WAC510 MCP
A local FastMCP server for one NETGEAR WAC510 access point. It talks directly to the stock firmware's local HTTPS interface and keeps one asynchronous connection pool open for efficient calls.
The WAC510 protocol is undocumented. This implementation was validated against production firmware V9.9.6.8.
The server targets one AP per process. It does not use NETGEAR Insight, SSH, or SNMP.
Requirements
- Python 3.14.7
- uv
- A WAC510 reachable through its local management URL
Expected startup failures are rendered as concise Rich panels with corrective guidance. Unexpected programming errors retain their tracebacks.
Install the locked environment:
uv sync
After the first PyPI release, run the server without cloning the repository:
uvx wac510-mcp
Run
Start the local OAuth-protected HTTP server:
uv run wac510-mcp
Connect your MCP client to:
http://127.0.0.1:8000/mcp
The MCP client's OAuth flow opens a page titled WAC510 MCP. Enter the access point URL, username, password, and optional connection settings. The server verifies that the device is a WAC510 before authorization completes.
Example URL-based MCP configuration:
{
"mcpServers": {
"wac510": {
"url": "http://127.0.0.1:8000/mcp"
}
}
}
The server always hides FastMCP's startup banner. No environment variable or launch flag is required.
Add to Codex
First, keep the server running in a terminal:
uvx wac510-mcp@latest
In another terminal, add its Streamable HTTP endpoint and start OAuth:
codex mcp add wac510 --url http://127.0.0.1:8000/mcp
codex mcp login wac510 --oauth-client-registration dcr
Your browser opens the WAC510 MCP setup page. Enter the AP connection settings and authorize the client. Confirm the connection with:
codex mcp list
You can also enter /mcp inside Codex to inspect the server and its tools. Codex CLI, the IDE extension, and the desktop app share the same MCP configuration. See the official OpenAI MCP documentation.
Add to Claude Code
Keep uvx wac510-mcp@latest running, then add the server at user scope so it is available in every project:
claude mcp add \
--transport http \
--scope user \
wac510 \
http://127.0.0.1:8000/mcp
Open Claude Code and enter:
/mcp
Select wac510, authenticate, and complete the setup page in your browser. Verify the saved configuration with:
claude mcp get wac510
See the official Claude Code MCP documentation.
The OAuth transport is HTTP, not stdio. Both clients connect to the running URL; they do not launch uvx through a command entry. The server listens only on this machine by default.
Stored settings
Settings are saved under the platform's user configuration directory. On Linux, the default location is:
~/.config/wac510-mcp/
settings.enc contains the encrypted AP configuration. settings.key contains its local encryption key. Both files use owner-only permissions, and the password is never rendered back into the setup page. OAuth clients and access tokens remain in memory; after a server restart, the MCP client authenticates again and the page reuses the saved settings.
TLS verification defaults to off because the AP normally uses a self-signed certificate. The setup page can enable verification or specify a private CA bundle.
Safety
Read tools run immediately. Configuration writes require confirm=true. Disruptive operations require the exact tokens returned in their tool descriptions:
REBOOTRESTORE_CONFIGURATIONUPGRADE_FIRMWAREFACTORY_RESET
The raw tools make the server maximally capable. They expose the AP's private JSON protocol, so inspect a read payload before applying it.
For example, read an arbitrary firmware field with raw_query:
{
"payload": {
"system": {
"basicSettings": {
"apName": ""
}
}
}
}
Pass the returned hierarchy with changed leaf values to apply_configuration first without confirmation. Review its redacted preview, then repeat the call with confirm=true.
Tools
list_capabilitiesandlist_endpointsdescribe the reverse-engineered surface.device_info,list_clients,radio_status, andtraffic_statisticsprovide common reads.query_capabilitiesreads any selection of 18 management domains with bounded concurrency.raw_queryaccepts any/socketCommunicationread selector.apply_configurationapplies arbitrary configuration after a preview and confirmation.raw_requestcalls any discovered JSON endpoint with endpoint-specific confirmation.download_fileandupload_filesupport logs, configuration, packet captures, ACL files, restore, and firmware files.rebootandfactory_resetrequire exact confirmation tokens.
Development
uv run pytest
uv run mypy src tests
Releasing
The release workflow publishes a new version to PyPI, creates a matching GitHub Release, attaches the wheel and source archive, and adds provenance attestations. Start a patch release from any clean checkout with:
just release
Choose another semantic version increment when needed:
just release minor
just release major
The recipe updates main, runs the local gate, bumps pyproject.toml and uv.lock, pushes main, fast-forwards and pushes release, then switches the checkout back to main. Use just sync-release to synchronize the branches without changing the version.
The live test suite is read-only and opt-in. Its environment variables exist only for automated testing; normal users configure the server through OAuth:
WAC510_LIVE_TEST=1 uv run pytest tests/test_live_readonly.py -q
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file wac510_mcp-0.1.1.tar.gz.
File metadata
- Download URL: wac510_mcp-0.1.1.tar.gz
- Upload date:
- Size: 20.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
uv/0.12.12 {"installer":{"name":"uv","version":"0.12.12","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
8603048483768be0bc06d4ea497131e4d3ef04f52fb701312f58fee9067b0159
|
|
| MD5 |
c9dbca303e470cfec53179b34de9da1e
|
|
| BLAKE2b-256 |
32a43d582ab1f3d8330cfe7c1925b9ddd74d2bffb0b3150cbcb0171f58d57ce4
|
Provenance
The following attestation bundles were made for wac510_mcp-0.1.1.tar.gz:
Publisher:
release.yml on skyline69/wac510-mcp
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
wac510_mcp-0.1.1.tar.gz -
Subject digest:
8603048483768be0bc06d4ea497131e4d3ef04f52fb701312f58fee9067b0159 - Sigstore transparency entry: 2773093736
- Sigstore integration time:
-
Permalink:
skyline69/wac510-mcp@73ba6904cdbab11594a17af921b3dfc24ee9ef5a -
Branch / Tag:
refs/heads/release - Owner: https://github.com/skyline69
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@73ba6904cdbab11594a17af921b3dfc24ee9ef5a -
Trigger Event:
push
-
Statement type:
File details
Details for the file wac510_mcp-0.1.1-py3-none-any.whl.
File metadata
- Download URL: wac510_mcp-0.1.1-py3-none-any.whl
- Upload date:
- Size: 25.3 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
uv/0.12.12 {"installer":{"name":"uv","version":"0.12.12","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
6f202def3fef8df6c785380e921e173b1c6d5fabfc43de092741fa2acbc6ddec
|
|
| MD5 |
ff8d04a25c765cd6c0d4108b4dbfef2f
|
|
| BLAKE2b-256 |
6029c538c4a624321c23a4edde6008c5a61dda25fdb74941a711a72a83c761d5
|
Provenance
The following attestation bundles were made for wac510_mcp-0.1.1-py3-none-any.whl:
Publisher:
release.yml on skyline69/wac510-mcp
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
wac510_mcp-0.1.1-py3-none-any.whl -
Subject digest:
6f202def3fef8df6c785380e921e173b1c6d5fabfc43de092741fa2acbc6ddec - Sigstore transparency entry: 2773093777
- Sigstore integration time:
-
Permalink:
skyline69/wac510-mcp@73ba6904cdbab11594a17af921b3dfc24ee9ef5a -
Branch / Tag:
refs/heads/release - Owner: https://github.com/skyline69
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@73ba6904cdbab11594a17af921b3dfc24ee9ef5a -
Trigger Event:
push
-
Statement type: