Server data from the Official MCP Registry
Administer a Zigbee2MQTT estate: health, mesh diagnostics, OTA, pairing, device management.
About
Administer a Zigbee2MQTT estate: health, mesh diagnostics, OTA, pairing, device management.
Security Report
This is a well-designed MCP server for Zigbee2MQTT administration with appropriate authentication, sensible permission scoping, and careful handling of destructive operations. The codebase shows strong security practices including credential handling via environment variables, tiered access control, and explicit confirmation requirements for irreversible operations. Minor code quality observations do not materially impact security. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.
3 files analyzed · 7 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
What You'll Need
Set these up before or after installing:
Environment variable: Z2M_MQTT_URL
Environment variable: Z2M_MQTT_USERNAME
Environment variable: Z2M_MQTT_PASSWORD
Environment variable: Z2M_BASE_TOPIC
Environment variable: Z2M_WRITE_MODE
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-alexpfau-zigbee2mqtt-mcp": {
"env": {
"Z2M_MQTT_URL": "your-z2m-mqtt-url-here",
"Z2M_BASE_TOPIC": "your-z2m-base-topic-here",
"Z2M_WRITE_MODE": "your-z2m-write-mode-here",
"Z2M_MQTT_PASSWORD": "your-z2m-mqtt-password-here",
"Z2M_MQTT_USERNAME": "your-z2m-mqtt-username-here"
},
"args": [
"-y",
"zigbee2mqtt-mcp"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
zigbee2mqtt-mcp
A Model Context Protocol server for administering a Zigbee2MQTT estate.
Most Zigbee integrations already let an assistant turn a light on. This one is for the layer underneath: mesh health, weak links, devices that keep rejoining, stale batteries, firmware updates, pairing, binding, reporting intervals and device options — the things you normally open the Zigbee2MQTT frontend for.
It talks directly to the Zigbee2MQTT MQTT bridge API, so it works with any Zigbee2MQTT 1.17+ installation regardless of whether you use Home Assistant, Node-RED, openHAB or nothing at all.
Why this exists
If you already run Home Assistant, your Zigbee devices are exposed there and an assistant can control them. What Home Assistant does not expose is the bridge itself: link quality, mesh topology, interview state, OTA availability, permit_join, device options, bindings and reporting configuration. This server fills exactly that gap.
Design
- No database. Zigbee2MQTT publishes its bridge topics as retained messages, so a fresh subscription yields a complete picture in a few hundred milliseconds. The server keeps only the latest payload per topic in memory.
- No daemon. Pure stdio. It starts and dies with the MCP session.
- Correlated requests. Every
bridge/request/*carries atransactionid and is matched to itsbridge/response/*, so concurrent calls cannot cross wires. - Tiered writes. Destructive operations are gated behind a write mode and an explicit
confirmargument.
Install
Requires Node.js 20 or newer and network access to the MQTT broker that Zigbee2MQTT uses.
npx zigbee2mqtt-mcp
VS Code / GitHub Copilot
Add to your MCP configuration:
{
"servers": {
"zigbee2mqtt": {
"command": "npx",
"args": ["-y", "zigbee2mqtt-mcp"],
"env": {
"Z2M_MQTT_URL": "mqtt://192.168.1.10:1883",
"Z2M_MQTT_USERNAME": "mqtt",
"Z2M_MQTT_PASSWORD": "${input:z2mPassword}"
}
}
}
}
Claude Desktop
{
"mcpServers": {
"zigbee2mqtt": {
"command": "npx",
"args": ["-y", "zigbee2mqtt-mcp"],
"env": {
"Z2M_MQTT_URL": "mqtt://192.168.1.10:1883"
}
}
}
}
Point
Z2M_MQTT_URLat your MQTT broker, not at the Zigbee2MQTT frontend port. If Zigbee2MQTT'sconfiguration.yamlsaysmqtt.server: mqtt://192.168.1.10:1883, use that value verbatim.
Behind a corporate npm proxy? If
npm config get registryis nothttps://registry.npmjs.org/, your proxy's upstream feed may not carry this package. Add an explicit override to the args rather than changing your global registry:"args": ["-y", "--registry", "https://registry.npmjs.org/", "zigbee2mqtt-mcp"]
Configuration
| Variable | Default | Purpose |
|---|---|---|
Z2M_MQTT_URL | required | Broker URL. mqtt://, mqtts://, ws://, wss:// |
Z2M_MQTT_USERNAME / Z2M_MQTT_PASSWORD | – | Broker credentials |
Z2M_BASE_TOPIC | zigbee2mqtt | Must match mqtt.base_topic |
Z2M_WRITE_MODE | safe | off, safe or full |
Z2M_LOG_LEVEL | error | Diagnostics on stderr |
Z2M_WEAK_LINK_THRESHOLD | 30 | Link quality below this is flagged |
Z2M_LOW_BATTERY_THRESHOLD | 20 | Battery percentage below this is flagged |
Z2M_STALE_HOURS | 24 | Hours of silence before a device is stale |
Z2M_CONNECT_TIMEOUT_MS | 10000 | Broker connect timeout |
Z2M_REQUEST_TIMEOUT_MS | 15000 | Default bridge request timeout |
Z2M_MQTT_REJECT_UNAUTHORIZED | true | Set false for self-signed TLS |
Z2M_MQTT_CA / _CERT / _KEY | – | Paths to TLS material |
Write modes
Tools above the active tier are not registered at all, so a model cannot reach for them.
| Mode | Exposes |
|---|---|
off | Read-only tools |
safe | Default. Read plus non-destructive writes: pairing, options, rename, configure, interview, binding, reporting, groups, state |
full | Everything, including device removal, OTA flashing, Touchlink and bridge restart |
Irreversible tools (z2m_remove_device, z2m_ota_update, z2m_touchlink, z2m_restart_bridge, z2m_set_bridge_options) additionally require confirm: true on every call.
Every tool also advertises MCP tool annotations so a client can decide what may run without prompting:
| Annotation | Meaning here |
|---|---|
readOnlyHint: true | The seven read tools. They never change the network. |
destructiveHint: true | z2m_remove_device, z2m_ota_update, z2m_touchlink, z2m_restart_bridge, z2m_set_bridge_options |
idempotentHint | True where repeating the call has no additional effect |
openWorldHint: true | Always — every tool reaches a live Zigbee network |
Opt in to the destructive tier only when you want it:
"env": { "Z2M_WRITE_MODE": "full" }
Tools
Read
| Tool | Purpose |
|---|---|
z2m_bridge_info | Version, coordinator, channel, PAN ID, permit_join, restart_required, runtime stats |
z2m_list_devices | Filter and sort devices by type, availability, link quality, battery, pending update |
z2m_get_device | Exposes, settable options, endpoints, bindings, configured reportings, current state |
z2m_health_report | Whole-estate audit in one call |
z2m_network_map | Mesh topology with parent, depth, link quality, orphan detection |
z2m_list_groups | Groups, members and scenes |
z2m_get_logs | Bridge logs and lifecycle events, buffered or watched live |
Safe writes
z2m_check_updates, z2m_permit_join, z2m_set_device_options, z2m_rename_device, z2m_configure_device, z2m_interview_device, z2m_set_state, z2m_manage_group, z2m_bind, z2m_configure_reporting
Full writes
z2m_remove_device, z2m_ota_update, z2m_restart_bridge, z2m_set_bridge_options, z2m_coordinator_check, z2m_touchlink
Data availability caveats
Some fields depend on your Zigbee2MQTT configuration. The server detects what is available and tells you rather than silently returning nothing.
| Field | Requires | If missing |
|---|---|---|
last_seen | advanced.last_seen set to e.g. ISO_8601 (default is disable) | Staleness checks are skipped and a hint is returned |
availability | availability.enabled: true | Offline detection is skipped and a hint is returned |
linkquality, battery, update | Live device traffic — Zigbee2MQTT does not retain device state topics | Pass collect_seconds to listen briefly, or use z2m_network_map for authoritative link quality |
z2m_coordinator_check | A Texas Instruments adapter (CC2652/CC1352) | Returns an error on other adapters; z2m_bridge_info reports whether it is supported |
Example prompts
- "Is my Zigbee network healthy?"
- "Which devices have the weakest signal?"
- "Which batteries need replacing?"
- "Any firmware updates available?"
- "Open the network for pairing via the kitchen router for two minutes."
- "This sensor stopped reporting temperature — fix it."
- "Bind the hallway remote to the hallway light so it works if the bridge is down."
Development
npm install
npm run build
npm run watch
# Manual smoke test against a real instance
Z2M_MQTT_URL=mqtt://192.168.1.10:1883 node scripts/smoke.mjs
Z2M_MQTT_URL=mqtt://192.168.1.10:1883 node scripts/smoke.mjs z2m_list_devices '{"only_problems":true}'
# Sequential read-after-write test. Renames a device and creates a group, then
# restores both, including on failure. Set Z2M_TEST_DEVICE to pick the device,
# or ROUNDTRIP_GROUPS_ONLY=1 to skip the rename.
Z2M_MQTT_URL=mqtt://192.168.1.10:1883 node scripts/roundtrip.mjs
Note that an MCP server may receive requests concurrently. When testing ordering,
await each response before sending the next, as roundtrip.mjs does — piping
several requests at once will produce misleading results.
Releases are tag-driven: npm version <patch|minor|major> then
git push --follow-tags. CI publishes to npm with provenance, rewrites
server.json's version from the tag and publishes to the MCP Registry, then
creates the GitHub release. The version committed in server.json is therefore
not authoritative — the tag is.
Safety
This server can remove devices from your network and flash firmware. Both are irreversible and OTA failures can brick hardware. Those tools live in the full tier, which is not enabled by default — you must opt in with Z2M_WRITE_MODE=full. Broker credentials are read from the environment and never logged.
Status
Early release. Developed and tested against a 50-device EmberZNet estate on Zigbee2MQTT 2.12.x. Other adapters (Texas Instruments, deCONZ/ConBee, zStack), TLS and WebSocket brokers, and large estates are unverified. Bug reports and pull requests are very welcome — please include your adapter type and Zigbee2MQTT version from z2m_bridge_info.
License
MIT
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
FinAgent
Freeby mcp-marketplace · Finance
Free stock data and market news for any MCP-compatible AI assistant.
