central-mcp-server
Community MCP server for HPE Aruba Networking Central. This exposes your Central data as tools that AI assistants can query directly.
WARNING - Unofficial Community Project
This is not an officially supported product of HPE. It is provided as-is, with no warranty or guarantee of fitness for any purpose.
- Review your organization's corporate device and data policies before connecting this server to any AI assistant.
- Never share credentials (API secrets, API keys) with AI model providers unless your security policy explicitly permits it.
- All read operations query live data from your HPE Aruba Networking Central instance. Recommended to test MCP server use in non-production or lab environments where possible before running on production.
Overview
central-mcp-server wraps Central REST APIs and exposes them as MCP (Model Context Protocol) tools — 12 MCP tools across inventory, monitoring, events, alerts, and troubleshooting. Once configured, AI assistants like Claude or GitHub Copilot can answer questions like:
- "Which sites have poor health scores right now?"
- "Show me all failed wireless clients at HQ in the last 24 hours."
- "Show me all online access points at the Chicago office."
- "What events happened on switch SW-CORE-01 yesterday?"
See the full overview guide for a deeper look at capabilities, limitations, and how the server works.
Getting Started
Getting Your Credentials
You need three values to connect this server to Central's REST APIs: CENTRAL_BASE_URL, CENTRAL_CLIENT_ID, and CENTRAL_CLIENT_SECRET.
API Gateway Base URL (CENTRAL_BASE_URL)
The API gateway base URL for your Central account (e.g. https://us5.api.central.arubanetworks.com).
For instructions on how to locate your base URL, see Finding Your Base URL in Central.
API Client Credentials (CENTRAL_CLIENT_ID & CENTRAL_CLIENT_SECRET)
OAuth credentials created through the HPE GreenLake Platform:
- Log in to your HPE GreenLake account and open Manage Workspace.
- Click Personal API clients.
- Click Create Personal API client.
- Give it a nickname (e.g.
central-mcp-server) and select your HPE Aruba Networking Central instance from the service dropdown. - Click Create personal API client.
- Copy both the Client ID and Client Secret immediately. The platform does not store the secret and it cannot be retrieved later.
Full guide: Generating and Managing Access Tokens
Installation
Install uv if you haven't already — it's the only prerequisite.
Using an MCP client (Claude Desktop, Claude Code, GitHub Copilot)?
No install command needed. Jump to MCP Client Configuration — the client fetches and runs the server automatically via uvx.
Want the server as a persistent CLI tool on your PATH?
uv tool install --prerelease=allow central-mcp-server
--prerelease=allowis required because this server depends onpycentral, which currently only has a pre-release version on PyPI. uv skips pre-releases by default.
See the full setup guide for prerequisites, troubleshooting, and step-by-step instructions.
MCP Client Configuration
Replace the placeholder values with your actual credentials in all examples below.
Optional: Code Mode Transform (DYNAMIC_TOOLS)
DYNAMIC_TOOLS is optional and only affects startup behavior:
- Code Mode is enabled only when
DYNAMIC_TOOLSis set totrue(case-insensitive). - Code Mode is disabled when
DYNAMIC_TOOLSis not set or set to any other value. - Variable name is strict: use
DYNAMIC_TOOLS(plural).DYNAMIC_TOOLis ignored.
When enabled, the server starts with CodeMode() and exposes Code Mode meta-tools to the client. When disabled, the server runs without the transform and exposes the normal registered tool catalog directly. Recommended to use CodeMode() when you have multiple MCP servers running to preserve your context window.
Claude Desktop
Add to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):
{
"mcpServers": {
"central-mcp": {
"command": "uvx",
"args": ["--prerelease=allow", "central-mcp-server"],
"env": {
"CENTRAL_BASE_URL": "your-central-base-url",
"CENTRAL_CLIENT_ID": "your-client-id",
"CENTRAL_CLIENT_SECRET": "your-client-secret"
}
}
}
}
See the Claude Desktop setup guide for full steps and troubleshooting.
Claude Code
claude mcp add central-mcp \
-e CENTRAL_BASE_URL=your-central-base-url \
-e CENTRAL_CLIENT_ID=your-client-id \
-e CENTRAL_CLIENT_SECRET=your-client-secret \
-- uvx --prerelease=allow central-mcp-server
See the Claude Code setup guide for full steps and troubleshooting.
GitHub Copilot (VS Code)
Add .vscode/mcp.json to your workspace root and add that path to .gitignore to keep credentials out of version control:
{
"servers": {
"central-mcp": {
"type": "stdio",
"command": "uvx",
"args": ["--prerelease=allow", "central-mcp-server"],
"env": {
"CENTRAL_BASE_URL": "your-central-base-url",
"CENTRAL_CLIENT_ID": "your-client-id",
"CENTRAL_CLIENT_SECRET": "your-client-secret"
}
}
}
}
Add to .gitignore:
.vscode/mcp.json
See the GitHub CoPilot setup guide for full steps and troubleshooting.
HTTP Transport (Streamable HTTP)
By default the server runs over stdio, which is the right choice for most MCP clients. If you need to run the server as a persistent HTTP process — for example, to share it across multiple clients or to connect via a remote URL — you can switch to the streamable-http transport.
Step 1 — Install the server as a CLI tool (if you haven't already):
uv tool install --prerelease=allow central-mcp-server
--prerelease=allowis required because this server depends onpycentral, which currently only has a pre-release version on PyPI.
Step 2 — Create a .env file in your working directory with your credentials and transport settings:
CENTRAL_BASE_URL=your-central-base-url
CENTRAL_CLIENT_ID=your-client-id
CENTRAL_CLIENT_SECRET=your-client-secret
MCP_TRANSPORT=http
MCP_HOST=127.0.0.1
MCP_PORT=8000
| Variable | Default | Description |
|---|---|---|
MCP_TRANSPORT |
stdio |
Transport mode: stdio or http |
MCP_HOST |
127.0.0.1 |
Host to bind when using HTTP transport |
MCP_PORT |
8000 |
Port to listen on when using HTTP transport |
Step 3 — Start the server:
# If installed via uv tool install:
central-mcp-server
# If running from source:
python server.py
The MCP endpoint will be available at http://<MCP_HOST>:<MCP_PORT>/mcp.
Step 4 — Connect your MCP client to the running server:
claude mcp add central-mcp --transport http --url http://127.0.0.1:8000/mcp
Or add it to your MCP client config:
{
"mcpServers": {
"central-mcp": {
"type": "http",
"url": "http://127.0.0.1:8000/mcp"
}
}
}
Note: Credentials must be set in the server's environment (via
.envor OS env vars) before starting it. They are not passed through the HTTP client config.
What You Can Ask
Once connected, you can ask your AI assistant questions like:
- "Give me a health overview of all sites."
- "Which sites are in poor health right now?"
- "Show me all access points at the Chicago office."
- "List the switches in the London campus and show CPU and PoE trends for SG34L5002Y."
- "How healthy is the BLR gateway cluster, and what's its client capacity trend?"
- "What critical alerts are active across the network?"
- "Find all failed wireless clients at HQ in the last 24 hours."
- "What events happened on switch SW-CORE-01 yesterday?"
- "Ping 8.8.8.8 from switch SW-CORE-01."
- "Run 'show version' and 'show interfaces brief' on switch SG43KN5017."
- "Bounce PoE on port 1/1/6 of switch SG43KN5017."
See Central MCP Server in Action for real query examples across all supported clients.
Example Queries
New to driving an AI assistant over your network? See What You Can Ask — a guided tour of real questions across every tool category (site health, devices, APs, switches, gateways, WLANs, clients, alerts, events, and live diagnostics), each shown with the answer it returns and a list of related questions to try.
Tools
The 0.2.x surface folds related operations into 13 tools. Envelope-returning reads default to response_format="concise"; use "detailed" for full item fields.
| Tool | Description |
|---|---|
central_get_devices |
Browse inventory or family monitoring data; exact serial/name lookup is supported. |
central_get_device_details |
Retrieve AP, switch, or gateway detail with family-specific includes. |
central_get_device_trends |
Retrieve bounded AP, switch, or gateway time-series samples. |
central_get_clients |
Browse filtered clients or look up one exact MAC address. |
central_get_client_analytics |
Client usage, roam trail, or per-stage onboarding analytics (metric selects the family). |
central_get_sites |
Retrieve summary or detailed site health views. |
central_get_wlans |
List WLANs or add throughput to one exact SSID. |
central_get_gateway_cluster |
Retrieve cluster members, health, and optional capacity/resources. |
central_get_events |
Retrieve event records (mode="records") or facets (mode="facets"). |
central_get_alerts |
Retrieve filtered active, cleared, or deferred alerts for a site. |
central_run_network_test |
Run a live network diagnostic against a device. |
central_run_show_commands |
Run validated show commands and return their output. |
central_bounce_port |
Bounce ports or toggle PoE after explicit confirmation. |
LLM Workflow for Events
- Resolve the target
site_id. - Call
central_get_eventswithmode="facets"andresponse_mode="compact"to discover useful filters. - Call it again with
mode="records"and targetedcategory,source_type, orevent_idfilters. - Use
mode="facets",response_mode="full"only when exact per-value counts are required.
Guided Prompts
The server includes 12 built-in prompts to help AI assistants run common workflows:
| Prompt | Description |
|---|---|
network_health_overview |
Full network health overview across all sites |
troubleshoot_site |
Deep-dive troubleshooting for a specific site |
client_connectivity_check |
Investigate connectivity status for a client by MAC address |
investigate_device_events |
Review recent events for a specific device |
site_event_summary |
Summarize all events at a site within a time window |
failed_clients_investigation |
Find and diagnose all failed clients at a site |
site_client_overview |
Overview of client connectivity at a site |
device_type_health |
Health check for all devices of a specific type at a site |
top_event_drivers |
Identify dominant event drivers at a site and pull supporting evidence |
critical_alerts_review |
Review all active critical alerts across the network |
wlan_health_check |
Assess WLAN health using client failures and related events over a time window |
compare_site_health |
Compare health metrics side-by-side across multiple sites |
Dev Setup
git clone <Github Server URL>
cd central-mcp-server
Create and activate a virtual environment, then install dependencies:
python3 -m venv .venv
source .venv/bin/activate
uv sync
Create .env with your credentials:
CENTRAL_BASE_URL=your-central-base-url
CENTRAL_CLIENT_ID=your-client-id
CENTRAL_CLIENT_SECRET=your-client-secret
Run the server:
python3 server.py
To install and test the package locally before publishing:
uv tool install .
Metadata
Release files for central-mcp-server 0.2.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| central_mcp_server-0.2.1.tar.gz | 2.9 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| central_mcp_server-0.2.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 3.0 MB
Release files / central_mcp_server-0.2.1.tar.gz
| Download URL | central_mcp_server-0.2.1.tar.gz |
|---|---|
| Size | 2.9 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
7dce8f44418377eff29daa8495a17eed05a6519101fe637657e043c949a6e43d
|
|
BLAKE2b-256 checksum How to use checksums |
b45ea88f07dc01131f3db2360fbcdd94bb6e7f4535fed8ea6e68edcf56bf586d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 7, 2026.
Transparency logRelease files / central_mcp_server-0.2.1-py3-none-any.whl
| Download URL | central_mcp_server-0.2.1-py3-none-any.whl |
|---|---|
| Size | 95.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
1b80907812eac3c44a4c7054c99d90fb1bd1ef94746c62137423ea4ef6e97a63
|
|
BLAKE2b-256 checksum How to use checksums |
467c8a0e52a477cffcb47ff668bf3d7b779f2ebd3b763f83ab97b4d28cbb9469
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 7, 2026.
Transparency log