Server data from the Official MCP Registry
MCP server for the Cisco Meraki Dashboard: networks, devices, wireless, switch, appliance.
About
MCP server for the Cisco Meraki Dashboard: networks, devices, wireless, switch, appliance.
Security Report
This is a well-structured MCP server with strong safety-by-default design and proper authentication mechanisms. The code demonstrates good security practices including read-only mode enforcement, destructive action confirmation gating, and appropriate credential handling via environment variables. A large portion of the analyzed file is an embedded UI component (generated from build process), which is not a security concern. Minor code quality observations exist but do not materially impact the security posture. Supply chain analysis found 5 known vulnerabilities in dependencies (2 critical, 2 high severity).
3 files analyzed ยท 7 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
What You'll Need
Set these up before or after installing:
Environment variable: MERAKI_API_KEY
Environment variable: MERAKI_ORG_ID
Environment variable: MERAKI_BASE_URL
Environment variable: READ_ONLY_MODE
Environment variable: MCP_TRANSPORT
Environment variable: AUTH_MODE
Environment variable: LOG_LEVEL
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-wyre-technology-meraki-mcp": {
"env": {
"AUTH_MODE": "your-auth-mode-here",
"LOG_LEVEL": "your-log-level-here",
"MCP_TRANSPORT": "your-mcp-transport-here",
"MERAKI_ORG_ID": "your-meraki-org-id-here",
"MERAKI_API_KEY": "your-meraki-api-key-here",
"READ_ONLY_MODE": "your-read-only-mode-here",
"MERAKI_BASE_URL": "your-meraki-base-url-here"
},
"args": [
"-y",
"@wyre-technology/meraki-mcp"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
Meraki MCP Server
A Model Context Protocol (MCP) server that provides AI assistants with structured access to the Cisco Meraki Dashboard โ organizations, networks, devices, clients, wireless, switching, and appliance operations.
Note: This project is maintained by Wyre Technology.
Quick Start
Claude Code (CLI):
claude mcp add meraki-mcp \
-e MERAKI_API_KEY=your-api-key \
-e MERAKI_ORG_ID=your-org-id \
-- npx -y github:wyre-technology/meraki-mcp
See Installation for Docker and from-source methods.
Features
- ๐ MCP Protocol Compliance: Full support for MCP tools over stdio and HTTP transports
- ๐ Network Coverage: Tools spanning organizations, networks, devices, clients, wireless, switching, and appliance (MX) operations
- ๐ Flattened Navigation:
meraki_navigateandmeraki_statusare stateless discovery aids โ every tool is callable at any time - ๐ Safety by Default: Read-only mode is ON by default; writes are gated and destructive actions require explicit confirmation
- ๐ผ๏ธ Interactive Device Card (MCP Apps):
meraki_devices_getrenders as a read-only interactive card in MCP Apps hosts (SEP-1865) โ neutral by default, brandable viawindow.__BRAND__injection orMCP_BRAND_*env vars - ๐งฐ Long-Tail Escape Hatch:
meraki_raw_requestreaches any Meraki v1 endpoint not covered by a curated tool - ๐ณ Docker Ready: Containerized deployment with HTTP transport and health checks
- ๐ Structured Logging: Configurable log levels
Installation
Option 1: Docker
docker run -d \
-e MERAKI_API_KEY=your-key \
-e MERAKI_ORG_ID=your-org-id \
-p 8080:8080 \
ghcr.io/wyre-technology/meraki-mcp:latest
Option 2: From Source
git clone https://github.com/wyre-technology/meraki-mcp.git
cd meraki-mcp
npm ci
npm run build
Configuration
| Variable | Description | Default |
|---|---|---|
MERAKI_API_KEY | Meraki Dashboard API key | โ |
MERAKI_ORG_ID | Default organization ID (optional) | โ |
MERAKI_BASE_URL | Override the Meraki API base URL (optional) | โ |
READ_ONLY_MODE | Safety switch โ blocks all writes when true | true |
MCP_TRANSPORT | Transport mode (stdio or http) | stdio |
MCP_HTTP_PORT | HTTP server port | 8080 |
AUTH_MODE | Auth mode (env or gateway) | env |
LOG_LEVEL | Log level (debug, info, warn, error) | info |
The legacy
READ_ONLYvariable is also honored;READ_ONLY_MODEtakes precedence.
Safety Model
This server defaults to read-only. Write operations (updates, reboots, deletions) are blocked unless you explicitly set READ_ONLY_MODE=false.
- Read tools (
*_list,*_get) are always available. - High-impact writes (e.g.
meraki_networks_update,meraki_clients_update_policy) are gated by read-only mode. - Confirmation-gated tools additionally require a
confirm_destructive_action: trueargument, even onceREAD_ONLY_MODE=false. The confirmation flag is never forwarded to the Meraki API. Two groups qualify:- Irreversible โ
meraki_networks_delete,meraki_devices_remove. - High blast radius โ
meraki_appliance_firewall_l3_update,meraki_switch_ports_update,meraki_wireless_ssids_update,meraki_devices_reboot. These are reversible in principle, but each is applied over the same network link the change can break, so an operator can lose the connectivity needed to undo it.meraki_appliance_firewall_l3_updatealso replaces the rule set โ any rule not in the payload is deleted โ andmeraki_wireless_ssids_updatedrops every client on the SSID when the PSK or auth mode changes.
- Irreversible โ
- Confirmation is not an escape hatch from read-only mode: while
READ_ONLY_MODEis on, a confirmed call is still blocked. - The
meraki_raw_requestescape hatch classifies the call by HTTP method:GETis a read;POST/PUT/DELETEare writes;DELETEis destructive.
Domains
All tools are returned upfront. Use meraki_navigate to explore a domain's tools, or meraki_status to check connectivity and the configured organization.
| Domain | Tools |
|---|---|
| organizations | meraki_organizations_list, meraki_organizations_get, meraki_organizations_inventory_list |
| networks | meraki_networks_list, meraki_networks_get, meraki_networks_update โ , meraki_networks_delete โ โ |
| devices | meraki_devices_list, meraki_devices_get, meraki_devices_reboot โ โ , meraki_devices_remove โ โ |
| clients | meraki_clients_list, meraki_clients_get, meraki_clients_get_policy, meraki_clients_update_policy โ |
| wireless | meraki_wireless_ssids_list, meraki_wireless_ssids_update โ โ , meraki_wireless_rf_profiles_list |
| switch | meraki_switch_ports_list, meraki_switch_ports_update โ โ , meraki_switch_port_statuses_list |
| appliance | meraki_appliance_firewall_l3_get, meraki_appliance_firewall_l3_update โ โ , meraki_appliance_vpn_status_get |
| (long tail) | meraki_raw_request โ โ (on DELETE) |
โ = high-impact write, gated by read-only mode ยท โ โ = additionally requires confirm_destructive_action: true
Docker Deployment
Copy .env.example to .env and fill in your credentials:
cp .env.example .env
# Edit .env with your Meraki API key (and org ID)
docker run --env-file .env -p 8080:8080 ghcr.io/wyre-technology/meraki-mcp:latest
Development
npm ci
npm run build # Build the project
npm run start # Run over stdio
npm run start:http # Run the HTTP transport
npm run test # Run tests
Testing
npm test
The test suite covers the safety contract: read-only enforcement, destructive confirmation, and that confirm_destructive_action is never forwarded to the SDK.
License
Apache 2.0 โ Copyright WYRE Technology
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Fetch
Freeby Modelcontextprotocol ยท Developer Tools
Web content fetching and conversion for efficient LLM usage
Toleno
Freeby Toleno ยท Developer Tools
Toleno Network MCP Server โ Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace ยท Developer Tools
Create, build, and publish Python MCP servers to PyPI โ conversationally.
MarkItDown
Freeby Microsoft ยท Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
MCP Marketplace
Freeby mcp-marketplace ยท Developer Tools
Search and install MCP servers from inside your AI client.
FinAgent
Freeby mcp-marketplace ยท Finance
Free stock data and market news for any MCP-compatible AI assistant.
