io.github.claymore666/ccu-mcp MCP Server
io.github.claymore666/ccu-mcp
What is the io.github.claymore666/ccu-mcp MCP server?
MCP server for controlling HomeMatic smart home devices via the CCU JSON-RPC API
How to install io.github.claymore666/ccu-mcp
Copy-paste configuration for popular MCP clients.
CCU_HOSTrequiredHostname or IP of your HomeMatic CCU (debmatic, CCU3, or OpenCCU/RaspberryMatic)
CCU_PASSWORDrequiredsecretCCU admin password (same as the WebUI login). Must be set; the value may be empty for a CCU with no password
CCU_USERCCU username
CCU_HTTPSConnect to the CCU via HTTPS (self-signed certificates supported)
CCU_PORTCCU API port (80 for HTTP, 443 for HTTPS)
CACHE_DIRDirectory for the device type cache and session persistence
MCP_ALLOWED_ORIGINSComma-separated allowlist of browser origins. Unset = no cross-origin browser access (default-deny). An allowlisted origin is reflected exactly in Access-Control-Allow-Origin (never '*'); the list also drives DNS-rebinding origin checks
MCP_ALLOWED_HOSTSExtra Host header values accepted by DNS-rebinding protection (comma-separated host:port); add your hostname when behind a proxy or container DNS name
CCU_PROFILESComma-separated names of multiple CCU targets (e.g. 'prod,dev'). Each profile takes the flat CCU_* settings prefixed CCU_<NAME>_ (CCU_PROD_HOST, ...), plus policy flags CCU_<NAME>_PROTECTED (writes need confirm:true) and CCU_<NAME>_READONLY. Unset = single default profile from the flat CCU_* vars
CCU_DEFAULT_PROFILEWhich profile from CCU_PROFILES is active at startup (default: the first listed)
CCU_TLS_VERIFYVerify the CCU's TLS certificate against the system trust store. Only meaningful with CCU_HTTPS=true. Default false, because a CCU ships a self-signed certificate — prefer CCU_TLS_FINGERPRINT or CCU_CA_CERT to verify one of those
CCU_TLS_FINGERPRINTPin the CCU's self-signed leaf certificate by its SHA-256 fingerprint (hex, colons optional). The strongest option for an appliance: the connection is rejected unless the presented certificate matches. Takes precedence over CCU_CA_CERT
CCU_CA_CERTPath to a PEM file holding the CCU's CA or self-signed certificate. The connection is then validated against it with standard chain verification
CCU_TIMEOUTTimeout for a CCU JSON-RPC call, in MILLISECONDS
CCU_SCRIPT_TIMEOUTTimeout for HomeMatic Script execution (ReGa), in MILLISECONDS — scripts are slower than plain API calls
CACHE_TTLLifetime of the on-disk device-type schema cache, in SECONDS
CCU_RATE_LIMIT_BURSTToken-bucket burst size for CCU requests — how many may be issued back to back
CCU_RATE_LIMIT_RATESustained CCU request rate, in requests per second
RESOURCE_POLL_INTERVALHow often MCP resources are polled for change notifications, in SECONDS
LOG_LEVELerror | warn | info | debug. Logs are structured JSON on stderr
Related MCP servers
MCP server for controlling HomeMatic smart home devices via the CCU JSON-RPC API

Clay Seal
Authorizes MCP tool calls against a session policy, not one call at a time.
Compare PDF or Word versions and return source-cited changes ranked by cost, time, or risk.

Manage UniFi sites, devices, clients, networks, port forwarding, DNS, and firewall
DeFi intelligence for Claude: whale tracking, alpha signals, yields, token safety. USDC on Base.

io.github.cleburn/aegis-mcp
Runtime governance enforcement for AI agents. Zero token overhead.

