Back to Discover

meraki-mcp

connector

wyre-technology

MCP server for the Cisco Meraki Dashboard: networks, devices, wireless, switch, appliance.

View on GitHub
0 starsSynced Aug 4, 2026

Install to Claude Code

/plugin marketplace add wyre-technology/meraki-mcp

README

Meraki MCP Server

Build Status License Node.js

A Model Context Protocol (MCP) server that provides AI assistants with structured access to the Cisco Meraki Dashboard โ€” organizations, networks, devices, clients, wireless, switching, and appliance operations.

Note: This project is maintained by Wyre Technology.

Quick Start

Claude Code (CLI):

claude mcp add meraki-mcp \
  -e MERAKI_API_KEY=your-api-key \
  -e MERAKI_ORG_ID=your-org-id \
  -- npx -y github:wyre-technology/meraki-mcp

See Installation for Docker and from-source methods.

Features

  • ๐Ÿ”Œ MCP Protocol Compliance: Full support for MCP tools over stdio and HTTP transports
  • ๐ŸŒ Network Coverage: Tools spanning organizations, networks, devices, clients, wireless, switching, and appliance (MX) operations
  • ๐Ÿ” Flattened Navigation: meraki_navigate and meraki_status are stateless discovery aids โ€” every tool is callable at any time
  • ๐Ÿ›Ÿ Safety by Default: Read-only mode is ON by default; writes are gated and destructive actions require explicit confirmation
  • ๐Ÿ–ผ๏ธ Interactive Device Card (MCP Apps): meraki_devices_get renders as a read-only interactive card in MCP Apps hosts (SEP-1865) โ€” neutral by default, brandable via window.__BRAND__ injection or MCP_BRAND_* env vars
  • ๐Ÿงฐ Long-Tail Escape Hatch: meraki_raw_request reaches any Meraki v1 endpoint not covered by a curated tool
  • ๐Ÿณ Docker Ready: Containerized deployment with HTTP transport and health checks
  • ๐Ÿ“Š Structured Logging: Configurable log levels

Installation

Option 1: Docker

docker run -d \
  -e MERAKI_API_KEY=your-key \
  -e MERAKI_ORG_ID=your-org-id \
  -p 8080:8080 \
  ghcr.io/wyre-technology/meraki-mcp:latest

Option 2: From Source

git clone https://github.com/wyre-technology/meraki-mcp.git
cd meraki-mcp
npm ci
npm run build

Configuration

VariableDescriptionDefault
MERAKI_API_KEYMeraki Dashboard API keyโ€”
MERAKI_ORG_IDDefault organization ID (optional)โ€”
MERAKI_BASE_URLOverride the Meraki API base URL (optional)โ€”
READ_ONLY_MODESafety switch โ€” blocks all writes when truetrue
MCP_TRANSPORTTransport mode (stdio or http)stdio
MCP_HTTP_PORTHTTP server port8080
AUTH_MODEAuth mode (env or gateway)env
LOG_LEVELLog level (debug, info, warn, error)info

The legacy READ_ONLY variable is also honored; READ_ONLY_MODE takes precedence.

Safety Model

This server defaults to read-only. Write operations (updates, reboots, deletions) are blocked unless you explicitly set READ_ONLY_MODE=false.

  • Read tools (*_list, *_get) are always available.
  • High-impact writes (e.g. meraki_networks_update, meraki_clients_update_policy) are gated by read-only mode.
  • Confirmation-gated tools additionally require a confirm_destructive_action: true argument, even once READ_ONLY_MODE=false. The confirmation flag is never forwarded to the Meraki API. Two groups qualify:
    • Irreversible โ€” meraki_networks_delete, meraki_devices_remove.
    • High blast radius โ€” meraki_appliance_firewall_l3_update, meraki_switch_ports_update, meraki_wireless_ssids_update, meraki_devices_reboot. These are reversible in principle, but each is applied over the same network link the change can break, so an operator can lose the connectivity needed to undo it. meraki_appliance_firewall_l3_update also replaces the rule set โ€” any rule not in the payload is deleted โ€” and meraki_wireless_ssids_update drops every client on the SSID when the PSK or auth mode changes.
  • Confirmation is not an escape hatch from read-only mode: while READ_ONLY_MODE is on, a confirmed call is still blocked.
  • The meraki_raw_request escape hatch classifies the call by HTTP method: GET is a read; POST/PUT/DELETE are writes; DELETE is destructive.

Domains

All tools are returned upfront. Use meraki_navigate to explore a domain's tools, or meraki_status to check connectivity and the configured organization.

DomainTools
organizationsmeraki_organizations_list, meraki_organizations_get, meraki_organizations_inventory_list
networksmeraki_networks_list, meraki_networks_get, meraki_networks_update โš , meraki_networks_delete โš โš 
devicesmeraki_devices_list, meraki_devices_get, meraki_devices_reboot โš โš , meraki_devices_remove โš โš 
clientsmeraki_clients_list, meraki_clients_get, meraki_clients_get_policy, meraki_clients_update_policy โš 
wirelessmeraki_wireless_ssids_list, meraki_wireless_ssids_update โš โš , meraki_wireless_rf_profiles_list
switchmeraki_switch_ports_list, meraki_switch_ports_update โš โš , meraki_switch_port_statuses_list
appliancemeraki_appliance_firewall_l3_get, meraki_appliance_firewall_l3_update โš โš , meraki_appliance_vpn_status_get
(long tail)meraki_raw_request โš โš  (on DELETE)

โš  = high-impact write, gated by read-only mode ยท โš โš  = additionally requires confirm_destructive_action: true

Docker Deployment

Copy .env.example to .env and fill in your credentials:

cp .env.example .env
# Edit .env with your Meraki API key (and org ID)
docker run --env-file .env -p 8080:8080 ghcr.io/wyre-technology/meraki-mcp:latest

Development

npm ci
npm run build       # Build the project
npm run start       # Run over stdio
npm run start:http  # Run the HTTP transport
npm run test        # Run tests

Testing

npm test

The test suite covers the safety contract: read-only enforcement, destructive confirmation, and that confirm_destructive_action is never forwarded to the SDK.

License

Apache 2.0 โ€” Copyright WYRE Technology

Rendered live from wyre-technology/meraki-mcp's GitHub README โ€” not stored, always reflects the source repo.

1 Install Method

NameDescriptionCategorySource
oci packageInstall via oci (stdio transport)mcp-serverghcr.io/wyre-technology/meraki-mcp:v1.1.1

0 Comments

Login required
Log in to post a comment or update on this repo.

No comments yet โ€” be the first to share an update.