Skip to main content
Connector guides

Connect UniFi

Ubiquiti's UniFi platform is really four products sharing one cloud account: Site Manager (the console and site inventory that ties everything together), Network (switching, WiFi, VLANs, firewall and…

Written By Christopher Scaminaci

Last updated 6 days ago

Ubiquiti's UniFi platform is really four products sharing one cloud account: Site Manager (the console and site inventory that ties everything together), Network (switching, WiFi, VLANs, firewall and guest access), Protect (cameras, sensors, sirens and alarms) and Mobility (mobile-routing workspaces and devices). StackJack connects to all four through Ubiquiti's official cloud API at api.ui.com, using a single API key you create once.

Connecting UniFi gives your AI a broad set of unifi_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Find your equipment — list every UniFi console you can reach, the sites on each one, and the devices across all of them
  • Investigate the network — adopted and pending devices, live client lists, per-device statistics, VLANs, WiFi broadcasts, VPN servers and tunnels, link aggregation and switch stacks
  • Read and change policy — firewall policies and zones, access-control rules, DNS policies and traffic-matching lists, including the order they are evaluated in
  • Run guest WiFi — generate, list and revoke hotspot vouchers, and authorize or cut off individual guests
  • Act on hardware — adopt a device, restart it, or power-cycle a single PoE switch port
  • Watch the premises — list cameras, sensors, lights, chimes, speakers, viewers and live views; take a camera snapshot; read stream URLs
  • Work the alarm system — arm and disarm, switch arm profiles, sound or silence a siren, trigger an alarm-hub output, and move PTZ cameras to stored presets
  • Check ISP health — per-site internet performance metrics and SD-WAN configuration status
  • Manage Mobility — list workspaces, devices and their clients, and update a device's name, LAN/DHCP settings or wireless configuration

What works today, and what needs more than a key

Set expectations before you configure anything, because UniFi draws a line most people do not expect:

  • Site Manager tools work with any valid cloud key. Listing consoles, sites and the device inventory, ISP metrics and SD-WAN status — these ask the UniFi cloud directly and need nothing beyond the key.
  • Network and Protect tools need more. Those calls are relayed to one specific console, and UniFi only relays to a console when your key's account owns it. A key that can list a console does not imply it can manage that console. Where it cannot, you have two ways in: a key from the console's owner, or a direct connection to the controller.

The three kinds of UniFi key

This is the single biggest source of confusion, so it is worth learning up front: there are three cases, and the first two are not interchangeable.

KindWhere you create itWhat it is for
Site Manager (cloud) keyunifi.ui.com → Settings → API KeysThe only key api.ui.com accepts. Comes in personal and organization flavors. This is the main API Key field
Local console keyOn a console: Settings → Control Plane → IntegrationsOnly works when StackJack talks to that console directly. This is the Local API Key field
None available—The legacy self-hosted UniFi Network Application has no Integrations page and cannot create an API key at all. It cannot be connected. UniFi OS Server can, and is supported

Pasting a local console key into the API Key field is a common mistake, and it fails loudly: every call returns 401 {"code":"unauthorized","httpStatusCode":401,"message":"unauthorized"}.

If you are hunting for Settings → Control Plane → Integrations on a self-hosted controller and cannot find it, stop looking. That page exists on UniFi OS only — consoles and UniFi OS Server. The older Network Application does not have it, and no amount of upgrading the Network application adds it.

Which lane am I on?

Your situationLaneWhat to configure
A console your key's account ownsCloud (default)Nothing beyond the API Key
A console someone else ownsCloud, with a per-console keyAsk its owner for a key; add it under Per-console API Keys
A console or UniFi OS Server you can reach directly and mint a key onDirectDirect Controller URL + Local API Key

How StackJack authenticates to UniFi

UniFi uses a static API key — the key alone authenticates every call. There is no client ID, OAuth consent, or refresh flow. Ubiquiti's current public getting-started guide does not publish an automatic expiry for Site Manager keys; revoke and replace the key when your policy requires rotation or if it may have been exposed.

The cloud endpoint is fixed at https://api.ui.com, so there is no regional URL to get right. The only URL you may need to enter is a direct controller's, and that is optional.

Read this before you create the key

Two separate things decide how much of the connector works, and both produce no error at setup time.

Personal vs organization decides what you can see:

Key typeWhat appears in your console list
PersonalOnly the consoles owned by the person who created the key
OrganizationEvery console in that organization

If you manage customer equipment across several owners — the normal situation for an MSP — create the key inside your organization, not as an individual. A personal key will look like it works: it authenticates fine and returns a console list. That list is just quietly short.

Owner vs admin decides what you can manage, and this one surprises nearly everyone:

Being an admin on a console is not enough — not even a full admin with every application permission. UniFi's cloud relays a request to a console only when your key's account is that console's Owner. An admin-only key lists the console perfectly well and then fails on every Network and Protect call against it with forbidden: access denied: user is not the owner of this host.

Create the key from the account that owns the consoles you intend to manage. A console's Settings → Admins & Users page shows which account that is. If ownership sits with someone else, that is what the per-console keys and the direct lane are for.

Before you begin

  • In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
  • In UniFi: you need an account that can create API keys — ideally the account that owns the consoles you intend to manage, in the organization those consoles belong to.

Step 1 — Create the API key in UniFi

  1. Sign in at unifi.ui.com with the Ubiquiti account that manages your consoles.
  2. Go to Settings → API Keys.
  3. Decide personal or organization first — see the table above. For an MSP, create the key inside your organization.
  4. Make sure you are signed in as the account that owns the consoles you intend to manage, not merely an admin on them. This decides whether Network and Protect tools will work at all, and it cannot be changed by editing permissions afterwards.
  5. Choose Create API Key and give it a name that identifies StackJack.
  6. If the dialog offers a site scope, choose "All Sites" (newer Site Manager releases, 5.0/5.1 and later, let a key be limited to specific sites at creation — including Fabrics-grouped sites). A key scoped to particular sites is silently blind to every other site, which looks exactly like missing equipment later. Narrow it only when you genuinely intend that key to manage a subset.
  7. Copy the key immediately and store it securely. UniFi shows it only once, and anyone holding it can read and act on your UniFi equipment.

Step 2 — Add the credentials in StackJack

  1. In the StackJack portal, open Connectors.
  2. Find the UniFi card. Click How To Connect for these steps inline, or Configure to enter the credentials.
  3. Paste the key into API Key. UniFi's cloud endpoint is fixed, so there is nothing to enter for it.
  4. Leave Mobility API Key empty unless you use UniFi Mobility and your main key does not cover it (see below).
  5. Leave Per-console API Keys and the three Direct Controller fields empty for now. They exist for consoles your own key cannot manage — see Which of my consoles will actually work? once you have saved, which tells you whether you need them at all.
  6. Click Save.

The optional Mobility key

UniFi Mobility is gated by its own application permission. If your main key does not cover it, create a second key that does and paste it into Mobility API Key. Leave the field empty if you do not use Mobility.

On an edit this field always starts blank, and leaving it blank keeps whatever is already stored — so rotating your main key never forces you to re-enter the Mobility one.

What happens when you save

  • The API key is stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
  • If this is the first time you configure UniFi, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
  • StackJack immediately live-validates the key by listing your consoles. Validation never blocks the save: you will either see a success confirmation or a "saved but validation failed" warning with the reason.

The validation read is the console list, which is also the discovery call your AI makes first. A success here proves the key works and shows you immediately whether it reaches the consoles you expected — which is exactly how you catch a personal key that should have been an organization key.

Finding your console ID

Network and Protect calls are relayed to one specific console, so every Network and Protect tool needs a console ID. Site Manager and Mobility tools do not.

Your AI discovers these itself: List UniFi Consoles (Hosts) returns every console the key can reach, and each host is a console. Ask your AI to list them once and it can work from that list afterwards. A console ID is a long hexadecimal string with a colon and a numeric suffix — pass it through exactly as returned, including the colon.

If a console you manage does not appear in that list at all, the key is the reason, not the console. See the personal-vs-organization table above.

Which of my consoles will actually work?

Do this once, right after saving the key. It turns a mystery 403 into something you can see in advance.

Ask your AI to list your UniFi consoles, and read the owner flag on each one:

ownerWhat it means
trueYour key owns this console. Network and Protect tools work against it
falseYour key can see this console but cannot manage it. Every Network and Protect call returns forbidden: access denied: user is not the owner of this host

A console with owner: false looks completely healthy — it is listed, it reports its firmware and its applications, and nothing about it says "you cannot use this." Being an admin on it, even a full admin with every application permission, does not change the flag. The flag is the honest answer, so check it before you plan work around a console.

Reaching consoles your key does not own

Every console showing owner: false has three ways forward, best first.

First, tell the two situations apart. A console listed with owner: false and a console not listed at all are different problems. Per-console keys widen what you can manage — they never widen what your main key can discover: the console list always comes from your main key, and a per-console key is consulted only for requests addressed to that console's ID. So for a console your key cannot even see, options 2 and 3 still work, but you must get the console ID from its owner (their own console list shows it) — it will never appear in yours, and that is expected, not a fault. A key limited by a site scope (see Step 1, item 6) is the other common reason a console is missing entirely.

1. Use a key from the account that owns it. Ownership, not permissions, is the deciding factor — so either create your Site Manager key from the owning account, or have ownership transferred to the account whose key you already use. A console's Settings → Admins & Users page shows which account is the Owner. This is the only fix that needs nothing further afterwards — and the only one that also fixes discovery.

2. Add a per-console key. Ask that console's owner to create an API key at unifi.ui.com exactly as you did, and paste it into Per-console API Keys as console id=key, one per line. That key is used only for requests to that console; everything else keeps using your own. Copy the console ID exactly, colon suffix included — from your console list when the console is visible to you, or from the owner's when it is not.

Leaving the Per-console API Keys box empty on an edit keeps every key already stored. To remove one, enter its console ID with nothing after the equals sign.

3. Connect to the controller directly — see the next section. This is also the only option for a console that is not maintaining its cloud connection at all.

Connecting directly to a controller

If a UniFi OS console or a UniFi OS Server is published on the internet with a valid certificate, StackJack can talk to it without going through the UniFi cloud:

  1. In Direct Controller URL, enter its address as scheme, host and port only — for example https://unifi.example.com:8443. Do not add a path.
  2. Set Direct Controller Type to UniFi OS Server (self-hosted), or UniFi OS console for a Dream Machine, Cloud Key or UNVR.
  3. Create a second key on that controller, under Settings → Control Plane → Integrations, and paste it into Local API Key. This is a different key from your unifi.ui.com one, and the two are never substituted for each other.

Your AI then reaches it by using the word local where a console ID would normally go — so "list the sites on the local controller" works the same way "list the sites on console X" does.

Four things to know:

  • The legacy self-hosted UniFi Network Application cannot be connected this way, or any other way. It has no Settings → Control Plane → Integrations page, so there is no API key to create for it. Its API routes exist and answer, but every call is refused because no valid key for them can exist. UniFi OS Server is the supported self-hosted product.
  • The address needs a valid public certificate. StackJack will not connect to a controller presenting a self-signed one.
  • The address must be a public one. StackJack reaches your controller from the internet, so a local-network address such as 192.168.1.1, 10.0.0.5 or 127.0.0.1 — or the name localhost — is refused when you save, because nothing outside your network could ever reach it. Publish the controller at a name or address that resolves on the internet. A name of your own that happens to point at a private address is accepted at save time and simply fails to connect.
  • UniFi Protect is available on the console type only. A self-hosted server serves its API at a path with no application segment, so it addresses UniFi Network and nothing else.
  • Site Manager and Mobility tools always use the cloud. Those are Ubiquiti cloud services with no on-controller equivalent, so they still need your unifi.ui.com key.

If a direct controller is the only UniFi equipment you are connecting, you can leave API Key empty and configure just the direct controller. Everything that needs the cloud will then tell you a cloud key is required, rather than failing obscurely.

Plans and available tools

  • Free includes console, site and device inventory across all products; ISP metrics and SD-WAN status; Network clients, devices, VLANs, WiFi broadcasts, firewall policies and zones, access-control rules, DNS policies, traffic-matching lists, VPN, switching and reference data; Protect equipment and NVR details; and Mobility workspace, device and client listings.
  • Pro adds write, action and sensitive-read operations for networks, WiFi broadcasts, firewall and ACL rules, DNS policies and traffic lists; device adoption, restart and removal; switch-port power cycling; guest authorization; hotspot vouchers; Protect device settings, PTZ movement, sirens, alarms and relays; Mobility device changes; and raw console relays.
  • Business offers the same tools as Pro with a higher usage allowance.

See the generated UniFi tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

UniFi has no per-user sign-in for its API, so all AI traffic authenticates as the single API key — there is no per-user attribution. Current pricing and quotas are shown in the portal's Billing page and at checkout.

Three things to know about the tiers

A few reads are Pro tools even though they change nothing. Reads are otherwise Free, and these are the deliberate exceptions, each one paid for what the answer contains rather than what the call does:

ToolWhy it is Pro
List / Get Hotspot VoucherReturns working guest-WiFi access codes
Get Camera RTSPS Stream URLsThe URLs function as live-video credentials
Get Camera SnapshotEgresses an image from inside the customer's premises
List / Get Identity UserThe enrolment records behind physical door access

The raw console-relay tools are Pro, and StackJack marks the read operation as a change too. This family forwards a request you specify straight to a console for endpoints StackJack has no purpose-built tool for. Write operations carry the marking for the obvious reason. The read operation carries it as well, because you choose the address it calls and some UniFi read endpoints have side effects. Prefer a purpose-built tool whenever one exists: they validate what you pass, cap page sizes, and describe what comes back.

Know which actions are disruptive before you grant them. StackJack marks every delete, device restart, and port power-cycle as a change. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review those settings, and grant only what you want an AI to reach. A few are worth calling out specifically, because the name does not tell you how far they go:

  • Remove (Unadopt) Device performs a factory reset on a device that is online, not merely an unadopt.
  • Reorder Firewall Policies and Reorder ACL Rules replace the whole ordered list. An incomplete list silently drops rules out of enforcement rather than erroring.
  • Siren and alarm controls are marked in both directions — sounding or silencing a siren, and arming or disarming the alarm, all change the security posture of a real premises.
  • Permanently Disable Camera Microphone cannot be undone without a factory reset of the camera.
  • Replace Mobility Device SSID and Password drops every client currently connected to that device.

Rate limits and the relay's two hard limits

Each console accepts 100 relayed requests per minute. StackJack paces requests and backs off on its own, which smooths a burst — a wide sweep across one console may just take a little longer. Pacing is not a guarantee that every call gets through: retries are bounded, and a wide enough sweep can still come back throttled. Narrow the read, honour the retry delay UniFi sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.

Relayed Network and Protect calls also carry two limits set by Ubiquiti that StackJack cannot work around:

  • A request must finish within 25 seconds. A very broad list against a busy console can exceed this.
  • A response larger than 10 MB is not returned.

Both have the same fix: ask for a narrower page or a tighter filter. Site Manager and Mobility calls are not relayed and are not subject to either limit.

Filtering by names containing & or #

Many UniFi Network tools accept a server-side filter expression, and names like Bed & Breakfast or R&D work normally in one. StackJack percent-encodes a literal & or # before sending, because those two characters delimit the request itself — left raw, either one cuts the filter short, and a shorter filter matches more, which on a voucher delete would destroy more than you asked for. UniFi decodes them correctly on the other side, so the filter you write is the filter that runs. Verified live against a UniFi console.

Rotating or replacing the credentials

The API key is the only secret. If you regenerate or revoke it in UniFi, the stored credential stops working. To restore access, open Connectors → UniFi → Configure, paste the new key, and Save.

If you are only adding or changing the Mobility key, leave the main API Key field blank and save — StackJack keeps the key it already has. The same applies to Local API Key and every entry in Per-console API Keys: a blank field keeps what is stored.

Because a blank field keeps the key rather than removing it, removing one has its own control. Tick Remove the stored cloud API key, leave the API Key field empty, and save. Do that only when you have revoked the key at unifi.ui.com or are moving to a direct controller alone — UniFi Site Manager, Mobility and every console addressed by ID stop working, and UniFi cannot show you the old key again. StackJack refuses the save if it would leave the connector with no way in at all, so configure the direct controller first.

One exception. If you change the Direct Controller URL, StackJack asks you to re-enter the Local API Key on that save rather than carrying it over — that key belongs to the controller you are moving away from, and a key is never carried to a new address. Your cloud keys are unaffected: the main API key, the Mobility key and every per-console key stay stored, because they answer to UniFi's cloud rather than to the controller you changed.

What the UniFi API does not expose

Worth knowing up front, so you do not go looking for tools that cannot exist:

  • Protect has no event history. There is no way to ask the API what happened last night — no motion events, no detections, no recording index. The connector can tell you what the equipment is and change what it does, not what it saw. Ubiquiti exposes events only over a live streaming connection, which a request-and-response tool cannot consume.
  • There is no way to read a PTZ camera's current position, or to list its presets. Moving a camera is therefore not reversible through the API, and StackJack cannot tell you in advance whether a camera supports PTZ at all or which preset slots are configured. Slot -1 is the home position; 0 and above select a stored preset.
  • Firewall zones and ACL rules created by UniFi itself cannot be edited. Only ones you defined are mutable.
  • Switching is read-only. UniFi publishes no create, update or delete for link aggregation groups, MC-LAG domains or switch stacks.
  • Protect events, PTZ positions and UniFi-created firewall rules stay out of reach whichever way you connect — the direct controller lane changes which equipment StackJack can talk to, not what the UniFi API offers.
  • A controller on a private network cannot be reached at all. The direct controller lane needs a publicly resolvable address with a valid certificate; a hosted service cannot see 192.168.x.x, and StackJack will not accept a self-signed certificate.

Troubleshooting

SymptomLikely causeWhat to do
A console you manage is missing from the listThe key is a personal key, not an organization keyCreate a new key inside the organization and re-save it in StackJack. This is by far the most common UniFi setup mistake, and it never produces an error
401 unauthorized on everything, including right after savingA local console key was pasted into the API Key fieldOnly a key from unifi.ui.com works against the UniFi cloud. Create one there for the API Key field, and move the console-minted key to Local API Key
forbidden: access denied: user is not the owner of this host on Network or Protect toolsThe key's account is not the Owner of that console. Admin — even full admin with every application permission — is not enoughCheck the owner flag in the console list to confirm. Then either use a key from the owning account (or transfer ownership), add a key from that owner under Per-console API Keys, or reach the controller directly. See Reaching consoles your key does not own
insufficient permissions on Mobility tools onlyThe key does not carry the Mobility application scopeCreate a key that includes Mobility and paste it into Mobility API Key. If reads work and only changes fail, that is a different problem — the key's user also needs to be an Admin of that workspace
408 DeviceTimeout or "device is offline" on one consoleThat console is not maintaining its connection to the UniFi cloud, so there is nothing to relay throughCheck its internet connection and that remote access is enabled on it. Your key is fine and other consoles are unaffected. A self-hosted controller with no cloud tunnel does this on every relayed call by design — use the direct lane for it instead
A console shows owner: true but every Network or Protect call returns 404That console does not expose the Integration API, even though the relay reaches itThis is console-side, not a StackJack or credential problem. Check the Network (or Protect) application's version and that it is actually installed on that console. Other consoles of the same model can work while one does not
A self-hosted controller cannot be connected at allIt is the legacy UniFi Network Application, which has no Integrations page and cannot create an API keyThere is no workaround — no key exists to create. UniFi OS Server is the supported self-hosted product and does have that page
A tool reports there is no direct controller configuredSomething used local as the console ID with no controller set upEither configure the direct controller fields, or use a real console ID from the console list
Protect tools fail on the direct controller while Network tools workThe controller type is set to UniFi OS Server (self-hosted)That path addresses UniFi Network only. Reach Protect through a UniFi OS console instead
Every direct-controller tool fails while cloud tools workThe Local API Key is missing, wrong, or was created at unifi.ui.com by mistakeThe direct controller needs its own key, created on the controller under Settings → Control Plane → Integrations. Your cloud key is never sent there
Saving says the direct controller URL is not validThe address includes a path, is not HTTPS, is a private or loopback address, or is Ubiquiti's own api.ui.comEnter scheme, host and port only, at a public address — for example https://unifi.example.com:8443. Leave the field empty if you have no direct controller
You revoked your cloud API key and the connector keeps failingThe stored key is still there — leaving the field blank keeps itTick Remove the stored cloud API key under the API Key field and save. You need a direct controller configured, or the connector would have no way in at all
Save or Re-test passes but direct-controller tools failOnly the cloud lane is checked for a verdict when both are configuredThis is deliberate: a controller that is down must not disable your working cloud tools. Check the controller's certificate, DNS record and reachability from the internet
"Saved but validation failed" right after savingThe key was mis-pasted, or was revoked in UniFiRe-copy the key from unifi.ui.com and save again
Every tool fails with an authentication errorThe key was regenerated or revoked in UniFiPaste the current key in Connectors → UniFi → Configure and save
A Network or Protect tool times outThe relay cut the request off at 25 secondsAsk for a smaller page or a tighter filter. Site Manager and Mobility calls are not affected
A large list comes back refused rather than truncatedThe response exceeded the relay's 10 MB capSame fix — narrow the request rather than retrying it unchanged
A Protect tool reports the device is unavailableThe camera, sensor or hub is offlineThis is device state, not a credential problem, and it does not count against your connector's health. Check the device in the UniFi Protect app
A camera snapshot link stops workingThe link is deliberately short-livedThe snapshot tool returns a download link valid for a few minutes rather than embedding the image. Run the tool again for a fresh link
A voucher or camera-snapshot tool is missingThe connector is on the Free tierThose are Pro tools. Upgrade the UniFi connector plan, then check your tool selections on the MCP Setup page

UniFi tools

unifi_ · 167 tools · Free 85 · Pro 82

UniFi Hosts & Sites

ToolWhat it does
unifi_sm_get_host
Free · Read-only
Get one UniFi console in full, by the host id from unifi_sm_list_hosts.
unifi_sm_list_hosts
Free · Read-only
List every UniFi console the API key can reach — the ENTRY POINT for this connector.
unifi_sm_list_sites
Free · Read-only
List the sites across every console the API key can reach.

UniFi Device Inventory

ToolWhat it does
unifi_sm_list_devices
Free · Read-only
List UniFi devices across every reachable console, grouped by host.

UniFi ISP Metrics

ToolWhat it does
unifi_sm_get_isp_metrics
Free · Read-only
Get ISP performance metrics for EVERY site on the account, at either 5-minute or 1-hour resolution.
unifi_sm_query_isp_metrics
Free · Read-only
Get ISP metrics for a caller-chosen list of sites, each with its own time window.

UniFi SD-WAN

ToolWhat it does
unifi_sm_get_sdwan_config
Free · Read-only
Get one SD-WAN configuration in full, by the id from unifi_sm_list_sdwan_configs.
unifi_sm_get_sdwan_config_status
Free · Read-only
Get the DEPLOYMENT STATUS of one SD-WAN configuration — deliberately separate from the configuration itself, because a valid configuration can still be failing to reach devices.
unifi_sm_list_sdwan_configs
Free · Read-only
List the account's SD-WAN configurations — the hub-and-spoke overlays that link sites together.

UniFi Console Proxy (raw)

ToolWhat it does
unifi_sm_proxy_delete
Pro · Destructive
ESCAPE HATCH — send an arbitrary DELETE to one UniFi console through the cloud relay.
unifi_sm_proxy_get
Pro · Write
ESCAPE HATCH — send an arbitrary GET to one UniFi console through the cloud relay, for endpoints StackJack has no typed tool for.
unifi_sm_proxy_patch
Pro · Destructive
ESCAPE HATCH — send an arbitrary PATCH to one UniFi console through the cloud relay.
unifi_sm_proxy_post
Pro · Destructive
ESCAPE HATCH — send an arbitrary POST to one UniFi console through the cloud relay.
unifi_sm_proxy_put
Pro · Destructive
ESCAPE HATCH — send an arbitrary PUT to one UniFi console through the cloud relay.

UniFi Mobility Workspaces

ToolWhat it does
unifi_mob_list_workspace_admins
Free · Read-only
List the administrators of one UniFi Mobility workspace, by the workspace UUID from unifi_mob_list_workspaces.
unifi_mob_list_workspaces
Free · Read-only
List the UniFi Mobility workspaces the API key can reach — the ENTRY POINT for the Mobility surface.

UniFi Mobility Devices

ToolWhat it does
unifi_mob_get_device
Free · Read-only
Get one UniFi Mobility device in full, by its workspace UUID and device UUID (both from the Mobility list tools).
unifi_mob_list_device_clients
Free · Read-only
List the clients currently connected to one UniFi Mobility device.
unifi_mob_list_devices
Free · Read-only
List the devices in one UniFi Mobility workspace, by the workspace UUID from unifi_mob_list_workspaces.
unifi_mob_update_device_name
Pro · Write
Rename one UniFi Mobility device.
unifi_mob_update_device_network
Pro · Destructive
Rewrite one UniFi Mobility device's LAN and DHCP configuration.
unifi_mob_update_device_wireless
Pro · Destructive
Replace one UniFi Mobility device's WiFi network name and password.

UniFi Network Application Info

ToolWhat it does
unifi_net_get_application_info
Free · Read-only
Get the version of the UniFi Network application running on one console.

UniFi Network Sites

ToolWhat it does
unifi_net_list_sites
Free · Read-only
List the UniFi Network sites on one console — CALL THIS SECOND, after unifi_sm_list_hosts.

UniFi Network Reference Data

ToolWhat it does
unifi_net_list_countries
Free · Read-only
List the ISO country codes and names UniFi accepts.
unifi_net_list_device_tags
Free · Read-only
List the device tags defined on a UniFi Network site.
unifi_net_list_dpi_applications
Free · Read-only
List the applications UniFi's deep packet inspection can recognise, each with the DPI category it belongs to.
unifi_net_list_dpi_categories
Free · Read-only
List UniFi's predefined deep-packet-inspection categories — the coarse traffic classes (streaming, gaming, social, and so on) that group the individual applications returned by unifi_net_list_dpi_applications.
unifi_net_list_radius_profiles
Free · Read-only
List the RADIUS authentication profiles on a UniFi Network site, with each profile's origin metadata showing whether UniFi defined it or an administrator did.
unifi_net_list_wan_interfaces
Free · Read-only
List the WAN interfaces defined on a UniFi Network site — the uplinks that network and NAT configuration bind to, and the ids a multi-WAN policy references.

UniFi Network VPN

ToolWhat it does
unifi_net_list_site_to_site_vpn_tunnels
Free · Read-only
List the site-to-site VPN tunnels on a UniFi Network site — the permanent links joining this site's networks to another location's.
unifi_net_list_vpn_servers
Free · Read-only
List the VPN servers configured on a UniFi Network site — the remote-access endpoints clients dial into, with each server's type and configuration.

UniFi Network Devices

ToolWhat it does
unifi_net_adopt_device
Pro · Write
Adopt a device onto a UniFi Network site, bringing it under the console's management.
unifi_net_get_device
Free · Read-only
Get one adopted device in full: firmware version and update state, uplink and adoption state, the features it supports, and its interfaces — the ports and radios.
unifi_net_get_device_latest_statistics
Free · Read-only
Get the most recent telemetry sample for one adopted device: uptime, transmit and receive rates, and CPU and memory utilisation.
unifi_net_list_devices
Free · Read-only
List the adopted UniFi devices on one Network site — access points, switches, gateways and the rest of the managed estate.
unifi_net_list_pending_devices
Free · Read-only
List devices that a console can see but has not adopted yet — new hardware waiting to be brought under management.
unifi_net_power_cycle_port
Pro · Destructive
Cut and restore PoE power on one switch port.
unifi_net_remove_device
Pro · Destructive
Remove a device from a UniFi Network site.
unifi_net_restart_device
Pro · Destructive
Reboot one adopted UniFi device.

UniFi Network Clients

ToolWhat it does
unifi_net_authorize_guest_access
Pro · Write
Authorize a guest client on a UniFi Network site, granting it network access without a voucher.
unifi_net_get_client
Free · Read-only
Get one connected client in full, by the client id from unifi_net_list_clients: name, IP and MAC addresses, how it is connected, and its access information — including, for a guest, whether its authorization is currently active and when it expires.
unifi_net_list_clients
Free · Read-only
List the clients currently connected to a UniFi Network site — wired, wireless, VPN and guest alike.
unifi_net_unauthorize_guest_access
Pro · Destructive
Revoke a guest client's network access on a UniFi Network site.

UniFi Network Networks (VLANs)

ToolWhat it does
unifi_net_create_network
Pro · Write
Create a network (VLAN) on a UniFi Network site.
unifi_net_delete_network
Pro · Destructive
Delete a network (VLAN) from a UniFi Network site.
unifi_net_get_network
Free · Read-only
Get one network (VLAN) in full, by the id from unifi_net_list_networks — its subnet, VLAN id, DHCP settings, purpose and the rest of its configuration.
unifi_net_get_network_references
Free · Read-only
List everything that references one network — the WiFi broadcasts, firewall rules, policies and other resources that would be affected if it went away.
unifi_net_list_networks
Free · Read-only
List the networks (VLANs) configured on a UniFi Network site, each with the network id every other network tool needs plus its name and core settings.
unifi_net_update_network
Pro · Write
Update a network (VLAN) on a UniFi Network site.

UniFi Network WiFi Broadcasts

ToolWhat it does
unifi_net_create_wifi_broadcast
Pro · Write
Create a WiFi broadcast (SSID) on a UniFi Network site.
unifi_net_delete_wifi_broadcast
Pro · Destructive
Delete a WiFi broadcast (SSID) from a UniFi Network site.
unifi_net_get_wifi_broadcast
Free · Read-only
Get one WiFi broadcast (SSID) in full, by the id from unifi_net_list_wifi_broadcasts — its security settings, the bands it uses, the network it bridges to, hotspot configuration and which device tags it is aimed at.
unifi_net_list_wifi_broadcasts
Free · Read-only
List the WiFi broadcasts (SSIDs) on a UniFi Network site, each with the broadcast id the other WiFi tools need, its name, and whether it is enabled.
unifi_net_update_wifi_broadcast
Pro · Write
Update a WiFi broadcast (SSID) on a UniFi Network site.

UniFi Network Hotspot Vouchers

ToolWhat it does
unifi_net_create_vouchers
Pro · Write
Generate hotspot vouchers on a UniFi Network site.
unifi_net_delete_voucher
Pro · Destructive
Delete ONE hotspot voucher by id.
unifi_net_delete_vouchers_by_filter
Pro · Destructive
Bulk-delete hotspot vouchers matching a filter expression.
unifi_net_get_voucher
Pro · Read-only
Get one hotspot voucher in full, by the voucher id from unifi_net_list_vouchers.
unifi_net_list_vouchers
Pro · Read-only
List hotspot vouchers on a UniFi Network site.

UniFi Network Firewall

ToolWhat it does
unifi_net_create_firewall_policy
Pro · Write
Create a firewall policy on a UniFi Network site.
unifi_net_create_firewall_zone
Pro · Write
Create a custom firewall zone on a UniFi Network site — a new trust grouping that policies can be written between.
unifi_net_delete_firewall_policy
Pro · Destructive
Delete a firewall policy from a UniFi Network site.
unifi_net_delete_firewall_zone
Pro · Destructive
Delete a custom firewall zone from a UniFi Network site.
unifi_net_get_firewall_policy
Free · Read-only
Get one firewall policy in full, by the id from unifi_net_list_firewall_policies — its action, source and destination zones, the traffic it matches (including any traffic-matching lists it references) and its schedule.
unifi_net_get_firewall_policy_ordering
Free · Read-only
Get the evaluation order of user-defined firewall policies FOR ONE SOURCE/DESTINATION ZONE PAIR.
unifi_net_get_firewall_zone
Free · Read-only
Get one firewall zone in full, by the id from unifi_net_list_firewall_zones — its name, the networks assigned to it, and its origin.
unifi_net_list_firewall_policies
Free · Read-only
List the firewall policies on a UniFi Network site — the rules governing which traffic may pass between zones.
unifi_net_list_firewall_zones
Free · Read-only
List the firewall zones on a UniFi Network site — the trust groupings (internal, external, guest, and any custom ones) that policies are written between.
unifi_net_patch_firewall_policy
Pro · Write
Change individual fields of a firewall policy, leaving everything else as it is.
unifi_net_reorder_firewall_policies
Pro · Destructive
Replace the evaluation order of user-defined firewall policies for ONE source/destination zone pair.
unifi_net_update_firewall_policy
Pro · Write
Update a firewall policy on a UniFi Network site.
unifi_net_update_firewall_zone
Pro · Write
Update a firewall zone on a UniFi Network site.

UniFi Network Access Control

ToolWhat it does
unifi_net_create_acl_rule
Pro · Write
Create a user-defined ACL rule on a UniFi Network site.
unifi_net_delete_acl_rule
Pro · Destructive
Delete a user-defined ACL rule from a UniFi Network site.
unifi_net_get_acl_rule
Free · Read-only
Get one ACL rule in full, by the id from unifi_net_list_acl_rules — its action and its complete source and destination filters.
unifi_net_get_acl_rule_ordering
Free · Read-only
Get the site-wide evaluation order of user-defined ACL rules, as an ordered list of rule ids.
unifi_net_list_acl_rules
Free · Read-only
List the access control list rules on a UniFi Network site — the switch- and network-level rules controlling which traffic may pass.
unifi_net_reorder_acl_rules
Pro · Destructive
Replace the site-wide evaluation order of user-defined ACL rules.
unifi_net_update_acl_rule
Pro · Write
Update a user-defined ACL rule on a UniFi Network site.

UniFi Network DNS Policies

ToolWhat it does
unifi_net_create_dns_policy
Pro · Write
Create a DNS policy (a local DNS record) on a UniFi Network site.
unifi_net_delete_dns_policy
Pro · Destructive
Delete a DNS policy (a local DNS record) from a UniFi Network site.
unifi_net_get_dns_policy
Free · Read-only
Get one DNS policy in full, by the id from unifi_net_list_dns_policies — its record type and the complete set of fields that type carries (an MX record's priority, an SRV record's port and weight, and so on).
unifi_net_list_dns_policies
Free · Read-only
List the DNS policies on a UniFi Network site — the DNS records the gateway serves locally, in the familiar A, AAAA, CNAME, MX, TXT and SRV shapes.
unifi_net_update_dns_policy
Pro · Write
Update a DNS policy on a UniFi Network site.

UniFi Network Traffic Matching Lists

ToolWhat it does
unifi_net_create_traffic_matching_list
Pro · Write
Create a traffic matching list on a UniFi Network site — a reusable named set of ports or IP addresses for firewall policies to reference.
unifi_net_delete_traffic_matching_list
Pro · Destructive
Delete a traffic matching list from a UniFi Network site.
unifi_net_get_traffic_matching_list
Free · Read-only
Get one traffic matching list in full, by the id from unifi_net_list_traffic_matching_lists — its type and every entry it contains.
unifi_net_list_traffic_matching_lists
Free · Read-only
List the traffic matching lists on a UniFi Network site — the named sets of ports or IP addresses that firewall policies reference instead of restating the same values in every rule.
unifi_net_update_traffic_matching_list
Pro · Write
Update a traffic matching list on a UniFi Network site.

UniFi Network Switching

ToolWhat it does
unifi_net_get_lag
Free · Read-only
Get one Link Aggregation Group in full, by the id from unifi_net_list_lags — its member ports, the devices they sit on, and the bond's configuration.
unifi_net_get_mc_lag_domain
Free · Read-only
Get one MC-LAG domain in full, by the id from unifi_net_list_mc_lag_domains — its member switches and the domain's configuration.
unifi_net_get_switch_stack
Free · Read-only
Get one switch stack in full, by the id from unifi_net_list_switch_stacks — its member switches and their roles within the stack.
unifi_net_list_lags
Free · Read-only
List the Link Aggregation Groups on a UniFi Network site — sets of switch ports bonded into one logical link for extra bandwidth or redundancy.
unifi_net_list_mc_lag_domains
Free · Read-only
List the MC-LAG (multi-chassis link aggregation) domains on a UniFi Network site — pairs of switches presenting themselves as one to a downstream device so a single switch failure does not break the link.
unifi_net_list_switch_stacks
Free · Read-only
List the switch stacks on a UniFi Network site — groups of physical switches managed as a single logical unit.

UniFi Protect Cameras

ToolWhat it does
unifi_protect_create_camera_rtsps_streams
Pro · Write
Enable RTSPS (secure RTSP) streams on one UniFi Protect camera at the requested quality levels, and return their URLs.
unifi_protect_create_camera_talkback_session
Pro · Write
Open a talkback (two-way audio) session to one UniFi Protect camera and return the stream URL plus its audio configuration — codec, sampling rate and bits per sample.
unifi_protect_delete_camera_rtsps_streams
Pro · Destructive
Remove the RTSPS stream(s) for one UniFi Protect camera at the named quality levels.
unifi_protect_disable_camera_mic_permanently
Pro · Destructive
PERMANENTLY disable a UniFi Protect camera's microphone.
unifi_protect_get_camera
Free · Read-only
Get one UniFi Protect camera in full, by the camera id from unifi_protect_list_cameras.
unifi_protect_get_camera_rtsps_streams
Pro · Read-only
Get the existing RTSPS (secure RTSP) stream URLs for one UniFi Protect camera.
unifi_protect_get_camera_snapshot
Pro · Read-only
Capture a still image from one UniFi Protect camera and return a short-lived read-only download URL (valid about three minutes) plus its content type, size and expiry — the JPEG itself is never inlined in the response.
unifi_protect_list_cameras
Free · Read-only
List every UniFi Protect camera on one console — the ENTRY POINT for the Protect camera surface.
unifi_protect_update_camera
Pro · Write
Update a UniFi Protect camera's settings.

UniFi Protect Camera PTZ

ToolWhat it does
unifi_protect_ptz_goto_preset
Pro · Destructive
Move a pan-tilt-zoom UniFi Protect camera to a stored preset position.
unifi_protect_start_ptz_patrol
Pro · Destructive
Start a stored patrol on a pan-tilt-zoom UniFi Protect camera, putting it into continuous motion between preset positions.
unifi_protect_stop_ptz_patrol
Pro · Destructive
Stop the patrol currently running on a pan-tilt-zoom UniFi Protect camera.

UniFi Protect Sirens

ToolWhat it does
unifi_protect_get_siren
Free · Read-only
Get one UniFi Protect siren in full, by the siren id from unifi_protect_list_sirens.
unifi_protect_list_sirens
Free · Read-only
List every UniFi Protect siren on one console.
unifi_protect_play_siren
Pro · Destructive
Sound a UniFi Protect siren alarm for a fixed duration.
unifi_protect_stop_siren
Pro · Destructive
Silence a sounding UniFi Protect siren immediately.
unifi_protect_test_siren_sound
Pro · Destructive
Sound a UniFi Protect siren for 5 seconds as a test.
unifi_protect_update_siren
Pro · Write
Update a UniFi Protect siren's settings.

UniFi Protect Arm Profiles

ToolWhat it does
unifi_protect_create_arm_profile
Pro · Write
Create a new arm profile on a UniFi Protect console.
unifi_protect_delete_arm_profile
Pro · Destructive
Permanently delete a UniFi Protect arm profile.
unifi_protect_disable_arm_alarm
Pro · Destructive
DISARM the UniFi Protect alarm system on one console.
unifi_protect_enable_arm_alarm
Pro · Destructive
ARM the UniFi Protect alarm system on one console, using whichever profile is currently selected.
unifi_protect_list_arm_profiles
Free · Read-only
List the arm profiles on one UniFi Protect console — the named security postures that decide which automations run, which schedules apply, whether everything is recorded, and how long arming is delayed.
unifi_protect_set_current_arm_profile
Pro · Destructive
Choose which arm profile the UniFi Protect console will use when it arms.
unifi_protect_update_arm_profile
Pro · Write
Update an existing UniFi Protect arm profile.

UniFi Protect Alarm Hubs

ToolWhat it does
unifi_protect_get_alarm_hub
Free · Read-only
Get one UniFi Protect alarm hub in full, by the id from unifi_protect_list_alarm_hubs.
unifi_protect_list_alarm_hubs
Free · Read-only
List every UniFi Protect alarm hub on one console.
unifi_protect_trigger_alarm_hub_output
Pro · Destructive
Switch one of a UniFi Protect alarm hub's hardwired output channels.
unifi_protect_update_alarm_hub
Pro · Write
Rename a UniFi Protect alarm hub.

UniFi Protect Alarm Manager

ToolWhat it does
unifi_protect_send_alarm_manager_webhook
Pro · Destructive
Fire the UniFi Protect alarms that an administrator has configured against a given trigger id.

UniFi Protect Relays

ToolWhat it does
unifi_protect_activate_relay_output
Pro · Destructive
Drive one of a UniFi Protect relay's output channels.
unifi_protect_get_relay
Free · Read-only
Get one UniFi Protect relay in full, by the relay id from unifi_protect_list_relays.
unifi_protect_list_relays
Free · Read-only
List every UniFi Protect relay on one console.
unifi_protect_update_relay
Pro · Write
Update a UniFi Protect relay's settings.

UniFi Protect Sensors

ToolWhat it does
unifi_protect_get_sensor
Free · Read-only
Get one UniFi Protect sensor in full, by the sensor id from unifi_protect_list_sensors.
unifi_protect_list_sensors
Free · Read-only
List every UniFi Protect sensor on one console.
unifi_protect_update_sensor
Pro · Write
Update a UniFi Protect sensor's settings.

UniFi Protect Lights

ToolWhat it does
unifi_protect_get_light
Free · Read-only
Get one UniFi Protect floodlight in full, by the light id from unifi_protect_list_lights.
unifi_protect_list_lights
Free · Read-only
List every UniFi Protect floodlight on one console.
unifi_protect_update_light
Pro · Write
Update a UniFi Protect floodlight's settings, including switching it on or off.

UniFi Protect Chimes

ToolWhat it does
unifi_protect_get_chime
Free · Read-only
Get one UniFi Protect chime in full, by the chime id from unifi_protect_list_chimes.
unifi_protect_list_chimes
Free · Read-only
List every UniFi Protect chime on one console.
unifi_protect_update_chime
Pro · Write
Update a UniFi Protect chime's settings.

UniFi Protect Speakers

ToolWhat it does
unifi_protect_get_speaker
Free · Read-only
Get one UniFi Protect speaker in full, by the speaker id from unifi_protect_list_speakers.
unifi_protect_list_speakers
Free · Read-only
List every UniFi Protect speaker on one console.
unifi_protect_test_speaker_sound
Pro · Write
Play a short test tone on a UniFi Protect speaker.
unifi_protect_update_speaker
Pro · Write
Update a UniFi Protect speaker's settings.

UniFi Protect Viewers

ToolWhat it does
unifi_protect_get_viewer
Free · Read-only
Get one UniFi Protect viewer in full, by the viewer id from unifi_protect_list_viewers.
unifi_protect_list_viewers
Free · Read-only
List every UniFi Protect viewer on one console — the display devices that show a live view on a monitor or video wall.
unifi_protect_update_viewer
Pro · Write
Rename a UniFi Protect viewer or change which live view it displays.

UniFi Protect Live Views

ToolWhat it does
unifi_protect_create_liveview
Pro · Write
Create a new UniFi Protect live view.
unifi_protect_get_liveview
Free · Read-only
Get one UniFi Protect live view in full, by the id from unifi_protect_list_liveviews.
unifi_protect_list_liveviews
Free · Read-only
List every UniFi Protect live view on one console — the named camera layouts that viewer devices display.
unifi_protect_update_liveview
Pro · Write
Update a UniFi Protect live view.

UniFi Protect Fobs

ToolWhat it does
unifi_protect_get_fob
Free · Read-only
Get one UniFi Protect key fob in full, by the fob id from unifi_protect_list_fobs.
unifi_protect_list_fobs
Free · Read-only
List every UniFi Protect key fob on one console — the handheld devices people use to arm and disarm.
unifi_protect_update_fob
Pro · Write
Rename a UniFi Protect key fob.

UniFi Protect Bridges

ToolWhat it does
unifi_protect_get_bridge
Free · Read-only
Get one UniFi Protect bridge in full, by the bridge id from unifi_protect_list_bridges.
unifi_protect_list_bridges
Free · Read-only
List every UniFi Protect bridge on one console — the radio devices that link wireless Protect accessories back to the console.
unifi_protect_update_bridge
Pro · Write
Rename a UniFi Protect bridge.
ToolWhat it does
unifi_protect_get_link_station
Free · Read-only
Get one UniFi Protect link station in full, by the id from unifi_protect_list_link_stations.
unifi_protect_list_link_stations
Free · Read-only
List every UniFi Protect link station on one console.
unifi_protect_update_link_station
Pro · Write
Rename a UniFi Protect link station.

UniFi Protect Device Asset Files

ToolWhat it does
unifi_protect_list_device_asset_files
Free · Read-only
List the device asset files uploaded to one UniFi Protect console.
unifi_protect_upload_device_asset_file
Pro · Write
Upload a device asset file to a UniFi Protect console — an animation shown on a doorbell display.

UniFi Protect NVR & App Info

ToolWhat it does
unifi_protect_get_app_info
Free · Read-only
Get the UniFi Protect application version running on one console.
unifi_protect_get_nvr
Free · Read-only
Get the UniFi Protect NVR record for one console.

UniFi Protect Users & Identity

ToolWhat it does
unifi_protect_get_identity_user
Pro · Read-only
Get one UniFi Identity user in full, by the id from unifi_protect_list_identity_users.
unifi_protect_get_user
Free · Read-only
Get one UniFi Protect application user in full, by the user id from unifi_protect_list_users.
unifi_protect_list_identity_users
Pro · Read-only
List the UniFi Identity users known to one UniFi Protect console.
unifi_protect_list_users
Free · Read-only
List the UniFi Protect application users on one console.