WhiteOmadaMcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| OMADA_ALLOW_WRITES | No | Set to true to allow writes; requires write credentials. Default is read-only. | false |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| v2_statusA | Login check: controller version, account, role, and hours left on a temporary account. Call this first. |
| v2_endpointsA | The verified v2 endpoint map for this build (6.2.14.11), derived from the controller's own GUI bundles and probed live — including what is NOT available and why. Read this before guessing a path. |
| v2_modeA | What this server is allowed to do: read-only vs write-enabled, which credential sets are loaded (never the values), which API is preferred, and the v1/v2 reachability of both transports. Call this to explain why a write was refused. |
| oa_getA | GET any Open API (v1) path, relative to /openapi/v1/{omadacId}. The v1 API is the ONLY one that returns event and audit logs on controller 6.2+ (measured: 88,522 events via v1, 0 via v2). |
| v2_set_ssid_rate_controlA | 802.11 rate control per SSID: disable CCK (kills 1/2/5.5/11 Mbps and the ERP-protection penalty), set the minimum data rate, choose whether beacons stay at 1 Mbps, and whether clients are FORCED to the minimum. Field schema verified against a live 6.2.14.11 controller. Warns about clients that would fall below the new floor before sending. [READ-ONLY MODE: returns the exact payload instead of sending it] |
| v2_ssid_broadcastC | Which APs broadcast which SSID, and change it per-AP. IMPORTANT SEMANTICS (verified): ssidOverrides[].ssidEnable is what decides whether an SSID is on the air on that AP; the sibling |
| v2_channel_utilA | Sample 2.4/5 GHz channel utilisation over time and report mean/median/min/max per channel. Use BEFORE and AFTER any RF change — this band swings 30-55 points on its own, so a single reading proves nothing and a short baseline will let you claim any result you like. |
| v2_client_survivalA | Snapshot every wireless client, wait, then re-check and name anything that disappeared. Run this after any RF or SSID change — it is how you catch a setting that silently evicted an IoT device instead of just reading "Success". |
| v2_radar_auditA | Settle a DFS argument with evidence rather than opinion. Reports which radios are actually on DFS channels, watches them live for an unrequested channel change, checks AP uptime (a radar hit cannot happen without one or the other), and sweeps the v1 event log per-AP for radar entries. States plainly what it can and cannot prove. |
| v2_security_auditA | Security posture of every SSID in one table: WPA version, PMF (802.11w) mode, 802.11r, guest isolation, band, VLAN, broadcast. Flags the combinations that are known to destabilise clients — notably PMF Mandatory (value 1) on WPA2-PSK, and WPA2/WPA3 transition mode, which is defeated by a documented downgrade attack and gives WPA2 security with WPA3 compatibility problems. |
| v2_client_historyA | Every association a given client made over N days: which AP, which channel, which band, and how often it disconnected. This is how you tell a band-steering problem from a roaming problem from a device that simply drops. Uses the v1 log API, which is the only one that returns events on 6.2+. |
| v2_interference_auditA | REAL interference detection, not inference. Uses the AP's own radio counters — interUtil (airtime lost to NON-WiFi emitters), busyUtil, txUtil/rxUtil, and rx/tx retry and drop deltas — sampled over time. Separates "the band is busy with WiFi" from "something non-WiFi is transmitting", which is the distinction that makes every other interference claim a guess. Optionally correlates against live aircraft overhead (opt-in, sends an approximate location to a public flight API). |
| v2_getA | GET any v2 path (relative to /api/v2). Use for anything the typed tools do not cover. Returns errorCode triage on failure. |
| v2_writeC | Escape hatch: any PATCH/POST/PUT/DELETE with automatic read-back and diff. dryRun defaults true. [READ-ONLY MODE: returns the exact payload instead of sending it] |
| v2_site_settingsB | FULL site settings decoded: roaming (fast/AI/non-stick/ping-pong/force-disassoc), band steering, airtime fairness, mesh, beacon+DTIM+RTS, LED, LLDP, NTP, alerts, remote syslog, auto-upgrade. Flags risky values. |
| v2_controller_settingsA | Controller-level configuration: name, timezone, DST, controller NTP, HTTP/HTTPS ports, certificate, mail server, logging levels, built-in RADIUS, device access management, data retention, uptime and version. Flags controller NTP off and plaintext management. |
| v2_servicesB | Every site service in one call: SNMP, SSH, mDNS, UPnP, IPTV/IGMP proxy, DHCP reservations, PoE schedules, reboot schedules, wireless MAC filter, 802.1X, MAC authentication, RADIUS profiles, rate-limit profiles, time ranges and IP/MAC groups. Flags insecure or unset services. |
| v2_wanB | WAN/internet view: WAN network config, number of WAN ports, per-port state and IP. On a controller with no Omada gateway this reports what is and is not manageable. |
| v2_switchesC | Switch-level state: model, firmware, uptime, CPU/mem, STP mode + bridge priority + timers, device-level loopback detection, jumbo frames, SNMP, LAGs, LLDP uplink/downlink neighbours. Flags STP-disabled switches. |
| v2_switch_portsA | Every port on every switch (or one switch), decoded with VLAN NAMES: link/speed, PVID, tagged/untagged, VLAN profile + profileOverride + profileVlanOverride, PoE, STP, loopback detection, storm control, isolation. Emits warnings for STP-off / loopback-off / all-VLAN / dead ports, and marks inter-switch trunks. |
| v2_port_statsA | Live per-port counters: link state, tx/rx bytes and packets, ERRORS and DROPS, plus PoE draw in watts per port and total budget. This is the tool for "is a cable or a device misbehaving". |
| v2_switch_statsB | Per-switch statistics view: per-port operation, speeds, PoE and traffic totals as the Statistics page shows them. |
| v2_vlan_profilesB | Switch VLAN port profiles (the "All"/"Disable"/custom profiles) fully decoded with VLAN names, plus which profile each switch port currently uses. This is what actually enforces per-port VLAN membership. |
| v2_lan_networksB | Every VLAN: name, tag, subnet, DHCP scope, IGMP/MLD snooping, DHCP guard, purpose. Flags networks with snooping off. |
| v2_ap_radiosA | Per-AP everything in REAL UNITS: channel/width/power per band, allowed channels, RSSI kick, load balance, WMM, OFDMA, mesh, management SSID, multicast VLAN, wired uplink rate, per-AP SSID enablement. Omit apMac for all APs. |
| v2_ssidsA | Full config of every SSID: band, VLAN, security/PMF, 802.11r, guest isolation, prohibitWifiShare (the TTL clamp), rate control, MAC filter, schedule, multicast/broadcast handling. Passphrases redacted unless showSecrets. |
| v2_rf_healthB | RF diagnostics without touching anything: per-channel AP/client counts and channel utilisation on both bands, per-AP interference, client RSSI distribution, and the controller's own wireless experience index history. The closest thing this build has to a wireless test. |
| v2_rogue_apsA | Neighbouring/rogue APs seen by your own APs — SSID, BSSID, channel, signal, security. Empty until a scan has run. |
| v2_clientsA | Known-client list: name, MAC, vendor, wired/wireless, VLAN, traffic totals, last seen, blocked state. NOTE this build's endpoint carries NO RSSI, SSID, AP or rate data — the tool says so rather than inventing it. Pass a mac to get that one client's full detail (vendor, OS, device type, IP settings, rate limit). |
| v2_past_connectionsB | Historical client sessions: MAC, SSID/network, AP, duration, traffic, disconnect reason. Use for "why did this device drop". |
| v2_topologyA | Physical topology: every node, what it is connected to, on which port, at what speed. Use this to confirm which ports are inter-switch trunks before touching loopback detection. |
| v2_eventsB | Site EVENT log with real filters: level (Error/Warning/Information), module (Operation/System/Device/Client), time window in hours, free-text search, paging. Diagnoses an empty result rather than reporting silence as health. |
| v2_alertsB | Site ALERT log (the subset of events flagged as alerts), with archived/unarchived filter, level, module, time window and search. |
| v2_audit_logsA | AUDIT log: who changed what, from which IP, with old and new values. This is the accountability trail — separate from events. |
| v2_log_settingsB | Everything that governs whether logs exist at all: site alert switch, remote syslog target, controller log retention policy, controller logging levels, webhook targets, and the current stored-log count against the cap. Explains an empty log rather than leaving it mysterious. |
| v2_notificationsB | The notification catalogue — which events are recorded, which raise alerts, and which send mail or webhook. This is the real alerting control; the |
| v2_log_diagnoseA | Why is the log empty? Runs the full evidence chain in one call: every log surface (site/controller events, alerts, audit), the stored-log counter vs its cap, retention policy, the notification catalogues that decide what gets recorded at all, and remote syslog state. Use this before concluding a quiet network — an empty log and a healthy network look identical. |
| v2_dfs_checkA | DFS/radar evidence. Compares each 5 GHz radio's CONFIGURED channel against the channel it is ACTUALLY operating on. A radar detection forces a 30-minute vacate onto a different channel, so configured != actual is a radar event caught in the act. Also flags which radios are on DFS channels at all, and whether any sits in the 5600-5650 MHz weather-radar sub-band. |
| v2_set_ap_ssidA | Enable or disable one SSID on ONE access point. This is the only real on/off switch an SSID has — there is no global enable field; on-air state lives per-AP in ssidOverrides[].ssidEnable. Use it to keep an SSID in one room only, or to cut beacon overhead on a busy band without changing coverage anywhere. [READ-ONLY MODE: returns the exact payload instead of sending it] |
| v2_diagnosticsA | The 6.2 diagnostic surface in one call: client distribution per band / per SSID / per AP, RSSI histogram, association failures (timeout, WPA failure, blocked), association-time buckets, client activity over time, longest-uptime devices, top applications, per-channel utilisation, per-AP interference, and PoE budget. This is the tool for "is the wireless actually healthy", as opposed to "is it configured correctly". |
| v2_rf_planningA | AI RF Planning — the controller's own channel/width/power optimiser. Reads the current plan settings, the run history with before/after experience index, and the status of the last run. Can trigger a new run with run:true. ⚠ A run re-plans channels across every AP and applies them, overriding any manual channel choice. |
| v2_speedtestA | Run the controller WAN speed test and poll for the result. NOTE: verified unsupported on this build (-1600) because the site has no Omada gateway — the tool says so explicitly instead of hanging. Kept for the day an ER-series router is adopted. [READ-ONLY MODE: returns the exact payload instead of sending it] |
| v2_health_auditA | One-shot audit across site settings, controller settings, services, switches, ports, VLAN profiles, radios, SSIDs, VLANs and logs. Returns a ranked list of misconfigurations, each with the exact tool call that fixes it and its blast radius. |
| v2_usersA | Controller accounts: role, type, 2FA, temporary-validity window and hours left. This server can DELETE an account but can never create, extend or enable one. |
| v2_set_ap_radioA | Set AP channel / width / tx power in REAL UNITS (channel 100, widthMHz 40). Warns on DFS and the 5600-5650 MHz weather-radar band. Read-back verified. [READ-ONLY MODE: returns the exact payload instead of sending it] |
| v2_set_ap_load_balanceB | Fix or set per-radio load balancing. Guards the maxClients:1 landmine — refuses maxClients under 5 unless force:true. [READ-ONLY MODE: returns the exact payload instead of sending it] |
| v2_set_ap_rssi_kickA | Set the RSSI threshold that disassociates a client clinging to a weak AP — the fix for sticky clients that sit at -80 dBm while a -55 dBm AP is in the same room. TP-Link: "if you did not set it, that is why you don't switch." Gentler than nonStickRoaming: it does not emit the MBO/OCE "cannot handle new STA" frames that feed Android's BSSID blocklist. ⚠ Set it BELOW the weakest signal you still want to keep, or you will disconnect distant devices you rely on. [READ-ONLY MODE: returns the exact payload instead of sending it] |
| v2_set_ap_mgmt_ssidA | ⚠ MEASURED NOT TO WORK on 6.2.14.11: mgtSsidSetting is read-only. The write returns success and the value reverts on read-back, the field appears in none of the 381 GUI modules, and no site-level control exists. Kept only so the attempt is recorded honestly rather than repeated — the tool will report REVERTED. Settle it with a phone scan instead. [READ-ONLY MODE: returns the exact payload instead of sending it] |
| v2_set_site_roamingA | Set site roaming: fastRoaming (802.11r/k), aiRoaming, nonStickRoaming, pingPongSuppression, forceDisassociation. NOTE nonStickRoaming and forceDisassociation send MBO/OCE "cannot handle new STA", which feeds the Android BSSID blocklist and produces the "phone thinks it is banned" symptom. [READ-ONLY MODE: returns the exact payload instead of sending it] |
| v2_set_site_featureB | Toggle site-wide features: airtime fairness per band, alert logging (the audit trail), remote syslog target, LED, LLDP, auto-upgrade, band steering. [READ-ONLY MODE: returns the exact payload instead of sending it] |
| v2_set_switch_stpA | Enable/disable STP on a switch and set bridge priority and timers (lower priority wins; 4096 forces root). ⚠ Enabling STP triggers ~30 s of listening/learning — ports carrying APs or cameras WILL drop. Do it when the network is quiet. [READ-ONLY MODE: returns the exact payload instead of sending it] |
| v2_set_portA | Set one switch port: loopback detection, STP on/off, STP edge-port and BPDU/root guard, storm-control thresholds, port isolation, PoE, enable/disable. ⚠ NEVER enable loopback detection on a switch-to-switch trunk — an edge loop could then shut the uplink and partition the network. The tool refuses trunk ports unless force:true. [READ-ONLY MODE: returns the exact payload instead of sending it] |
| v2_set_ports_bulkA | Apply one change to many ports at once, with the same trunk guard as v2_set_port. Select ports explicitly, or by selector: "access" (all non-trunk), "dead" (link down, non-trunk — zero blast radius), "all". Use this with edgePort:true before enabling STP on a switch: it is the step that turns a 30-second convergence outage into no outage at all on the access ports. Each port is written and verified individually. [READ-ONLY MODE: returns the exact payload instead of sending it] |
| v2_set_port_pvidA | Set a switch port's PVID — the VLAN an UNTAGGED frame lands on. This is what decides where a laptop plugged straight into the port ends up, and it is what makes a rescue/console port actually work without configuring the laptop. The tagged VLAN list is preserved unless you replace it. Refuses inter-switch trunks unless force:true. [READ-ONLY MODE: returns the exact payload instead of sending it] |
| v2_set_port_profileA | Bind a switch port to a VLAN port profile — the real fix for "every port permits every VLAN". Refuses to change an inter-switch trunk unless force:true, because a wrong profile there partitions the network. [READ-ONLY MODE: returns the exact payload instead of sending it] |
| v2_set_lan_igmpA | Enable/disable IGMP and MLD snooping on a VLAN. ⚠ Without an IGMP querier on that VLAN, snooping STOPS multicast instead of optimising it — test TVs and speakers immediately after enabling. [READ-ONLY MODE: returns the exact payload instead of sending it] |
| v2_set_ssidA | Change one SSID: enable/disable, broadcast, 802.11r fast roaming, PMF, guest isolation, prohibitWifiShare (the TTL clamp that breaks VMs and hotspots), VLAN and rate-limit profile. Read-back verified. [READ-ONLY MODE: returns the exact payload instead of sending it] |
| v2_set_serviceA | Toggle site services: SNMP v1/v2c/v3, SSH access, mDNS repeater, UPnP. Each is read back and diffed. [READ-ONLY MODE: returns the exact payload instead of sending it] |
| v2_delete_userA | DELETE a controller account. Deliberately the only account operation this server has: deleting removes access, it cannot grant it, so no credential in this config can mint admin. Refuses the account you are logged in as and refuses Owner/root accounts. Requires confirm:true. [READ-ONLY MODE: returns the exact payload instead of sending it] |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 59 tools
The set has many distinct tools, but several overlaps: generic v2_get/v2_write/oa_get compete with typed readers/writers; v2_ssid_broadcast and v2_set_ap_ssid both control per-AP SSID state; v2_radar_audit and v2_dfs_check both cover DFS radar evidence; and diagnostic tools like v2_health_audit, v2_diagnostics, v2_rf_health, and v2_security_audit overlap. Descriptions are detailed, which helps, but an agent still faces real misselection risk.
Consistent v2_ snake_case prefix and set_* write convention, but read tools are mostly noun-based (v2_clients, v2_ssids, v2_events) rather than the verb_noun pattern, and oa_get/v2_get/v2_write introduce mixed verb styles. Still readable and largely predictable.
59 tools is very heavy; for a single controller domain, many typed tools duplicate what v2_get/v2_write can do, and the diagnostic/audit suite is sprawling. The broad Omada feature set provides some justification, but the surface is over-scoped.
Covers extensive read coverage plus many targeted writes, but CRUD is incomplete: no create/delete for VLANs, SSIDs, users (delete only), port profiles, DHCP reservations, or many service objects, and no firmware/backup/reboot actions. Agents can work around some gaps via generic paths, but lifecycle dead ends remain.