Skip to main content

MCP server for managing VyOS routers via the VyOS HTTP API

Project description

VyOS MCP Server

An MCP server for managing VyOS routers via the VyOS HTTP API. Gives any MCP-compatible AI assistant full control over your VyOS router — from reading config to setting up interfaces, firewall rules, VPNs, and more.

Prerequisites

A VyOS router (1.4+ or rolling) with the HTTP API enabled:

configure
set service https api keys id my-app key 'YOUR_API_KEY'
set service https api rest
commit
save

Quick Start

No installation needed — run directly with uvx:

uvx vyos-mcp

Claude Code

claude mcp add vyos \
  -e VYOS_URL=https://10.0.0.1 \
  -e VYOS_API_KEY=YOUR_API_KEY \
  -e VYOS_VERIFY_SSL=false \
  -- uvx vyos-mcp

Or add to your ~/.claude.json or project .mcp.json:

{
  "mcpServers": {
    "vyos": {
      "command": "uvx",
      "args": ["vyos-mcp"],
      "env": {
        "VYOS_URL": "https://10.0.0.1",
        "VYOS_API_KEY": "YOUR_API_KEY",
        "VYOS_VERIFY_SSL": "false"
      }
    }
  }
}

Claude Desktop

Add to your Claude Desktop config:

  • macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
  • Windows: %APPDATA%\Claude\claude_desktop_config.json
{
  "mcpServers": {
    "vyos": {
      "command": "uvx",
      "args": ["vyos-mcp"],
      "env": {
        "VYOS_URL": "https://10.0.0.1",
        "VYOS_API_KEY": "YOUR_API_KEY",
        "VYOS_VERIFY_SSL": "false"
      }
    }
  }
}

Environment Variables

Variable Required Description
VYOS_URL Yes Base URL of your VyOS router (e.g. https://10.0.0.1)
VYOS_API_KEY Yes API key configured on the router
VYOS_VERIFY_SSL No Set to false to skip TLS verification (default: true)

Tools

Read-Only

Tool Description
vyos_info Get system version, hostname, and banner (no auth required)
vyos_show Run operational-mode show commands (interfaces, routes, BGP, etc.)
vyos_show_config Retrieve running configuration (full or partial subtree)
vyos_exists Check whether a configuration path exists
vyos_return_values Return values of a multi-valued config node (e.g. DNS servers)

Configuration

Tool Description
vyos_set Set a single configuration path
vyos_delete Delete a configuration path and its children
vyos_comment Add a comment to a configuration node
vyos_configure_batch Apply multiple set/delete/comment operations in a single atomic commit

All configuration tools automatically save to /config/config.boot after a successful commit, so changes persist across reboots.

Use confirm_time (1-60 minutes) on any config tool for safe rollback — changes auto-revert unless confirmed with vyos_confirm_commit.

Config File Management

Tool Description
vyos_save_config Save running config to disk (default or custom path)
vyos_load_config Load a config file, replacing the running configuration
vyos_merge_config Merge config from a file or inline string into running config
vyos_confirm_commit Confirm a pending commit-confirm timer

System

Tool Description
vyos_generate Run generate commands (WireGuard keys, certificates, etc.)
vyos_reset Reset protocol sessions, counters, or runtime state
vyos_image Add (download) or delete system images
vyos_system_control Reboot or power off the router (requires explicit confirmation)

Examples

Once configured, ask your AI assistant things like:

  • "Show me the current interface status"
  • "Set up eth0 as WAN with DHCP and eth1 as LAN with a DHCP server on 192.168.1.0/24"
  • "Add a firewall rule to block incoming traffic on port 22 from WAN"
  • "Set up a WireGuard VPN tunnel to 203.0.113.1"
  • "Show me the routing table"
  • "What DHCP leases are active?"
  • "Generate a new WireGuard key pair"

Development

git clone https://github.com/openclaw/vyos-mcp.git
cd vyos-mcp
python -m venv .venv
source .venv/bin/activate
pip install -e .

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

vyos_mcp-0.1.0.tar.gz (10.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

vyos_mcp-0.1.0-py3-none-any.whl (11.8 kB view details)

Uploaded Python 3

File details

Details for the file vyos_mcp-0.1.0.tar.gz.

File metadata

  • Download URL: vyos_mcp-0.1.0.tar.gz
  • Upload date:
  • Size: 10.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.14

File hashes

Hashes for vyos_mcp-0.1.0.tar.gz
Algorithm Hash digest
SHA256 ae9c90e7cdf0d976f15c964d7d21317f73092f626dfcfeb55555e9a771d883bc
MD5 6d5dac2977b5837a27734bc65fd62cec
BLAKE2b-256 19e4df2b8edcd0a8173da76f0f3f3811b605cebeaa048015aeedc351a6fc76ab

See more details on using hashes here.

File details

Details for the file vyos_mcp-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: vyos_mcp-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 11.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.14

File hashes

Hashes for vyos_mcp-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 0be9b434090153fb058358ebb38c352e2c2055ca5879709a93d1eb605e5ea425
MD5 f21bacce68ae5d9d3aa43eb5a6c49c62
BLAKE2b-256 47dbff057811be3c96fddb3ca3e57b566e03894d7e6bd6fd841828c416249184

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page