MCPLow riskUnclaimed

mikrotik-mcp

MCP server for MikroTik routers: firewall, NAT, routing, DHCP, DNS, WireGuard and more via SSH.

jeff-nasserijeff-nasseri/mikrotik-mcp★ 293Updated Oct 3, 2026

server.json

{
  "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
  "name": "io.github.jeff-nasseri/mikrotik-mcp",
  "description": "MCP server for MikroTik routers: firewall, NAT, routing, DHCP, DNS, WireGuard and more via SSH.",
  "repository": {
    "url": "https://github.com/jeff-nasseri/mikrotik-mcp",
    "source": "github"
  },
  "version": "0.24.0.0",
  "packages": [
    {
      "registryType": "pypi",
      "identifier": "mcp-server-mikrotik",
      "version": "0.24.0.0",
      "transport": {
        "type": "stdio"
      },
      "environmentVariables": [
        {
          "description": "IP address or hostname of the MikroTik router (single-device mode; default: 127.0.0.1). Not needed when an inventory is configured.",
          "format": "string",
          "name": "MIKROTIK_HOST"
        },
        {
          "description": "SSH username for the MikroTik router (single-device mode; default: admin)",
          "format": "string",
          "name": "MIKROTIK_USERNAME"
        },
        {
          "description": "SSH password for the MikroTik router (single-device mode)",
          "format": "string",
          "isSecret": true,
          "name": "MIKROTIK_PASSWORD"
        },
        {
          "description": "SSH port of the MikroTik router (single-device mode; default: 22)",
          "format": "string",
          "name": "MIKROTIK_PORT"
        },
        {
          "description": "Path to SSH private key file for key-based authentication (single-device mode)",
          "format": "string",
          "name": "MIKROTIK_KEY_FILENAME"
        },
        {
          "description": "When true, expose only tools that do not modify RouterOS or its file store. Use a read-only RouterOS account as defence in depth.",
          "format": "boolean",
          "name": "MIKROTIK_READ_ONLY"
        },
        {
          "description": "When true, redact recognized credentials and private key material from tool results, MCP notifications, and logs, and omit tools that return opaque sensitive payloads.",
          "format": "boolean",
          "name": "MIKROTIK_SENSITIVE_HIDING"
        },
        {
          "description": "Path to a YAML file listing multiple MikroTik devices (title, host, port, username, password, key_filename, tags, region). See docs/reference/inventory.",
          "format": "string",
          "name": "MIKROTIK_INVENTORY_FILE"
        },
        {
          "description": "Inline multi-device inventory as a YAML (or JSON) list; takes precedence over MIKROTIK_INVENTORY_FILE and the single-device variables. Holds credentials.",
          "format": "string",
          "isSecret": true,
          "name": "MIKROTIK_INVENTORY"
        }
      ]
    }
  ]
}

Permissions

DeclaredDetected
Runs code—python
Installs—pypi:mcp-server-mikrotik@0.24.0.0
Runs install scripts—None
NetworkNoneNone
Needs credentialsMIKROTIK_INVENTORYMIKROTIK_PASSWORDMIKROTIK_INVENTORYMIKROTIK_PASSWORD
Outside the workspace—None
Agent tools—None

Checks

Low risk · Nothing worth a warning was found.

Not reviewed by a person · Checked by rules; the model review is not switched on yet.

Versions

  1. #10.24.0.0latestOct 7, 2026