mcp-router
by macbeth76
README.md
# mcp-router
TypeScript MCP server for Linksys router control with a read-only-first tool surface.
> Full operational reference (network path, credentials location, deployment
> status, open issues): `docs/linksys-router.md` in the `BlahBlahBlah` repo.
## Features
- `router_get_details`: `core/GetDeviceInfo`
- `router_list_devices`: `devicelist/GetDevices`
- `router_jnap_read`: generic read-only JNAP actions (`Get*` / `Check*` only)
- `router_reboot`: optional write action gated by `ROUTER_ENABLE_WRITES=true` and `confirm=true`
## Setup (Local)
1. Copy env file:
```bash
cp .env.example .env
```
2. Fill `.env`:
- `ROUTER_URL` (for example `http://192.168.76.1`)
- `ROUTER_USERNAME` (usually `admin`)
- `ROUTER_PASSWORD`
- `ROUTER_TIMEOUT_MS` (optional, default `10000`)
- `ROUTER_ENABLE_WRITES` (`false` by default)
3. Confirm the runtime is on the same trusted LAN as the router before calling JNAP. The Linksys device is reachable only from a host connected to the `192.168.76.0/24` segment (for example Dragon's USB Ethernet path), not from a generic off-LAN Windows host.
4. Install and build:
```bash
pnpm install
pnpm build
```
4. Run:
```bash
pnpm dev
```
## Deployment to Dragon
### Option 1: Systemd Service
```bash
./deploy-dragon.sh
```
This will:
1. Clone the repo to `/opt/mcp-router`
2. Install dependencies with pnpm
3. Build the TypeScript
4. Install and start the systemd service
Check logs:
```bash
journalctl -u mcp-router -f
```
### Option 2: Docker Compose
```bash
docker-compose up -d
```
The service will restart automatically on failure.
Set the `ROUTER_PASSWORD` environment variable before running:
```bash
export ROUTER_PASSWORD="<your-password>"
docker-compose up -d
```
## Configuration
### Environment Variables
- `ROUTER_URL`: HTTP URL to the router (e.g., `http://192.168.76.1`)
- `ROUTER_USERNAME`: JNAP username (default: `admin`)
- `ROUTER_PASSWORD`: JNAP password (required)
- `ROUTER_TIMEOUT_MS`: Request timeout in milliseconds (default: `10000`, min: `1000`)
- `ROUTER_ENABLE_WRITES`: Enable write operations (default: `false`)
## Security Notes
- Keep write operations disabled by default
- Use `router_jnap_read` for discovery and status checks before adding new mutating tools
- Store credentials in `.env` (local) or environment variables (deployment)
- Credentials are sent via Basic Auth over HTTP — ensure the router is on a trusted LAN only
## Testing
Run the included test script:
```bash
pnpm tsx test-router.ts
```
This validates connectivity and runs sample read-only operations against the router.
This server cannot be deployed
Maintenance
ActivityMaintained
ResponsivenessNo issues