# io.github.KallistoX/mcp-unifi-applications (pypi · mcp-unifi-applications)

Queryable UniFi API docs: endpoint search, schemas, code examples. No controller access.

- Trust score: 58/100 (low)
- Change this week: −12
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-20

## Components

- pypi · `mcp-unifi-applications`: 58/100 (this document), [markdown](https://verifymcp.io/servers/kallistox-mcp-unifi-applications/mcp-unifi-applications.md), [page](https://verifymcp.io/servers/kallistox-mcp-unifi-applications/mcp-unifi-applications)

## Channel facts

- Registry: `pypi`
- Package: `mcp-unifi-applications`
- Version: `0.4.0`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-20.

- **Supply Chain Security**: 50/100
  - Malware scan not yet available for this package.
  - No known CVEs affecting this package version or its production dependencies.
  - Runs setuptools.build_meta at install time, a recognised native-build step with no shell scripting around it.
  - 1 of 16 dependencies flagged as unhealthy.
- **Provenance & Transparency**: 32/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - License check failed: no license is declared.
  - Actively maintained (last published 9 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 76/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 1577 tokens (~157/item across 10 items; 10 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 37/100
  - Stability observed for 11 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 10 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 11 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a current MCP spec version (2026-07-28).

## Install

### How do I install the io.github.KallistoX/mcp-unifi-applications server?

io.github.KallistoX/mcp-unifi-applications runs locally as a PyPI package, launched with uvx mcp-unifi-applications. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add kallistox-mcp-unifi-applications -- uvx mcp-unifi-applications
```

### Cursor

```json
{
  "mcpServers": {
    "kallistox-mcp-unifi-applications": {
      "command": "uvx",
      "args": [
        "mcp-unifi-applications"
      ]
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "kallistox-mcp-unifi-applications": {
      "command": "uvx",
      "args": [
        "mcp-unifi-applications"
      ]
    }
  }
}
```

### Codex

```bash
codex mcp add kallistox-mcp-unifi-applications -- uvx mcp-unifi-applications
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "kallistox-mcp-unifi-applications": {
      "type": "local",
      "command": [
        "uvx",
        "mcp-unifi-applications"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add kallistox-mcp-unifi-applications --command uvx --arg mcp-unifi-applications
```

### Hermes

```yaml
mcp_servers:
  kallistox-mcp-unifi-applications:
    command: "uvx"
    args: ["mcp-unifi-applications"]
```

### Netclaw

```json
{
  "McpServers": {
    "kallistox-mcp-unifi-applications": {
      "Transport": "stdio",
      "Command": "uvx",
      "Arguments": [
        "mcp-unifi-applications"
      ]
    }
  }
}
```

### Vellum

```bash
assistant mcp add kallistox-mcp-unifi-applications -t stdio -c uvx -a mcp-unifi-applications
```

### Other

```json
{
  "mcpServers": {
    "kallistox-mcp-unifi-applications": {
      "command": "uvx",
      "args": [
        "mcp-unifi-applications"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-19 (score 58, +1)

No change was recorded against any check on this day. Stability & Change Management went from 30 to 33. That category is still filling its 30-day observation window: 9 days of observed history at the previous scan, 10 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-17 (score 57, +1)

No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-15 (score 56, +1)

No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-14 (score 55, −15)

- [security regression] Malware scan: pass → unverified

### 2026-09-13 (score 70, +1)

No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-12 (score 69, +15)

- [security improvement] Malware scan: unverified → pass

### 2026-09-10 (score 54, 0)

- [security improvement] Malware scan: unverified → pass
- [functional regression] Schema quality: pass → fail
- [functional improvement] Stability: unverified → 0.03
- [functional] Package version: 0.2.0 → 0.4.0
- [functional] Package version: 0.2.0 → 0.3.1

### 2026-09-09 (score 54)

First indexed and scored.

## MCP tools (10)

### `list_endpoints` (~134 tokens)

List Endpoints

Browse the endpoint catalogue: one line per endpoint with method, path, slug
and title.

Returns at most 200 lines; beyond that the reply says how many were withheld and
which filters would narrow it. For finding a specific endpoint, search_endpoints
ranks by relevance instead. Unknown filter values are rejected by name rather
than returned as an empty result.

Input parameters:

- `app`: Optional app filter (network, protect, site-manager, innerspace, mobility, carrier-fabric). Omit to list all.
- `method`: Optional HTTP method filter (GET, POST, PUT, DELETE, PATCH).

Output parameters:

- `result` (string)

### `search_endpoints` (~163 tokens)

Search Endpoints

Find endpoints by name, path fragment, method or description.

Returns up to ten matches ranked by relevance, each as a slug, method, path,
title and a one-line description. Matching is fuzzy but floored: a query that
resembles nothing returns no matches rather than the least-bad guess. Pass a
result's slug to get_endpoint for the full schema. Unknown filter values are
rejected by name.

Input parameters:

- `app`: Optional app filter (network, protect, site-manager, innerspace, mobility, carrier-fabric). Omit to search all.
- `method`: Optional HTTP method filter (GET, POST, PUT, DELETE, PATCH).
- `query` (string, required): Search term (endpoint name, path fragment, or keyword).

Output parameters:

- `result` (string)

### `get_endpoint` (~204 tokens)

Get Endpoint

Get everything documented about one endpoint: method, path, description,
path and query parameters, request body and response fields.

Returns readable text: a nested field list with types, required markers and
descriptions, discriminator variants in brackets and enum values inline, folded
at three levels deep. Large endpoints run to tens of thousands of characters —
when you already know which field you need, get_field_schema returns that
subtree alone. An unknown slug returns close matches rather than an error.

Input parameters:

- `slug` (string, required): Endpoint identifier, app-qualified ('network/createnetwork') or bare   ('createnetwork') when only one application has it. Use   search_endpoints or list_endpoints to find one.
- `summary` (boolean): True (default) returns the folded text above. False returns the raw      scraped JSON — complete and unfolded to every depth, several times      larger, and only worth it when the folding hides somet…

Output parameters:

- `result` (string)

### `get_example` (~234 tokens)

Get Example

Get a runnable request for one endpoint, in one language, as published by
Ubiquiti.

Returns a heading naming the endpoint, language and mode, followed by a single
code block. The request shape is authoritative; host addresses, site ids and API
keys are placeholders to fill in. Bodies show the schema's default values, not a
worked example — combine with get_endpoint or get_field_schema when the payload
matters. If the requested language and mode pair does not exist, the reply lists
the pairs that do instead of failing.

Input parameters:

- `language` (string): One of curl, go, nodejs, python, ansible.
- `mode`: 'local' addresses the console directly (https://<console-ip>/proxy/…);   'remote' goes through the UniFi cloud API (api.ui.com). Defaults to   'local', except for the cloud-only applications — site-m…
- `slug` (string, required): Endpoint identifier, app-qualified or bare when unambiguous.

Output parameters:

- `result` (string)

### `get_response_sample` (~96 tokens)

Get Response Sample

Get the sample response body published for one endpoint.

Returns raw JSON exactly as the documentation shows it, with placeholder values.
About two thirds of endpoints have one; the rest say so plainly. This is the
shape of a successful reply — for the field-by-field schema including types and
which fields are optional, use get_endpoint.

Input parameters:

- `slug` (string, required): Endpoint identifier (e.g. 'network/getnetworksoverviewpage').

Output parameters:

- `result` (string)

### `find_field` (~147 tokens)

Find Field

Locate a field by name across every endpoint, including inside discriminator
variants.

Returns one line per occurrence: endpoint slug, dotted path, and which schema
section it sits in (request body, parameters, or response). Common names appear
hundreds of times; the reply is capped at 50 and states the true total and how
many endpoints are involved, so a short list is never mistaken for a complete
one. Paths from here can be passed straight to get_field_schema. A name that
matches nothing returns close alternatives.

Input parameters:

- `field_name` (string, required): The field name to search for (case-insensitive).
- `slug`: Optional — limit search to a specific endpoint.

Output parameters:

- `result` (string)

### `get_field_schema` (~123 tokens)

Get Field Schema

Drill into a specific field's schema within an endpoint.

Instead of fetching the full 70KB endpoint schema, use this to get just the
subtree you need. Paths from find_field output work directly.

Input parameters:

- `field_path` (string, required): Dotted path to the field, with discriminator variants in brackets.         Examples: 'dhcpV4', 'management[GATEWAY].dhcpV4',         'management[GATEWAY].dhcpV4.gateway'.
- `slug` (string, required): Endpoint identifier (e.g. 'network/createnetwork').

Output parameters:

- `result` (string)

### `get_endpoint_group` (~120 tokens)

Get Endpoint Group

See every operation on one resource at once, grouped by API path.

Returns each matching resource path with its endpoints beneath it — method, slug,
title and a one-line description — so the available verbs on a resource are
visible together rather than found one at a time. Matching is a substring of the
path, so 'networks' also finds nested paths, and one query can span applications.

Input parameters:

- `resource` (string, required): Resource name or path fragment (e.g. 'networks', 'acl-rules', 'wifi/broadcasts').

Output parameters:

- `result` (string)

### `get_guide` (~148 tokens)

Get Guide

Read a prose guide page: filtering syntax, error handling, getting started,
response formats.

Returns the page as markdown with its title and source URL. Omit the topic to
list what is available. Topics resolve by slug first, then by title; when the
same slug exists in several applications the reply lists them and asks for an
app rather than picking one. These pages carry the conventions that endpoint
schemas assume but do not repeat.

Input parameters:

- `app`: Optional app filter (network, protect, site-manager, innerspace, mobility, carrier-fabric). Omit to search all.
- `topic`: Guide slug or search term. Omit to list all available guides.

Output parameters:

- `result` (string)

### `get_docs_info` (~69 tokens)

Get Docs Info

Report what documentation this server is serving.

Returns one line per application: API version, when it was scraped, and how many
endpoints and guides it holds. Worth checking before trusting an answer about a
recent API change — the documentation is a point-in-time copy, not a live view.

Output parameters:

- `result` (string)

## Diagnostics

Captured diagnostic sections: Provenance, Install scripts, Dependencies. The full working is on the page: https://verifymcp.io/servers/kallistox-mcp-unifi-applications/mcp-unifi-applications#diagnostics

## Score history

- 2026-09-20: 58
- 2026-09-19: 58
- 2026-09-18: 57
- 2026-09-17: 57
- 2026-09-16: 56
- 2026-09-15: 56
- 2026-09-14: 55
- 2026-09-13: 70
- 2026-09-12: 69
- 2026-09-11: 54
- 2026-09-10: 54
- 2026-09-09: 54

## Common questions

### What is the io.github.KallistoX/mcp-unifi-applications server?

io.github.KallistoX/mcp-unifi-applications is listed in the public MCP registry as io.github.KallistoX/mcp-unifi-applications. Queryable UniFi API docs: endpoint search, schemas, code examples. No controller access. This page covers its PyPI package (mcp-unifi-applications).

### Is the io.github.KallistoX/mcp-unifi-applications server safe to use?

io.github.KallistoX/mcp-unifi-applications scores 58 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the io.github.KallistoX/mcp-unifi-applications server expose?

io.github.KallistoX/mcp-unifi-applications exposes 10 tools: list_endpoints, search_endpoints, get_endpoint, get_example, get_response_sample, and 5 more. Their descriptions and schemas cost roughly 1,438 tokens of context every time the server is loaded.

### Is the io.github.KallistoX/mcp-unifi-applications server still maintained?

io.github.KallistoX/mcp-unifi-applications is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- PyPI project: https://pypi.org/project/mcp-unifi-applications/
- Socket report: https://socket.dev/pypi/package/mcp-unifi-applications
- Repository: https://github.com/KallistoX/mcp-unifi-applications
- Changelog RSS feed: https://verifymcp.io/servers/kallistox-mcp-unifi-applications/mcp-unifi-applications.xml
- Changelog JSON feed: https://verifymcp.io/servers/kallistox-mcp-unifi-applications/mcp-unifi-applications.json
- HTML version of this page: https://verifymcp.io/servers/kallistox-mcp-unifi-applications/mcp-unifi-applications
