Skip to main content

WAC510 MCP

A local FastMCP server for one NETGEAR WAC510 access point. It talks directly to the stock firmware's local HTTPS interface and keeps one asynchronous connection pool open for efficient calls.

The WAC510 protocol is undocumented. This implementation was validated against production firmware V9.9.6.8.

The server targets one AP per process. It does not use NETGEAR Insight, SSH, or SNMP.

Requirements

  • Python 3.14.7
  • uv
  • A WAC510 reachable through its local management URL

Expected startup failures are rendered as concise Rich panels with corrective guidance. Unexpected programming errors retain their tracebacks.

Install the locked environment:

uv sync

After the first PyPI release, run the server without cloning the repository:

uvx wac510-mcp

Run

Start the local OAuth-protected HTTP server:

uv run wac510-mcp

Connect your MCP client to:

http://127.0.0.1:8000/mcp

The MCP client's OAuth flow opens a page titled WAC510 MCP. Enter the access point URL, username, password, and optional connection settings. The server verifies that the device is a WAC510 before authorization completes.

Example URL-based MCP configuration:

{
  "mcpServers": {
    "wac510": {
      "url": "http://127.0.0.1:8000/mcp"
    }
  }
}

The server always hides FastMCP's startup banner. No environment variable or launch flag is required.

Add to Codex

First, keep the server running in a terminal:

uvx wac510-mcp@latest

In another terminal, add its Streamable HTTP endpoint and start OAuth:

codex mcp add wac510 --url http://127.0.0.1:8000/mcp
codex mcp login wac510 --oauth-client-registration dcr

Your browser opens the WAC510 MCP setup page. Enter the AP connection settings and authorize the client. Confirm the connection with:

codex mcp list

You can also enter /mcp inside Codex to inspect the server and its tools. Codex CLI, the IDE extension, and the desktop app share the same MCP configuration. See the official OpenAI MCP documentation.

Add to Claude Code

Keep uvx wac510-mcp@latest running, then add the server at user scope so it is available in every project:

claude mcp add \
  --transport http \
  --scope user \
  wac510 \
  http://127.0.0.1:8000/mcp

Open Claude Code and enter:

/mcp

Select wac510, authenticate, and complete the setup page in your browser. Verify the saved configuration with:

claude mcp get wac510

See the official Claude Code MCP documentation.

The OAuth transport is HTTP, not stdio. Both clients connect to the running URL; they do not launch uvx through a command entry. The server listens only on this machine by default.

Stored settings

Settings are saved under the platform's user configuration directory. On Linux, the default location is:

~/.config/wac510-mcp/

settings.enc contains the encrypted AP configuration, oauth.enc contains OAuth client registrations and tokens, and settings.key contains their local encryption key. All files use owner-only permissions, and the password is never rendered back into the setup page. OAuth access and refresh tokens survive server restarts while retaining expiration, client binding, rotation, and revocation behavior.

TLS verification defaults to off because the AP normally uses a self-signed certificate. The setup page can enable verification or specify a private CA bundle.

Safety

Read tools run immediately. Configuration writes require confirm=true. Disruptive operations require the exact tokens returned in their tool descriptions:

  • REBOOT
  • RESTORE_CONFIGURATION
  • UPGRADE_FIRMWARE
  • FACTORY_RESET

The raw tools make the server maximally capable. They expose the AP's private JSON protocol, so inspect a read payload before applying it.

For example, read an arbitrary firmware field with raw_query:

{
  "payload": {
    "system": {
      "basicSettings": {
        "apName": ""
      }
    }
  }
}

Pass the returned hierarchy with changed leaf values to apply_configuration first without confirmation. Review its redacted preview, then repeat the call with confirm=true.

Tools

  • list_capabilities and list_endpoints describe the reverse-engineered surface.
  • device_info, list_clients, radio_status, and traffic_statistics provide common reads.
  • query_capabilities reads any selection of 18 management domains with bounded concurrency.
  • raw_query accepts any /socketCommunication read selector.
  • apply_configuration applies arbitrary configuration after a preview and confirmation.
  • raw_request calls any discovered JSON endpoint with endpoint-specific confirmation.
  • download_file and upload_file support logs, configuration, packet captures, ACL files, restore, and firmware files.
  • reboot and factory_reset require exact confirmation tokens.

Development

uv run pytest
uv run mypy src tests

Releasing

The release workflow publishes a new version to PyPI, creates a matching GitHub Release, attaches the wheel and source archive, and adds provenance attestations. Start a patch release from any clean checkout with:

just release

Choose another semantic version increment when needed:

just release minor
just release major

The recipe updates main, runs the local gate, bumps pyproject.toml and uv.lock, pushes main, fast-forwards and pushes release, then switches the checkout back to main. Use just sync-release to synchronize the branches without changing the version.

The live test suite is read-only and opt-in. Its environment variables exist only for automated testing; normal users configure the server through OAuth:

WAC510_LIVE_TEST=1 uv run pytest tests/test_live_readonly.py -q

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

wac510_mcp-0.1.4.tar.gz (21.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

wac510_mcp-0.1.4-py3-none-any.whl (26.9 kB view details)

Uploaded Python 3

File details

Details for the file wac510_mcp-0.1.4.tar.gz.

File metadata

  • Download URL: wac510_mcp-0.1.4.tar.gz
  • Upload date:
  • Size: 21.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: uv/0.12.12 {"installer":{"name":"uv","version":"0.12.12","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for wac510_mcp-0.1.4.tar.gz
Algorithm Hash digest
SHA256 b545db229b4089c8ce9b87191bab90a0d482c268cd49c50a766415f069752229
MD5 fbdc2dd3072914e7955c6a9c4ea4ff35
BLAKE2b-256 e617f0d317ec253fa5ff06bebfaa6626fb906d5aada220c213be21ec3afb775a

See more details on using hashes here.

Provenance

The following attestation bundles were made for wac510_mcp-0.1.4.tar.gz:

Publisher: release.yml on skyline69/wac510-mcp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file wac510_mcp-0.1.4-py3-none-any.whl.

File metadata

  • Download URL: wac510_mcp-0.1.4-py3-none-any.whl
  • Upload date:
  • Size: 26.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: uv/0.12.12 {"installer":{"name":"uv","version":"0.12.12","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for wac510_mcp-0.1.4-py3-none-any.whl
Algorithm Hash digest
SHA256 6848a71cf5265a84b93b1f03f4d3842b3e8b970ead1856dc6c2674b4e201d82b
MD5 2ea037b8cda4ecff9942ecd8a5f52112
BLAKE2b-256 7493ce7c648a78c603b63bb1611cfea29201283240c57f056db7d55d552183e2

See more details on using hashes here.

Provenance

The following attestation bundles were made for wac510_mcp-0.1.4-py3-none-any.whl:

Publisher: release.yml on skyline69/wac510-mcp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

0.1.4 This release

2 files

0.1.3

2 files

0.1.2

2 files

0.1.1

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page