English | Русский
MikroTik REST MCP
MCP server that gives coding agents structured access to a RouterOS 7 device over its REST API — reads, filtered queries, guarded writes, a scheduled rollback guard, container shell, and file transfer. One MCP server over stdio.
Built for real ops work: the agent can inventory the router, diff firewall/routing state, poke containers, watch counters, and apply changes — with a human confirmation gate in front of anything disruptive.
Features
- Broad read coverage
- ~60 curated
get_*tools for the common collections (firewall, routes, DHCP, DNS, interfaces, WireGuard, containers, scheduler, logs, system resources). - 200+ additional
get_*endpoints stay callable by name through the same filter pipeline — they are deliberately unlisted so the tool schema stays small.catalog_searchmakes them discoverable. routeros_gettakes any/rest/path directly, plusrouteros_batchfor up to 16 parallel reads in one call.
- ~60 curated
- Real query power
- Client-side
wherefilters with__contains,__in,__not,__gt,__gte,__lt,__lte,__startswith,__endswith. fieldsprojection,sort_by,limit,compact(one-line-per-item output that saves a lot of tokens).- RouterOS-native
.proplist/.querypass-through for server-side filtering.
- Client-side
- Guarded mutations
MIKROTIK_MODE=readonly: mutation/execution tools are not registered at all — the protocol surface itself is read-only, not just policy-gated.MIKROTIK_MODE=careful(default): operations classified as disruptive returnrequires_confirmation— the agent relays it to the user and re-runs withconfirm: trueafter approval. MCP elicitation shows a native dialog where supported. The confirmation flag is a UX gate, not a security boundary — the RouterOS account permissions are what actually limits the agent.- Method-aware policy:
PUTonly on known collections,PATCH/DELETEonly oncollection/<id>items,POSTonly on an explicit action allowlist (ping,traceroute,fetch,file/read,script/run,dns flush,backup/save,export, container shell — seecatalog.py). MIKROTIK_STRICT_CONFIRM=1gates every mutation.MIKROTIK_MODE=yoloremoves all gates and can switch to a separate full-privilege account (MIKROTIK_YOLO_USERNAME/MIKROTIK_YOLO_PASSWORD_FILE) — for supervised automation windows only.
- Scheduled rollback guard (not RouterOS Safe Mode — this works over plain REST)
apply_safesnapshots the target, arms an on-router scheduler, then applies the mutation. Once armed, the rollback no longer depends on the MCP process or client staying alive —commit_safedisarms it withinwindow_seconds.- Supported methods:
PATCH(restores the snapshotted values of changed fields — not transactional, no concurrent-edit detection) andDELETE(best-effort recreate; list position and generated fields are not preserved — the response says so).PUTis rejected because a created item's.idcan't be known until after it exists. - Ambiguous transport failures leave the rollback armed rather than silently disarming;
commit_safekeeps the pending record if disarm fails so it can be retried. safe_statusreports currently armed rollbacks.
- Container & diagnostics
container_shellruns commands inside RouterOS containers by name or.id— off by default (MIKROTIK_ENABLE_CONTAINER_SHELL), confirmation-gated in careful mode, and the genericrouteros_writepath can't bypass the flag.interface_trafficmeasures live rx/tx bps and pps over a sampling window;routeros_watchdiffs numeric fields across samples — counter deltas without two manual reads.run_ping,run_traceroute,run_fetch,run_wifi_monitor,describe_path(field introspection before you write filters).
- File ops with a sandbox
- Router-side file create/read/update/rename/delete plus chunked
download_file/upload_file. - Host filesystem access is off by default;
MIKROTIK_ENABLE_LOCAL_FILES+MIKROTIK_LOCAL_ROOTconfine it to one directory; transfers are capped at 8 MiB anddownload_filerequiresoverwrite: trueto replace an existing local file.
- Router-side file create/read/update/rename/delete plus chunked
- Secret hygiene
- Credentials come from
MIKROTIK_PASSWORD_FILE(recommended) orMIKROTIK_PASSWORD. - Every response passes through a scrubber that masks
password/secret/psk/token/private-key-shaped fields (MIKROTIK_REDACT=0disables). Redaction is field-name based — secrets embedded in free-form text (comments, script bodies, log lines, file contents) are not reliably detected. - Tool annotations (
readOnlyHint,destructiveHint,idempotentHint,openWorldHint) on every tool so clients can enforce their own policy.
- Credentials come from
Requirements
- Python 3.10+ (developed on 3.13).
- RouterOS 7.1+ with REST reachable (integration-tested on 7.24.5, hAP ax³ — REST, containers, scheduler rollback, file ops). HTTPS via
www-sslrecommended; plain HTTP viawwwrequires RouterOS 7.9+ and should be used only on isolated networks — REST uses Basic auth, readable on the wire. - A RouterOS user with
read+api+rest-apifor read-only use. Addwrite+testfor mutations/diagnostics,ftpfor file tools (download_file,/file/read). Script entries have their ownpolicyattribute — the account only needswriteto run them, and cannot run a script with broader policy than it possesses.
Installation
pipx install git+https://github.com/Sogl/mikrotik-rest-mcp.git # or: pip install .
This exposes the mikrotik-rest-mcp-server console script. For development: git clone + pip install -e .
Configuration
Point your MCP client at the server:
{
"mcpServers": {
"mikrotik_rest": {
"command": "mikrotik-rest-mcp-server",
"env": {
"MIKROTIK_BASE": "https://192.168.88.1",
"MIKROTIK_USERNAME": "mcp-agent",
"MIKROTIK_PASSWORD_FILE": "/path/to/password-file"
}
}
}
}
See .env.example for the full variable list (modes, capability flags, timeouts, TLS verification).
Recommended RouterOS account
# ops account — reads, config writes, diagnostics; no user/policy management,
# no sensitive fields, no reboot
/user group add name=agent policy=read,write,api,rest-api,test,ftp
/user add name=mcp-agent group=agent password=<random>
# monitoring-only account (pair with MIKROTIK_MODE=readonly)
/user group add name=monitor policy=read,api,rest-api,test
For yolo mode, create a second account in full and wire it via MIKROTIK_YOLO_*. Omit ftp if you don't need file tools.
Using it with agents
Typical flow an agent follows:
get_dhcp_leases {compact: true} → quick device list
routeros_batch {requests: [...]} → status in one call
describe_path {path: "/rest/interface/ethernet"} → field names before filtering
interface_traffic {name: "ether1", seconds: 2} → live throughput
routeros_watch {path: ..., diff: true} → counter deltas
routeros_write {method: "PATCH", ...} → routine config edit
routeros_write {method: "DELETE", ...} → stops for confirmation
apply_safe {method: "PATCH", path: "…/<.id>", window_seconds: 60}
→ rollback armed on router; commit_safe to keep
run_script_inline creates a temporary RouterOS script, runs it, and removes it (always confirmed in careful mode). container_shell and host file transfer need their opt-in flags.
Layout
src/mikrotik_rest_mcp/
client.py — REST transport, TLS, env config
catalog.py — endpoint/tool tables (pure data)
policy.py — risk tiers, confirmation gate, mutation allowlist
output.py — secret redaction, filters, compact serialization
files.py — local file sandbox + router file helpers
safe_apply.py — snapshot/rollback machinery
server.py — tool list, dispatch, resources, entrypoint
Tests
pytest tests/
Unit tests run without a router (REST calls are mocked).
Security
See SECURITY.md. Don't point this at routers you don't administer; treat yolo as a loaded gun and container_shell as remote code execution (because it is).
Metadata
Release files for mikrotik-rest-mcp-server 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| mikrotik_rest_mcp_server-0.1.1.tar.gz | 42.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| mikrotik_rest_mcp_server-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 78.1 kB
Release files / mikrotik_rest_mcp_server-0.1.1.tar.gz
| Download URL | mikrotik_rest_mcp_server-0.1.1.tar.gz |
|---|---|
| Size | 42.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
bfed115775591d8431455cf5b2dab404cc865bfcfda8ea7ffffbf4521d6efeee
|
|
BLAKE2b-256 checksum How to use checksums |
d06a514c1c02f830e111b6f8c10d9f808d4b61aab4161d786abcaef21d714f36
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / mikrotik_rest_mcp_server-0.1.1-py3-none-any.whl
| Download URL | mikrotik_rest_mcp_server-0.1.1-py3-none-any.whl |
|---|---|
| Size | 35.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
84101c3b3f121b703789066bb5c638f14442318056b363d7ceca874eb02feb4e
|
|
BLAKE2b-256 checksum How to use checksums |
26e291e491e236d53648646c6545fdb16f3189e5e348b3adf90f23bde23ffb0f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency log