Featured

Deploy OpenClaw in 60 seconds β€” 20% off logoDeploy OpenClaw in 60 seconds β€” 20% off

Launch OpenClaw on Hostinger in about 60 seconds and keep your agent live 24/7. Our referral link gives you 20% off, no coupon code needed.

Launch on Hostinger β†’
Run your Hermes agent on Hostinger, fully managed logoRun your Hermes agent on Hostinger, fully managed

Launch Hermes on Hostinger in one click, fully managed, no VPS knowledge needed. Use code ZACAARON10 for 10% off.

Launch on Hostinger β†’
Crawl and scrape any site into clean data, 10% off logoCrawl and scrape any site into clean data, 10% off

Firecrawl crawls and scrapes any site into clean markdown for your agent. Get 1,000 free credits, and new users get 10% off their first purchase.

Try Firecrawl free β†’
Your own AI agent, running 24/7 with QwikClaw logoYour own AI agent, running 24/7 with QwikClaw

QwikClaw sets up and runs an always-on OpenClaw agent for you. One click, no config files, no server setup.

Deploy now β†’
One API to scrape, enrich, and extract the internet. logoOne API to scrape, enrich, and extract the internet.

Context.dev gives your agents a single API to scrape, enrich, and extract live web data β€” no proxies, no parsers, no maintenance.

Start building free β†’
SetupClaw: done-for-you OpenClaw for founders & exec teams logoSetupClaw: done-for-you OpenClaw for founders & exec teams

White-glove OpenClaw for founders and exec teams (4–50+ employees): we install, harden, integrate your tools, and maintain it β€” secured from day one.

Get it set up for you β†’
SEO data APIs for your agent, $1 free credit logoSEO data APIs for your agent, $1 free credit

DataForSEO gives your agent live access to SERP results, keyword data, backlinks, and on-page SEO data through one API. New accounts get a $1 credit, good for up to 20,000 keyword or backlink lookups.

Try DataForSEO free β†’
Reach 47,000+ AI builders

A flat monthly placement in front of developers actively installing AI tools. No lock-in, cancel anytime.

Advertise here β†’
MikroMCP logo

MikroMCP

AliKarami/MikroMCP
35 starsv1.0.10STDIORegistry activeMITUpdated 2026-05-30Community

Works with

Claude CodeClaude DesktopCursorVS CodeClineCodex CLIOpenClaw+ any MCP client

Install to Claude Code

claude mcp add mikromcp -- npx -y mikromcp

Summary

AliKarami/MikroMCP MCP server](https://glama.ai/mcp/servers/AliKarami/MikroMCP/badges/score.svg)](https://glama.ai/mcp/servers/AliKarami/MikroMCP) πŸ“‡ 🏠 🍎 πŸͺŸ 🐧 - Manage MikroTik RouterOS devices through AI assistants β€” interfaces, firewall rules, DHCP,...

Connect from your MCP client

One-click install

Add this server to your editor with a single click. Fill in any required credentials afterward.

Claude Code

Run this once and Claude Code registers the server for you:

claude mcp add mikromcp -- npx -y mikromcp

Claude Desktop

Add this to claude_desktop_config.json under Settings β†’ Developer β†’ Edit Config:

{
  "mcpServers": {
    "mikromcp": {
      "command": "npx",
      "args": [
        "-y",
        "mikromcp"
      ],
      "env": {
        "MIKROMCP_CONFIG_PATH": "<MIKROMCP_CONFIG_PATH>",
        "MIKROMCP_STDIO_IDENTITY": "<MIKROMCP_STDIO_IDENTITY>",
        "MIKROMCP_LOG_LEVEL": "<MIKROMCP_LOG_LEVEL>"
      }
    }
  }
}

Cursor

Add this to .cursor/mcp.json in your project (or ~/.cursor/mcp.json for all projects):

{
  "mcpServers": {
    "mikromcp": {
      "command": "npx",
      "args": [
        "-y",
        "mikromcp"
      ],
      "env": {
        "MIKROMCP_CONFIG_PATH": "<MIKROMCP_CONFIG_PATH>",
        "MIKROMCP_STDIO_IDENTITY": "<MIKROMCP_STDIO_IDENTITY>",
        "MIKROMCP_LOG_LEVEL": "<MIKROMCP_LOG_LEVEL>"
      }
    }
  }
}

Cline and other MCP clients

Most MCP clients accept the standard mcpServers JSON block:

{
  "mcpServers": {
    "mikromcp": {
      "command": "npx",
      "args": [
        "-y",
        "mikromcp"
      ],
      "env": {
        "MIKROMCP_CONFIG_PATH": "<MIKROMCP_CONFIG_PATH>",
        "MIKROMCP_STDIO_IDENTITY": "<MIKROMCP_STDIO_IDENTITY>",
        "MIKROMCP_LOG_LEVEL": "<MIKROMCP_LOG_LEVEL>"
      }
    }
  }
}

Codex CLI

Register the server with OpenAI's Codex CLI β€” run this once, or add the equivalent block to ~/.codex/config.toml:

codex mcp add mikromcp --env MIKROMCP_CONFIG_PATH=<MIKROMCP_CONFIG_PATH> --env MIKROMCP_STDIO_IDENTITY=<MIKROMCP_STDIO_IDENTITY> --env MIKROMCP_LOG_LEVEL=<MIKROMCP_LOG_LEVEL> -- npx -y mikromcp

# or add to ~/.codex/config.toml:
[mcp_servers.mikromcp]
command = "npx"
args = ["-y", "mikromcp"]
[mcp_servers.mikromcp.env]
MIKROMCP_CONFIG_PATH = "<MIKROMCP_CONFIG_PATH>"
MIKROMCP_STDIO_IDENTITY = "<MIKROMCP_STDIO_IDENTITY>"
MIKROMCP_LOG_LEVEL = "<MIKROMCP_LOG_LEVEL>"

OpenClaw

OpenClaw reads MCP servers from the mcp.servers section of ~/.openclaw/openclaw.json (managed via `openclaw mcp add` or the mcporter skill):

{
  "mcp": {
    "servers": {
      "mikromcp": {
        "command": "npx",
        "args": [
          "-y",
          "mikromcp"
        ],
        "env": {
          "MIKROMCP_CONFIG_PATH": "<MIKROMCP_CONFIG_PATH>",
          "MIKROMCP_STDIO_IDENTITY": "<MIKROMCP_STDIO_IDENTITY>",
          "MIKROMCP_LOG_LEVEL": "<MIKROMCP_LOG_LEVEL>"
        }
      }
    }
  }
}

Replace the <PLACEHOLDER> values with your own credentials β€” see the configuration table below.

Configuration

MikroMCP reads the following environment variables:

VariableRequired
MIKROMCP_CONFIG_PATHOptional
MIKROMCP_STDIO_IDENTITYOptional
MIKROMCP_LOG_LEVELOptional

README.md

MikroMCP

<p align="center"> <picture> <source media="(prefers-color-scheme: dark)" srcset="./docs/assets/MikroMCP-logo-dark.png"> <source media="(prefers-color-scheme: light)" srcset="./docs/assets/MikroMCP-logo-light.png"> <img alt="MikroMCP" src="./docs/assets/MikroMCP-logo-dark.png" width="700"> </picture> </p>

AI-native network automation for MikroTik RouterOS. MikroMCP exposes RouterOS as a typed, auditable Model Context Protocol server so Claude, Cursor, Codex, and other MCP clients can inspect, diagnose, and safely operate MikroTik routers in natural language.

![CI](https://github.com/AliKarami/MikroMCP/actions/workflows/ci.yml) ![Release](https://github.com/AliKarami/MikroMCP/actions/workflows/release.yml) ![Version](package.json) ![License: MIT](LICENSE) ![Node.js >= 22](package.json) ![RouterOS 7.x](https://help.mikrotik.com/docs/display/ROS/REST+API) ![MCP Server](https://modelcontextprotocol.io) ![Tools](https://github.com/AliKarami/MikroMCP/wiki/Available-Tools) ![MikroMCP MCP server](https://glama.ai/mcp/servers/AliKarami/MikroMCP)

MikroMCP exists because raw router CLI access is the wrong abstraction for AI agents. RouterOS is powerful, but asking an LLM to improvise shell commands against production network gear is risky. MikroMCP gives agents a controlled tool surface: strict schemas, idempotent writes, dry-run previews, per-router circuit breakers, retry policies, RBAC, audit logs, snapshots, and rollback-aware change workflows.

In one sentence: MikroMCP turns MikroTik RouterOS into a production-minded MCP control plane for AI infrastructure, DevOps automation, and modern router management.

!AI assistant connected through MikroMCP to a small MikroTik fleet, with tool calls flowing through validation, audit, and RouterOS REST

---

Quick Start

<p align="center"> <img src="docs/assets/quickstart.svg" alt="MikroMCP quick start: npm install -g mikromcp, mikromcp init, then ask Claude Desktop about your router" width="760"> </p>

That's the whole setup for a single-router stdio deployment. For standalone binaries, Docker, HTTP/SSE mode, the RouterOS API prerequisites, and the full 15-minute walkthrough, see the Getting Started guide.

---

Feature Showcase

| Category | What MikroMCP covers | | -------------------------- | ----------------------------------------------------------------------------------------------------- | | 🧭 Router management | System status, clock, reboot, packages, files, scripts, scheduler jobs, containers | | 🌐 Network operations | Interfaces, VLANs, IP addresses, DHCP leases, DNS static records, bridge ports, WiFi clients | | πŸ”₯ Firewall and policy | Filter/NAT rules, mangle rules, address lists, route tables, routing rules | | πŸ›°οΈ Routing visibility | Static routes, routing tables, BGP peers, OSPF neighbors | | πŸ” Secure access | HTTP bearer auth, bcrypt token hashes, RBAC, router/tool restrictions, confirmation tokens | | πŸ§ͺ Diagnostics | Router-originated ping, traceroute, torch, log filtering, guarded SSH command execution | | πŸ›‘οΈ Change safety | Dry-run, idempotent writes, snapshots, write journal, plan_changes, apply_plan, rollback_change | | βš™οΈ Production behavior | Retries for read tools, per-router circuit breakers, correlation IDs, structured logs, audit logs | | πŸ€– AI-agent fit | Human-readable responses plus structured JSON content for reasoning, chaining, and automation; server advertises an instructions string on MCP initialize so clients self-configure; optional routerId resolved via MIKROMCP_DEFAULT_ROUTER for single-router setups; usage skill for safe, guided tool use in Claude Code | | 🧩 MCP compatibility | stdio for desktop clients, Streamable HTTP and legacy SSE for remote or service-style clients |

118 typed tools in total β€” browse the full catalog with parameters, defaults, and copy-paste example prompts in Available Tools.

---

Demo

Usage

<p align="center"> <img src="docs/assets/demo-1.gif" width="900" /> </p>

Review by Claude

!Claude Reviewed Router Configuration

---

Real-World Usage Examples

Router Inspection

Use MikroMCP to inspect core-01. Summarize system resources, RouterOS version,
running interfaces, active routes, DNS settings, and recent warning/error logs.
Flag anything that looks operationally risky.

Firewall Management

List firewall filter and NAT rules on edge-01. Identify disabled rules,
overlapping port forwards, broad accept rules, and anything without comments.
Do not change anything yet.

Safe Static Route Change

Dry-run a route on core-01 for 10.20.0.0/16 via 192.168.88.1 in the main table.
Show the exact planned diff and tell me whether an existing route conflicts.

WireGuard Operations

Show WireGuard peers on branch-02. Sort by last handshake age and flag peers
that have not handshaken recently or have no transfer counters.

Interface Diagnostics

Check interface health on edge-01, then run ping and traceroute from the router
to 1.1.1.1. If packet loss is present, use torch on the WAN interface for a
short traffic snapshot.

Plan / Apply / Rollback Workflow

Create a change plan that adds a DNS record and a firewall address-list entry
on edge-01. Use dry-run first, explain the plan, then wait for approval before
applying anything.

---

Why MikroMCP Is Useful For AI Agents

MCP gives LLMs a standard way to call tools. MikroMCP makes RouterOS a high-quality MCP target by turning network operations into well-described, machine-readable, permission-aware actions.

AI assistants can use MikroMCP to:

  • Investigate router state without memorizing RouterOS command syntax.
  • Chain tool calls across interfaces, routes, firewall rules, logs, and diagnostics.
  • Return both operator-friendly summaries and structured JSON for follow-up reasoning.
  • Preview changes before mutation and explain exactly what would happen.
  • Respect tool-level authorization, router scoping, maintenance windows, and confirmation gates.

---

FAQ

What is MikroMCP?

MikroMCP is an open-source Model Context Protocol (MCP) server that exposes MikroTik RouterOS as 118 typed, auditable tools β€” letting AI assistants inspect, diagnose, and safely operate routers in natural language instead of improvising CLI commands.

MikroMCP vs RouterOS API

The RouterOS REST/API exposes raw endpoints. MikroMCP wraps them in schema-validated, idempotent, dry-run-able tools with RBAC, audit logging, snapshots, and rollback β€” the safety layer an LLM needs before it touches production gear.

MikroMCP vs SSH automation

Instead of brittle SSH scripts that screen-scrape CLI output, MikroMCP returns structured, typed results with confirmation gates and per-router circuit breakers. SSH is used only where REST can't reach β€” ping, traceroute, torch, and guarded run_command.

MikroMCP for Claude Code

MikroMCP speaks MCP over stdio and HTTP/SSE, so Claude Code and Claude Desktop drive RouterOS directly. Pair it with the bundled usage skill for safe, guided workflows.

MikroMCP for Codex

Codex connects to MikroMCP over the standard MCP protocol β€” see Connecting to AI Assistants.

MikroMCP for Cursor

Cursor connects to MikroMCP as an MCP server (stdio or HTTP) to inspect and manage MikroTik routers without leaving the editor.

MikroMCP for OpenClaw

Any MCP-compatible client β€” OpenClaw included β€” can use MikroMCP; configure it as a stdio or HTTP MCP server.

RouterOS AI Automation Guide

Start with Getting Started to install and connect, then use the usage skill and Available Tools to automate RouterOS safely with an AI assistant.

Best MCP Servers for Network Engineers

MikroMCP is purpose-built for MikroTik/RouterOS operations with production-grade safety β€” dry-run, rollback, audit, and RBAC β€” making it a strong MCP choice for network engineers adopting AI tooling.

---

Documentation

The README stays intentionally short. Everything below is documented in depth in the wiki:

| Resource | Use it for | | ----------------------------------------------------------------------------------------------------- | ---------------------------------------------------------- | | Getting Started | Install (npm, binary, Docker), configure, and connect in 15 minutes | | RouterOS API Setup | Enable the REST API, create a user, TLS and firewall | | Configuration | Router registry, credentials, all environment variables | | Running | Run commands, HTTP/SSE transport, troubleshooting | | Connecting to Claude Desktop | Register MikroMCP in Claude Desktop | | Connecting to AI Assistants | Claude Code, Cursor, Codex, HTTP/Docker/systemd | | Using the Skill | Install the MikroMCP usage skill so your assistant drives the tools safely | | Available Tools | All 118 tools β€” parameters and example prompts | | Architecture | System layers, request pipeline, auth model | | Error Handling | Error categories, retry engine, circuit breaker | | Security | Threat model, hardening checklist, vulnerability reporting | | Development | Project structure, tests, MCP Inspector workflow | | Contributing | Adding tools, coding conventions, PR checklist | | Roadmap Β· ROADMAP.md | Shipped milestones and guiding principles |

---

Contributing

Issues, bug reports, tool requests, documentation improvements, and pull requests are welcome.

Good first contributions:

  • Add a read-only tool for an uncovered RouterOS surface.
  • Add screenshots, demo GIFs, or topology diagrams.
  • Expand tests around RouterOS response normalization and idempotency edge cases.
  • Help validate RouterOS version compatibility across real MikroTik devices and CHR.

Development standards:

  • TypeScript strict mode, ESM imports with .js extensions
  • Zod schemas with .strict(), idempotency and dryRun for write tools
  • MikroMCPError for domain errors, focused Vitest coverage for every tool

Please open an issue before large changes so maintainers can align on scope.

---

Security

MikroMCP controls real network devices β€” treat it like an operations system: least-privilege RouterOS users, verified TLS (or pinned fingerprints), credentials only in ~/.mikromcp/.env, scoped RBAC identities, and audit logging for shared use. The full hardening checklist and vulnerability-reporting process are on the Security page.

---

Community And Support

  • ⭐ Star the repository if MikroMCP helps your MikroTik or MCP workflow.
  • 🍴 Fork it to add RouterOS surfaces your network depends on.
  • 🧡 Open an issue for bugs, feature requests, compatibility notes, or documentation gaps.

---

License

MikroMCP is released under the MIT License.

See related servers & alternatives β†’

Related MCP servers

Browse all β†’

Related guides

Hand-picked reading to help you choose and use AI & ML servers.