Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
OMADA_ALLOW_WRITESNoSet to true to allow writes; requires write credentials. Default is read-only.false

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
v2_statusA

Login check: controller version, account, role, and hours left on a temporary account. Call this first.

v2_endpointsA

The verified v2 endpoint map for this build (6.2.14.11), derived from the controller's own GUI bundles and probed live — including what is NOT available and why. Read this before guessing a path.

v2_modeA

What this server is allowed to do: read-only vs write-enabled, which credential sets are loaded (never the values), which API is preferred, and the v1/v2 reachability of both transports. Call this to explain why a write was refused.

oa_getA

GET any Open API (v1) path, relative to /openapi/v1/{omadacId}. The v1 API is the ONLY one that returns event and audit logs on controller 6.2+ (measured: 88,522 events via v1, 0 via v2).

v2_set_ssid_rate_controlA

802.11 rate control per SSID: disable CCK (kills 1/2/5.5/11 Mbps and the ERP-protection penalty), set the minimum data rate, choose whether beacons stay at 1 Mbps, and whether clients are FORCED to the minimum. Field schema verified against a live 6.2.14.11 controller. Warns about clients that would fall below the new floor before sending. [READ-ONLY MODE: returns the exact payload instead of sending it]

v2_ssid_broadcastC

Which APs broadcast which SSID, and change it per-AP. IMPORTANT SEMANTICS (verified): ssidOverrides[].ssidEnable is what decides whether an SSID is on the air on that AP; the sibling enable flag governs per-AP name/PSK/VLAN overrides and does NOT gate broadcast. Use this to keep an SSID on one AP only.

v2_channel_utilA

Sample 2.4/5 GHz channel utilisation over time and report mean/median/min/max per channel. Use BEFORE and AFTER any RF change — this band swings 30-55 points on its own, so a single reading proves nothing and a short baseline will let you claim any result you like.

v2_client_survivalA

Snapshot every wireless client, wait, then re-check and name anything that disappeared. Run this after any RF or SSID change — it is how you catch a setting that silently evicted an IoT device instead of just reading "Success".

v2_radar_auditA

Settle a DFS argument with evidence rather than opinion. Reports which radios are actually on DFS channels, watches them live for an unrequested channel change, checks AP uptime (a radar hit cannot happen without one or the other), and sweeps the v1 event log per-AP for radar entries. States plainly what it can and cannot prove.

v2_security_auditA

Security posture of every SSID in one table: WPA version, PMF (802.11w) mode, 802.11r, guest isolation, band, VLAN, broadcast. Flags the combinations that are known to destabilise clients — notably PMF Mandatory (value 1) on WPA2-PSK, and WPA2/WPA3 transition mode, which is defeated by a documented downgrade attack and gives WPA2 security with WPA3 compatibility problems.

v2_client_historyA

Every association a given client made over N days: which AP, which channel, which band, and how often it disconnected. This is how you tell a band-steering problem from a roaming problem from a device that simply drops. Uses the v1 log API, which is the only one that returns events on 6.2+.

v2_interference_auditA

REAL interference detection, not inference. Uses the AP's own radio counters — interUtil (airtime lost to NON-WiFi emitters), busyUtil, txUtil/rxUtil, and rx/tx retry and drop deltas — sampled over time. Separates "the band is busy with WiFi" from "something non-WiFi is transmitting", which is the distinction that makes every other interference claim a guess. Optionally correlates against live aircraft overhead (opt-in, sends an approximate location to a public flight API).

v2_getA

GET any v2 path (relative to /api/v2). Use for anything the typed tools do not cover. Returns errorCode triage on failure.

v2_writeC

Escape hatch: any PATCH/POST/PUT/DELETE with automatic read-back and diff. dryRun defaults true. [READ-ONLY MODE: returns the exact payload instead of sending it]

v2_site_settingsB

FULL site settings decoded: roaming (fast/AI/non-stick/ping-pong/force-disassoc), band steering, airtime fairness, mesh, beacon+DTIM+RTS, LED, LLDP, NTP, alerts, remote syslog, auto-upgrade. Flags risky values.

v2_controller_settingsA

Controller-level configuration: name, timezone, DST, controller NTP, HTTP/HTTPS ports, certificate, mail server, logging levels, built-in RADIUS, device access management, data retention, uptime and version. Flags controller NTP off and plaintext management.

v2_servicesB

Every site service in one call: SNMP, SSH, mDNS, UPnP, IPTV/IGMP proxy, DHCP reservations, PoE schedules, reboot schedules, wireless MAC filter, 802.1X, MAC authentication, RADIUS profiles, rate-limit profiles, time ranges and IP/MAC groups. Flags insecure or unset services.

v2_wanB

WAN/internet view: WAN network config, number of WAN ports, per-port state and IP. On a controller with no Omada gateway this reports what is and is not manageable.

v2_switchesC

Switch-level state: model, firmware, uptime, CPU/mem, STP mode + bridge priority + timers, device-level loopback detection, jumbo frames, SNMP, LAGs, LLDP uplink/downlink neighbours. Flags STP-disabled switches.

v2_switch_portsA

Every port on every switch (or one switch), decoded with VLAN NAMES: link/speed, PVID, tagged/untagged, VLAN profile + profileOverride + profileVlanOverride, PoE, STP, loopback detection, storm control, isolation. Emits warnings for STP-off / loopback-off / all-VLAN / dead ports, and marks inter-switch trunks.

v2_port_statsA

Live per-port counters: link state, tx/rx bytes and packets, ERRORS and DROPS, plus PoE draw in watts per port and total budget. This is the tool for "is a cable or a device misbehaving".

v2_switch_statsB

Per-switch statistics view: per-port operation, speeds, PoE and traffic totals as the Statistics page shows them.

v2_vlan_profilesB

Switch VLAN port profiles (the "All"/"Disable"/custom profiles) fully decoded with VLAN names, plus which profile each switch port currently uses. This is what actually enforces per-port VLAN membership.

v2_lan_networksB

Every VLAN: name, tag, subnet, DHCP scope, IGMP/MLD snooping, DHCP guard, purpose. Flags networks with snooping off.

v2_ap_radiosA

Per-AP everything in REAL UNITS: channel/width/power per band, allowed channels, RSSI kick, load balance, WMM, OFDMA, mesh, management SSID, multicast VLAN, wired uplink rate, per-AP SSID enablement. Omit apMac for all APs.

v2_ssidsA

Full config of every SSID: band, VLAN, security/PMF, 802.11r, guest isolation, prohibitWifiShare (the TTL clamp), rate control, MAC filter, schedule, multicast/broadcast handling. Passphrases redacted unless showSecrets.

v2_rf_healthB

RF diagnostics without touching anything: per-channel AP/client counts and channel utilisation on both bands, per-AP interference, client RSSI distribution, and the controller's own wireless experience index history. The closest thing this build has to a wireless test.

v2_rogue_apsA

Neighbouring/rogue APs seen by your own APs — SSID, BSSID, channel, signal, security. Empty until a scan has run.

v2_clientsA

Known-client list: name, MAC, vendor, wired/wireless, VLAN, traffic totals, last seen, blocked state. NOTE this build's endpoint carries NO RSSI, SSID, AP or rate data — the tool says so rather than inventing it. Pass a mac to get that one client's full detail (vendor, OS, device type, IP settings, rate limit).

v2_past_connectionsB

Historical client sessions: MAC, SSID/network, AP, duration, traffic, disconnect reason. Use for "why did this device drop".

v2_topologyA

Physical topology: every node, what it is connected to, on which port, at what speed. Use this to confirm which ports are inter-switch trunks before touching loopback detection.

v2_eventsB

Site EVENT log with real filters: level (Error/Warning/Information), module (Operation/System/Device/Client), time window in hours, free-text search, paging. Diagnoses an empty result rather than reporting silence as health.

v2_alertsB

Site ALERT log (the subset of events flagged as alerts), with archived/unarchived filter, level, module, time window and search.

v2_audit_logsA

AUDIT log: who changed what, from which IP, with old and new values. This is the accountability trail — separate from events.

v2_log_settingsB

Everything that governs whether logs exist at all: site alert switch, remote syslog target, controller log retention policy, controller logging levels, webhook targets, and the current stored-log count against the cap. Explains an empty log rather than leaving it mysterious.

v2_notificationsB

The notification catalogue — which events are recorded, which raise alerts, and which send mail or webhook. This is the real alerting control; the alert.enable field in site settings is NOT writable and does not correspond to this page. Reads controller scope and site scope separately, because they are different catalogues.

v2_log_diagnoseA

Why is the log empty? Runs the full evidence chain in one call: every log surface (site/controller events, alerts, audit), the stored-log counter vs its cap, retention policy, the notification catalogues that decide what gets recorded at all, and remote syslog state. Use this before concluding a quiet network — an empty log and a healthy network look identical.

v2_dfs_checkA

DFS/radar evidence. Compares each 5 GHz radio's CONFIGURED channel against the channel it is ACTUALLY operating on. A radar detection forces a 30-minute vacate onto a different channel, so configured != actual is a radar event caught in the act. Also flags which radios are on DFS channels at all, and whether any sits in the 5600-5650 MHz weather-radar sub-band.

v2_set_ap_ssidA

Enable or disable one SSID on ONE access point. This is the only real on/off switch an SSID has — there is no global enable field; on-air state lives per-AP in ssidOverrides[].ssidEnable. Use it to keep an SSID in one room only, or to cut beacon overhead on a busy band without changing coverage anywhere. [READ-ONLY MODE: returns the exact payload instead of sending it]

v2_diagnosticsA

The 6.2 diagnostic surface in one call: client distribution per band / per SSID / per AP, RSSI histogram, association failures (timeout, WPA failure, blocked), association-time buckets, client activity over time, longest-uptime devices, top applications, per-channel utilisation, per-AP interference, and PoE budget. This is the tool for "is the wireless actually healthy", as opposed to "is it configured correctly".

v2_rf_planningA

AI RF Planning — the controller's own channel/width/power optimiser. Reads the current plan settings, the run history with before/after experience index, and the status of the last run. Can trigger a new run with run:true. ⚠ A run re-plans channels across every AP and applies them, overriding any manual channel choice.

v2_speedtestA

Run the controller WAN speed test and poll for the result. NOTE: verified unsupported on this build (-1600) because the site has no Omada gateway — the tool says so explicitly instead of hanging. Kept for the day an ER-series router is adopted. [READ-ONLY MODE: returns the exact payload instead of sending it]

v2_health_auditA

One-shot audit across site settings, controller settings, services, switches, ports, VLAN profiles, radios, SSIDs, VLANs and logs. Returns a ranked list of misconfigurations, each with the exact tool call that fixes it and its blast radius.

v2_usersA

Controller accounts: role, type, 2FA, temporary-validity window and hours left. This server can DELETE an account but can never create, extend or enable one.

v2_set_ap_radioA

Set AP channel / width / tx power in REAL UNITS (channel 100, widthMHz 40). Warns on DFS and the 5600-5650 MHz weather-radar band. Read-back verified. [READ-ONLY MODE: returns the exact payload instead of sending it]

v2_set_ap_load_balanceB

Fix or set per-radio load balancing. Guards the maxClients:1 landmine — refuses maxClients under 5 unless force:true. [READ-ONLY MODE: returns the exact payload instead of sending it]

v2_set_ap_rssi_kickA

Set the RSSI threshold that disassociates a client clinging to a weak AP — the fix for sticky clients that sit at -80 dBm while a -55 dBm AP is in the same room. TP-Link: "if you did not set it, that is why you don't switch." Gentler than nonStickRoaming: it does not emit the MBO/OCE "cannot handle new STA" frames that feed Android's BSSID blocklist. ⚠ Set it BELOW the weakest signal you still want to keep, or you will disconnect distant devices you rely on. [READ-ONLY MODE: returns the exact payload instead of sending it]

v2_set_ap_mgmt_ssidA

⚠ MEASURED NOT TO WORK on 6.2.14.11: mgtSsidSetting is read-only. The write returns success and the value reverts on read-back, the field appears in none of the 381 GUI modules, and no site-level control exists. Kept only so the attempt is recorded honestly rather than repeated — the tool will report REVERTED. Settle it with a phone scan instead. [READ-ONLY MODE: returns the exact payload instead of sending it]

v2_set_site_roamingA

Set site roaming: fastRoaming (802.11r/k), aiRoaming, nonStickRoaming, pingPongSuppression, forceDisassociation. NOTE nonStickRoaming and forceDisassociation send MBO/OCE "cannot handle new STA", which feeds the Android BSSID blocklist and produces the "phone thinks it is banned" symptom. [READ-ONLY MODE: returns the exact payload instead of sending it]

v2_set_site_featureB

Toggle site-wide features: airtime fairness per band, alert logging (the audit trail), remote syslog target, LED, LLDP, auto-upgrade, band steering. [READ-ONLY MODE: returns the exact payload instead of sending it]

v2_set_switch_stpA

Enable/disable STP on a switch and set bridge priority and timers (lower priority wins; 4096 forces root). ⚠ Enabling STP triggers ~30 s of listening/learning — ports carrying APs or cameras WILL drop. Do it when the network is quiet. [READ-ONLY MODE: returns the exact payload instead of sending it]

v2_set_portA

Set one switch port: loopback detection, STP on/off, STP edge-port and BPDU/root guard, storm-control thresholds, port isolation, PoE, enable/disable. ⚠ NEVER enable loopback detection on a switch-to-switch trunk — an edge loop could then shut the uplink and partition the network. The tool refuses trunk ports unless force:true. [READ-ONLY MODE: returns the exact payload instead of sending it]

v2_set_ports_bulkA

Apply one change to many ports at once, with the same trunk guard as v2_set_port. Select ports explicitly, or by selector: "access" (all non-trunk), "dead" (link down, non-trunk — zero blast radius), "all". Use this with edgePort:true before enabling STP on a switch: it is the step that turns a 30-second convergence outage into no outage at all on the access ports. Each port is written and verified individually. [READ-ONLY MODE: returns the exact payload instead of sending it]

v2_set_port_pvidA

Set a switch port's PVID — the VLAN an UNTAGGED frame lands on. This is what decides where a laptop plugged straight into the port ends up, and it is what makes a rescue/console port actually work without configuring the laptop. The tagged VLAN list is preserved unless you replace it. Refuses inter-switch trunks unless force:true. [READ-ONLY MODE: returns the exact payload instead of sending it]

v2_set_port_profileA

Bind a switch port to a VLAN port profile — the real fix for "every port permits every VLAN". Refuses to change an inter-switch trunk unless force:true, because a wrong profile there partitions the network. [READ-ONLY MODE: returns the exact payload instead of sending it]

v2_set_lan_igmpA

Enable/disable IGMP and MLD snooping on a VLAN. ⚠ Without an IGMP querier on that VLAN, snooping STOPS multicast instead of optimising it — test TVs and speakers immediately after enabling. [READ-ONLY MODE: returns the exact payload instead of sending it]

v2_set_ssidA

Change one SSID: enable/disable, broadcast, 802.11r fast roaming, PMF, guest isolation, prohibitWifiShare (the TTL clamp that breaks VMs and hotspots), VLAN and rate-limit profile. Read-back verified. [READ-ONLY MODE: returns the exact payload instead of sending it]

v2_set_serviceA

Toggle site services: SNMP v1/v2c/v3, SSH access, mDNS repeater, UPnP. Each is read back and diffed. [READ-ONLY MODE: returns the exact payload instead of sending it]

v2_delete_userA

DELETE a controller account. Deliberately the only account operation this server has: deleting removes access, it cannot grant it, so no credential in this config can mint admin. Refuses the account you are logged in as and refuses Owner/root accounts. Requires confirm:true. [READ-ONLY MODE: returns the exact payload instead of sending it]

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

B3.1/5.0

Scored across 59 tools

Disambiguation3/5

The set has many distinct tools, but several overlaps: generic v2_get/v2_write/oa_get compete with typed readers/writers; v2_ssid_broadcast and v2_set_ap_ssid both control per-AP SSID state; v2_radar_audit and v2_dfs_check both cover DFS radar evidence; and diagnostic tools like v2_health_audit, v2_diagnostics, v2_rf_health, and v2_security_audit overlap. Descriptions are detailed, which helps, but an agent still faces real misselection risk.

Naming Consistency4/5

Consistent v2_ snake_case prefix and set_* write convention, but read tools are mostly noun-based (v2_clients, v2_ssids, v2_events) rather than the verb_noun pattern, and oa_get/v2_get/v2_write introduce mixed verb styles. Still readable and largely predictable.

Tool Count2/5

59 tools is very heavy; for a single controller domain, many typed tools duplicate what v2_get/v2_write can do, and the diagnostic/audit suite is sprawling. The broad Omada feature set provides some justification, but the surface is over-scoped.

Completeness3/5

Covers extensive read coverage plus many targeted writes, but CRUD is incomplete: no create/delete for VLANs, SSIDs, users (delete only), port profiles, DHCP reservations, or many service objects, and no firmware/backup/reboot actions. Agents can work around some gaps via generic paths, but lifecycle dead ends remain.

Maintenance

ActivityMaintained
ResponsivenessNo issues