_PORTS | No | Ports no write may ever touch: the uplink and the server's own port. Required and non-empty whenever EASYSMART_ALLOW_WRITES=true (startup fails otherwise). E.g. 16,15. | |
| EASYSMART_LOGIN_COOLDOWN_S | No | Minimum gap between a failed/unconfirmed login and the next attempt. Default 300. | 300 |
| EASYSMART_LOGOUT_AFTER_READS | No | If true, read tools also log out. Use it when a human works in the switch web UI often. Default false. | false |
| EASYSMART_CYCLE_POWER_TIMEOUT_S | No | How long to wait for powerstatus == on after re-enabling a port. Default 60. | 60 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| switch_statusA | Healthcheck: policy, one credential-free reachability GET, session-model guess and breaker state. Never logs in, never POSTs, never returns the password or cookies. |
| switch_check_authA | Probe the switch without logging in: report the session model, auth variant and login mode plus breaker/cooldown state. Makes one GET, no POST. |
| switch_loginA | Perform exactly one login, confirm it with a data GET, then log out. Returns the session model and hardware/firmware. Never returns cookies. Refuses (no POST) in restored-account or encrypted-variant modes, and the breaker blocks it after a prior failure until a human clears it. |
| switch_logoutA | End any lingering session with GET /Logout.htm. A no-op (no network) if not currently logged in. Does not mutate switch settings. |
| switch_get_system_infoA | Read-only: model, hardware revision, firmware, MAC, IP, netmask, gateway and the session model. Logs in lazily; does not mutate anything. |
| switch_get_portsA | Read-only: per-port admin state, link, configured/actual speed, flow control, LAG id, friendly name and whether the port is protected. Set only_linked=true to list only ports with a live link. Does not mutate. |
| switch_get_port_statsA | Read-only: tx/rx good/bad packet counters. Pass a port number or a PORT_MAP name for one port, or omit it for all ports plus error_ports (any port with rx_bad+tx_bad > 0). Does not mutate. |
| switch_get_poeA | Read-only: PoE budget totals and per-port state, priority, power limit, PD class ("--" when none), watts, milliamps, volts and status, plus derived fault_ports and unpowered_enabled_ports. Does not mutate. |
| switch_get_vlansA | Read-only: the 802.1Q VLAN table and per-port PVIDs. Returns NOT_SUPPORTED if this firmware does not serve a VLAN page. Does not mutate. |
| switch_resolve_portA | Read-only helper: resolve a port number or PORT_MAP name to {port, name, is_poe, protected, max_port}. Resolution is type-stable: an integer or a string of digits is ALWAYS a port number (never a name), so 3 and "3" mean the same physical port and a numeric name can never shadow one. A non-digit string is a case-insensitive name. UNKNOWN_PORT lists the known names; AMBIGUOUS_NAME if a name maps to more than one port; an out-of-range number is INVALID_PORT. Does not mutate. |
| switch_set_poeA | MUTATES PoE on one port. Reads the live PoE page, re-sends the port's current priority and power limit, and changes only on/off, then verifies (WRITE_VERIFY_FAILED if priority/limit were clobbered). Refuses a non-PoE port (NOT_POE_PORT) or a protected port (PROTECTED_PORT). Requires EASYSMART_ALLOW_WRITES=true and confirm_write=true; otherwise no network call. Honours EASYSMART_DRY_RUN (returns the exact form, sends nothing). |
| switch_set_portA | MUTATES one port's admin state (enable/disable the link). Reads the live page, re-sends the port's current speed and flow control, changes only the state, then verifies. Refuses a protected port (PROTECTED_PORT). Requires both write gates; otherwise no network call. Honours EASYSMART_DRY_RUN. |
| switch_poe_cycleA | MUTATES: power-cycle one PoE camera (off, wait off_seconds, on, wait for power). Resolve a PORT_MAP camera name or port number. Refuses non-PoE (NOT_POE_PORT), protected (PROTECTED_PORT), an already-off port (ALREADY_OFF) and a second concurrent cycle (CYCLE_IN_PROGRESS). If it cannot restore power it reports CYCLE_INCOMPLETE/POWER_NOT_RESTORED naming the port that may be UNPOWERED. Requires both write gates; honours EASYSMART_DRY_RUN (returns both planned forms, sends nothing). |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 13 tools
Most tools target distinct resources or actions, but switch_status and switch_check_auth both perform a credential-free probe and report session/auth/breaker state, creating one confusing pair. switch_login and switch_get_system_info also overlap in session handling, though their descriptions clarify the difference.
All tools use snake_case with a consistent switch_ prefix. Verbs like get_, set_, resolve_, check_, login, and logout are conventional and readable throughout, with no mixed conventions.
The 13 tools are well-scoped for a switch management server. They cover status, authentication, read operations, safe writes, a helper, and a specialized PoE cycle without excessive bloat.
The surface covers read-heavy diagnostics and limited safe mutations, but it lacks VLAN configuration, port speed/flow-control changes, LAG management, and a way to clear the auth breaker. These are notable gaps for full switch management, though core read and safe write workflows exist.