openwrt-mcp
Provides full administrative control of OpenWRT routers over SSH, with typed tools for system info, network interfaces, DHCP leases, Wi-Fi, firewall, package management, services, logs, and UCI configuration, along with a preview-then-confirm safety model for mutating operations.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@openwrt-mcpList all currently connected Wi-Fi clients"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
openwrt-mcp
An MCP server that gives an AI assistant full administrative control of OpenWRT router(s) over SSH, with typed tools and a preview→confirm safety model.
Install
npm install && npm run buildRelated MCP server: OpenWrt MCP Controller
Configure
Copy openwrt-mcp.config.example.json to openwrt-mcp.config.json and edit:
{
"routers": {
"home": {
"host": "192.168.1.1",
"port": 22,
"username": "root",
"auth": { "type": "key", "privateKeyPath": "~/.ssh/id_ed25519" },
"readonly": false,
"default": true
}
}
}Password auth:
"auth": { "type": "password", "password": "${RTR_PW}" }(the${RTR_PW}form reads the value from that environment variable).readonly: truehard-blocks all mutating tools on that router.
Config path override: set OPENWRT_MCP_CONFIG=/path/to/config.json.
Run / connect
Add to your MCP client (e.g. Claude Desktop / Claude Code) as a stdio server:
{
"mcpServers": {
"openwrt": {
"command": "node",
"args": ["/absolute/path/to/openwrt-mcp/dist/index.js"],
"env": { "OPENWRT_MCP_CONFIG": "/absolute/path/to/openwrt-mcp.config.json" }
}
}
}Safety model
read tools run immediately.
mutate / risky tools require a two-step call: the first call (without
confirm: true) returns a preview (the exact commands + auci changesdiff where relevant); call again withconfirm: trueto execute.risky tools (firewall, network commit, reboot, raw shell) add a lock-out warning.
Tools
system_info, system_resources, reboot, net_interfaces, net_dhcp_leases, net_wifi_clients, net_routes, net_arp, uci_show, uci_get, uci_changes, uci_set, uci_delete, uci_revert, uci_commit, wifi_radios, wifi_set_enabled, wifi_configure, fw_list, fw_add_rule, fw_remove_rule, opkg_update, opkg_list, opkg_list_installed, opkg_install, opkg_remove, service_list, service_control, service_enabled, log_read, dmesg, run_command.
This server cannot be deployed
Maintenance
Related MCP Connectors
- emisarOAuthdev.emisar
Let AI operate servers without SSH. Choose actions, approve risky changes, and audit every step.
Read devices, users, keys, ACLs and DNS for a tailnet; manage devices, routes and auth keys.
Run commands and read/write files on your servers over Termalin's keyless tunnels (hosted MCP).
Tailscale device, route, DNS, key, user, and ACL management over MCP and CLI.
Related MCP Servers
- AlicenseAqualityFmaintenanceEnables AI agents to manage OpenWRT routers remotely via SSH, supporting system monitoring, network management, OpenThread Border Router configuration, and package management through natural language commands.1916MIT
- FlicenseAqualityDmaintenanceEnables management and control of OpenWrt devices via a simple API, including reboot, status checks, log reading, and LED control.51-
- FlicenseNot gradedqualityDmaintenanceAllows you to interact with an OpenWrt router via SSH, enabling command execution, file operations, and system info retrieval.-
- FlicenseBqualityBmaintenanceEnables management of OpenWrt routers via SSH, providing tools for network configuration, system administration, file operations, and package management through natural language.571-