PluginBench
MCP Server
Maintained
MIT

MikroMCP MCP Server

io.github.AliKarami/mikromcp

AI-native network automation for MikroTik RouterOS with typed tools, dry-run, RBAC, audit logs, and rollback.

What is the MikroMCP MCP server?

MikroMCP is an open-source Model Context Protocol (MCP) server that exposes MikroTik RouterOS as 122 typed, auditable tools for AI assistants. It lets Claude, Cursor, and other MCP clients inspect, diagnose, and safely operate routers in natural language with schema validation, idempotent writes, dry-run previews, RBAC, audit logging, snapshots, and rollback workflows.

MikroMCP turns RouterOS into a production-minded MCP control plane by wrapping the REST API in safety layers that AI agents need: strict schemas, confirmation gates, per-router circuit breakers, and change workflows. Instead of asking LLMs to improvise CLI commands against production network gear, MikroMCP provides a controlled tool surface for infrastructure automation, DevOps, and modern router management.

How to install MikroMCP

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • MIKROMCP_CONFIG_PATH

    Path to the MikroMCP router registry YAML file. Defaults to ~/.mikromcp/routers.yaml.

  • MIKROMCP_STDIO_IDENTITY

    Optional identity name for stdio transport RBAC. Omit to use the built-in superadmin identity.

  • MIKROMCP_LOG_LEVEL

    Optional log level: trace, debug, info, warn, or error. Defaults to info.

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "mikromcp": {
      "command": "npx",
      "args": [
        "-y",
        "mikromcp"
      ],
      "env": {
        "MIKROMCP_CONFIG_PATH": "<YOUR_MIKROMCP_CONFIG_PATH>",
        "MIKROMCP_STDIO_IDENTITY": "<YOUR_MIKROMCP_STDIO_IDENTITY>",
        "MIKROMCP_LOG_LEVEL": "<YOUR_MIKROMCP_LOG_LEVEL>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • System status and management — Inspect system resources, RouterOS version, reboot, manage packages, files, scripts, scheduler jobs, and containers
  • Network operations — Manage interfaces, VLANs, IP addresses, DHCP leases, DNS static records, bridge ports, and WiFi clients
  • Firewall and policy — Configure filter/NAT rules, mangle rules, address lists, route tables, and routing rules
  • Routing visibility — View static routes, routing tables, BGP peers, and OSPF neighbors
  • SwOS switches — Experimental support for MikroTik SwOS and SwOS Lite switches: port links, PoE, SFP diagnostics, and guarded writes
  • Diagnostics — Run router-originated ping, traceroute, torch, filter logs, and execute guarded SSH commands
  • Change safety — Dry-run changes, create snapshots, use write journal, plan_changes, apply_plan, and rollback_change
  • Secure access — HTTP bearer auth, bcrypt token hashes, RBAC, router/tool restrictions, and confirmation tokens
  • Audit and logging — Structured logs, audit logs, correlation IDs, and per-router circuit breakers

Use cases

  • Inspect router state and summarize system resources, RouterOS version, interfaces, routes, DNS settings, and logs without memorizing CLI syntax
  • Review firewall filter and NAT rules to identify disabled rules, overlapping port forwards, broad accept rules, and missing comments
  • Dry-run network changes (static routes, DNS records, address lists) with exact diffs before applying to production
  • Diagnose interface health and run ping/traceroute from the router to detect packet loss and traffic anomalies
  • Chain tool calls across multiple routers to manage a MikroTik fleet with RBAC and audit trails for compliance
  • Plan, review, and rollback configuration changes with confirmation gates and snapshots for safe multi-step workflows

MikroMCP MCP server FAQ

What is MikroMCP?

MikroMCP is an open-source MCP server that exposes MikroTik RouterOS as 122 typed, auditable tools — letting AI assistants inspect, diagnose, and safely operate routers in natural language instead of improvising CLI commands.

How does MikroMCP differ from using RouterOS REST API directly?

The RouterOS REST API exposes raw endpoints. MikroMCP wraps them in schema-validated, idempotent, dry-run-able tools with RBAC, audit logging, snapshots, and rollback — the safety layer an LLM needs before touching production network gear.

How do I install MikroMCP in Claude Desktop?

Install via npm (`npm install -g mikromcp`), run `mikromcp init` to configure your router credentials, then register the server in Claude Desktop's config file. See the Getting Started guide for detailed steps.

What authentication does MikroMCP require?

MikroMCP requires RouterOS REST API credentials (username/password or bearer token), stored securely in `~/.mikromcp/.env`. It supports bcrypt token hashes, RBAC per router, and tool-level authorization.

Is MikroMCP free?

Yes, MikroMCP is open-source under the MIT License and free to use. It requires a MikroTik router with RouterOS 7.x and the REST API enabled.

Can I use MikroMCP with Cursor or other MCP clients?

Yes, MikroMCP works with any MCP-compatible client — Claude Desktop, Claude Code, Cursor, Codex, and others — over stdio or HTTP/SSE transport.

README (reference)

Source of truth, from the repository.

MikroMCP

<p align="center"> <picture> <source media="(prefers-color-scheme: dark)" srcset="./docs/assets/MikroMCP-logo-dark.png"> <source media="(prefers-color-scheme: light)" srcset="./docs/assets/MikroMCP-logo-light.png"> <img alt="MikroMCP" src="./docs/assets/MikroMCP-logo-dark.png" width="700"> </picture> </p>

AI-native network automation for MikroTik RouterOS. MikroMCP exposes RouterOS as a typed, auditable Model Context Protocol server so Claude, Cursor, Codex, and other MCP clients can inspect, diagnose, and safely operate MikroTik routers in natural language.

CI Release Version License: MIT Node.js >= 22 RouterOS 7.x MCP Server Tools MikroMCP MCP server

MikroMCP exists because raw router CLI access is the wrong abstraction for AI agents. RouterOS is powerful, but asking an LLM to improvise shell commands against production network gear is risky. MikroMCP gives agents a controlled tool surface: strict schemas, idempotent writes, dry-run previews, per-router circuit breakers, retry policies, RBAC, audit logs, snapshots, and rollback-aware change workflows.

In one sentence: MikroMCP turns MikroTik RouterOS into a production-minded MCP control plane for AI infrastructure, DevOps automation, and modern router management.

AI assistant connected through MikroMCP to a small MikroTik fleet, with tool calls flowing through validation, audit, and RouterOS REST


Quick Start

<p align="center"> <img src="docs/assets/quickstart.svg" alt="MikroMCP quick start: npm install -g mikromcp, mikromcp init, then ask Claude Desktop about your router" width="760"> </p>

That's the whole setup for a single-router stdio deployment. For standalone binaries, Docker, HTTP/SSE mode, the RouterOS API prerequisites, and the full 15-minute walkthrough, see the Getting Started guide.


Feature Showcase

CategoryWhat MikroMCP covers
🧭 Router managementSystem status, clock, reboot, packages, files, scripts, scheduler jobs, containers
🌐 Network operationsInterfaces, VLANs, IP addresses, DHCP leases, DNS static records, bridge ports, WiFi clients
🔥 Firewall and policyFilter/NAT rules, mangle rules, address lists, route tables, routing rules
🛰️ Routing visibilityStatic routes, routing tables, BGP peers, OSPF neighbors
🔀 SwOS switchesExperimental. MikroTik SwOS and SwOS Lite switches (deviceType: "swos") over the reverse-engineered .b HTTP API: port links, PoE, SFP diagnostics, and guarded whole-blob writes with a firmware-compatibility check
🔐 Secure accessHTTP bearer auth, bcrypt token hashes, RBAC, router/tool restrictions, confirmation tokens
🧪 DiagnosticsRouter-originated ping, traceroute, torch, log filtering, guarded SSH command execution
🛡️ Change safetyDry-run, idempotent writes, snapshots, write journal, plan_changes, apply_plan, rollback_change
⚙️ Production behaviorRetries for read tools, per-router circuit breakers, correlation IDs, structured logs, audit logs
🤖 AI-agent fitHuman-readable responses plus structured JSON content for reasoning, chaining, and automation; server advertises an instructions string on MCP initialize so clients self-configure; optional routerId resolved via MIKROMCP_DEFAULT_ROUTER for single-router setups; usage skill for safe, guided tool use in Claude Code
🧩 MCP compatibilitystdio for desktop clients, Streamable HTTP and legacy SSE for remote or service-style clients

122 typed tools in total — browse the full catalog with parameters, defaults, and copy-paste example prompts in Available Tools.


Demo

Usage

<p align="center"> <img src="docs/assets/demo-1.gif" width="900" /> </p>

Review by Claude

Claude Reviewed Router Configuration


Real-World Usage Examples

Router Inspection

Use MikroMCP to inspect core-01. Summarize system resources, RouterOS version,
running interfaces, active routes, DNS settings, and recent warning/error logs.
Flag anything that looks operationally risky.

Firewall Management

List firewall filter and NAT rules on edge-01. Identify disabled rules,
overlapping port forwards, broad accept rules, and anything without comments.
Do not change anything yet.

Safe Static Route Change

Dry-run a route on core-01 for 10.20.0.0/16 via 192.168.88.1 in the main table.
Show the exact planned diff and tell me whether an existing route conflicts.

WireGuard Operations

Show WireGuard peers on branch-02. Sort by last handshake age and flag peers
that have not handshaken recently or have no transfer counters.

Interface Diagnostics

Check interface health on edge-01, then run ping and traceroute from the router
to 1.1.1.1. If packet loss is present, use torch on the WAN interface for a
short traffic snapshot.

Plan / Apply / Rollback Workflow

Create a change plan that adds a DNS record and a firewall address-list entry
on edge-01. Use dry-run first, explain the plan, then wait for approval before
applying anything.

Why MikroMCP Is Useful For AI Agents

MCP gives LLMs a standard way to call tools. MikroMCP makes RouterOS a high-quality MCP target by turning network operations into well-described, machine-readable, permission-aware actions.

AI assistants can use MikroMCP to:

  • Investigate router state without memorizing RouterOS command syntax.
  • Chain tool calls across interfaces, routes, firewall rules, logs, and diagnostics.
  • Return both operator-friendly summaries and structured JSON for follow-up reasoning.
  • Preview changes before mutation and explain exactly what would happen.
  • Respect tool-level authorization, router scoping, maintenance windows, and confirmation gates.

FAQ

What is MikroMCP?

MikroMCP is an open-source Model Context Protocol (MCP) server that exposes MikroTik RouterOS as 122 typed, auditable tools — letting AI assistants inspect, diagnose, and safely operate routers in natural language instead of improvising CLI commands.

MikroMCP vs RouterOS API

The RouterOS REST/API exposes raw endpoints. MikroMCP wraps them in schema-validated, idempotent, dry-run-able tools with RBAC, audit logging, snapshots, and rollback — the safety layer an LLM needs before it touches production gear.

MikroMCP vs SSH automation

Instead of brittle SSH scripts that screen-scrape CLI output, MikroMCP returns structured, typed results with confirmation gates and per-router circuit breakers. SSH is used only where REST can't reach — ping, traceroute, torch, and guarded run_command.

MikroMCP for Claude Code

MikroMCP speaks MCP over stdio and HTTP/SSE, so Claude Code and Claude Desktop drive RouterOS directly. Pair it with the bundled usage skill for safe, guided workflows.

MikroMCP for Codex

Codex connects to MikroMCP over the standard MCP protocol — see Connecting to AI Assistants.

MikroMCP for Cursor

Cursor connects to MikroMCP as an MCP server (stdio or HTTP) to inspect and manage MikroTik routers without leaving the editor.

MikroMCP for OpenClaw

Any MCP-compatible client — OpenClaw included — can use MikroMCP; configure it as a stdio or HTTP MCP server.

RouterOS AI Automation Guide

Start with Getting Started to install and connect, then use the usage skill and Available Tools to automate RouterOS safely with an AI assistant.

Best MCP Servers for Network Engineers

MikroMCP is purpose-built for MikroTik/RouterOS operations with production-grade safety — dry-run, rollback, audit, and RBAC — making it a strong MCP choice for network engineers adopting AI tooling.


Documentation

The README stays intentionally short. Everything below is documented in depth in the wiki:

ResourceUse it for
Getting StartedInstall (npm, binary, Docker), configure, and connect in 15 minutes
RouterOS API SetupEnable the REST API, create a user, TLS and firewall
ConfigurationRouter registry, credentials, all environment variables
RunningRun commands, HTTP/SSE transport, troubleshooting
Connecting to Claude DesktopRegister MikroMCP in Claude Desktop
Connecting to AI AssistantsClaude Code, Cursor, Codex, HTTP/Docker/systemd
Using the SkillInstall the MikroMCP usage skill so your assistant drives the tools safely
Available ToolsAll 122 tools — parameters and example prompts
ArchitectureSystem layers, request pipeline, auth model
Error HandlingError categories, retry engine, circuit breaker
SecurityThreat model, hardening checklist, vulnerability reporting
DevelopmentProject structure, tests, MCP Inspector workflow
ContributingAdding tools, coding conventions, PR checklist
Roadmap · ROADMAP.mdShipped milestones and guiding principles

Contributing

Issues, bug reports, tool requests, documentation improvements, and pull requests are welcome.

Good first contributions:

  • Add a read-only tool for an uncovered RouterOS surface.
  • Add screenshots, demo GIFs, or topology diagrams.
  • Expand tests around RouterOS response normalization and idempotency edge cases.
  • Help validate RouterOS version compatibility across real MikroTik devices and CHR.

Development standards:

  • TypeScript strict mode, ESM imports with .js extensions
  • Zod schemas with .strict(), idempotency and dryRun for write tools
  • MikroMCPError for domain errors, focused Vitest coverage for every tool

Please open an issue before large changes so maintainers can align on scope.

Acknowledgements

  • @f0086 — SwOS / SwOS Lite switch support (v1.9.0), which took MikroMCP beyond RouterOS for the first time.

Security

MikroMCP controls real network devices — treat it like an operations system: least-privilege RouterOS users, verified TLS (or pinned fingerprints), credentials only in ~/.mikromcp/.env, scoped RBAC identities, and audit logging for shared use. The full hardening checklist and vulnerability-reporting process are on the Security page.


Community And Support

  • ⭐ Star the repository if MikroMCP helps your MikroTik or MCP workflow.
  • 🍴 Fork it to add RouterOS surfaces your network depends on.
  • 🧵 Open an issue for bugs, feature requests, compatibility notes, or documentation gaps.

License

MikroMCP is released under the MIT License.

Related MCP servers

Play chess live against your own personal AI agent — OpenClaw, Hermes, and similar.

0
MIT
View repository →

Unofficial, self-hosted MCP server for the documented OpenSolar API.

0
TypeScript
MIT
View repository →
STStoryflo logo

Storyflo

Active

Curated audio news, daily briefings, the Declassified library + market-linked signals.

1
JavaScript
MIT
View repository →

Provider resolution for AI apps — search, rank, hold, confirm bookings across your provider network.

0
Python
MIT
View repository →
ALAllNewsAPI logo

Get access to real-time and historical news data including top headlines from global sources

1
TypeScript
MIT
View repository →

Measure whether your AI agrees with itself using statistical consensus metrics.

0
Dockerfile
View repository →