{"name":"io.github.itunified-io/opnsense","slug":"itunified-io-opnsense","title":"OPNsense MCP Server","description":"OPNsense MCP Server — 72 tools for DNS, Firewall, DHCP, ACME, Routing, VLANs & more","url":"https://mcp.market/server/itunified-io-opnsense","rating":null,"grade":"C","score":65,"certified":false,"status":"active","category":"other","tags":[],"presence":{"score":0,"stars":null,"forks":null,"downloads_week":null,"last_push_at":null,"license":"AGPL-3.0-only"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/itunified-io/mcp-opnsense","website":null,"version":"2026.4.10","remotes":[],"packages":[{"registryType":"npm","identifier":"@itunified.io/mcp-opnsense","version":"2026.4.10-4","runtimeHint":"npx","transport":{"type":"stdio"},"environmentVariables":[{"description":"OPNsense base URL (e.g. https://192.168.1.1)","name":"OPNSENSE_URL"},{"description":"OPNsense API key for authentication","name":"OPNSENSE_API_KEY"},{"description":"OPNsense API secret for authentication","name":"OPNSENSE_API_SECRET"},{"description":"Set to false for self-signed certificates (default: true)","name":"OPNSENSE_VERIFY_SSL"}]}],"tools":[{"name":"opnsense_acme_add_account","description":"Register a new ACME account with a certificate authority (Let's Encrypt, ZeroSSL, etc.). Run opnsense_acme_apply afterwards.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_acme_add_challenge","description":"Add a DNS-01 challenge configuration for automated certificate validation. For Cloudflare, use the dedicated dns_cf_* fields instead of dns_environment. Run opnsense_acme_apply afterwards.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_acme_apply","description":"Apply pending ACME configuration changes (reconfigure service)","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_acme_create_cert","description":"Create a new ACME certificate request. Requires an account and challenge to be configured first. Run opnsense_acme_apply afterwards.","write_action":true,"price_micros":0,"input_schema":null},{"name":"opnsense_acme_delete_account","description":"Delete an ACME account by UUID. Run opnsense_acme_apply afterwards.","write_action":true,"price_micros":0,"input_schema":null},{"name":"opnsense_acme_delete_cert","description":"Delete an ACME certificate by UUID. Run opnsense_acme_apply afterwards.","write_action":true,"price_micros":0,"input_schema":null},{"name":"opnsense_acme_delete_challenge","description":"Delete an ACME challenge/validation method by UUID. Run opnsense_acme_apply afterwards.","write_action":true,"price_micros":0,"input_schema":null},{"name":"opnsense_acme_list_accounts","description":"List all ACME accounts (Let's Encrypt, ZeroSSL, etc.) configured in the os-acme-client plugin","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_acme_list_certs","description":"List all ACME certificates and their status (issued, pending, expired)","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_acme_list_challenges","description":"List all configured ACME challenge/validation methods (DNS-01, HTTP-01, etc.)","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_acme_register_account","description":"Trigger registration of an ACME account with its certificate authority. Use after adding an account to verify it registers successfully.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_acme_renew_cert","description":"Trigger immediate renewal/signing of an ACME certificate by UUID","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_acme_settings","description":"Get or update ACME service settings (enable/disable, environment, auto-renewal, log level). When called with no parameters, returns current settings. Run opnsense_acme_apply afterwards when updating.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_acme_update_challenge","description":"Update an existing ACME challenge/validation by UUID. Use to change credentials or settings. Run opnsense_acme_apply afterwards.","write_action":true,"price_micros":0,"input_schema":null},{"name":"opnsense_dhcp_add_static","description":"Add a static DHCP mapping (MAC-to-IP reservation). Supports both Kea DHCP and ISC DHCP (legacy) backends — auto-detected. Requires DHCP service restart to take effect.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_dhcp_delete_static","description":"Delete a static DHCP mapping by UUID. Supports both Kea DHCP and ISC DHCP (legacy) backends — auto-detected.","write_action":true,"price_micros":0,"input_schema":null},{"name":"opnsense_dhcp_find_lease","description":"Search DHCPv4 leases by IP address, MAC address, or hostname","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_dhcp_list_leases","description":"List all current DHCPv4 leases","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_dhcp_list_static","description":"List all static DHCP mappings (MAC-to-IP reservations). Supports both Kea DHCP and ISC DHCP (legacy) backends — auto-detected.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_diag_arp_table","description":"Show the ARP table (IP-to-MAC mappings). Optionally filter by IP, MAC, or interface.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_diag_dns_lookup","description":"Perform a DNS lookup from the OPNsense firewall","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_diag_fw_logs","description":"Retrieve recent firewall log entries","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_diag_fw_states","description":"List active firewall connection tracking states","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_diag_ping","description":"Ping a host from the OPNsense firewall","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_diag_reverse_dns","description":"Perform a reverse DNS lookup (IP to hostname) from the OPNsense firewall","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_diag_routes","description":"Show the routing table","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_diag_system_info","description":"Get system status information (CPU, memory, uptime, disk, versions)","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_diag_traceroute","description":"Run a traceroute from the OPNsense firewall to a destination","write_action":true,"price_micros":0,"input_schema":null},{"name":"opnsense_dns_add_forward","description":"Add a DNS forwarding server (DNS-over-TLS). Run opnsense_dns_apply afterwards to activate.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_dns_add_override","description":"Add a DNS host override (A/AAAA/CNAME record) to Unbound. Run opnsense_dns_apply afterwards to activate.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_dns_apply","description":"Apply pending DNS/Unbound configuration changes (reconfigure service)","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_dns_block_domain","description":"Block a domain by adding a domain override with an empty server. Run opnsense_dns_apply afterwards to activate.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_dns_cache_search","description":"Search the Unbound DNS cache for entries matching a domain. Useful for diagnosing cached SERVFAIL, stale records, or verifying cache state.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_dns_delete_forward","description":"Delete a DNS forwarding entry by UUID. Run opnsense_dns_apply afterwards to activate.","write_action":true,"price_micros":0,"input_schema":null},{"name":"opnsense_dns_delete_override","description":"Delete a DNS host override by UUID. Run opnsense_dns_apply afterwards to activate.","write_action":true,"price_micros":0,"input_schema":null},{"name":"opnsense_dns_diagnostics","description":"Dump the current Unbound DNS cache for diagnostic purposes","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_dns_flush_cache","description":"Flush the Unbound DNS resolver cache","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_dns_flush_zone","description":"Flush all cached DNS entries for a specific domain/zone. Use this to clear stale SERVFAIL or outdated records for a domain. Restarts Unbound to ensure complete cache clearing.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_dns_infra","description":"Dump the Unbound infrastructure cache showing upstream server RTT, EDNS support, and lame delegation status. Useful for diagnosing upstream DNS connectivity issues.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_dns_list_blocklist","description":"List all domain overrides (used for domain blocking) in Unbound","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_dns_list_forwards","description":"List all DNS-over-TLS forwarding servers configured in Unbound","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_dns_list_overrides","description":"List all DNS host overrides (A/AAAA/CNAME records) configured in Unbound","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_dns_stats","description":"Get Unbound DNS resolver statistics: query counts, cache hits/misses, uptime, and memory usage","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_dns_unblock_domain","description":"Unblock a domain by deleting its domain override. Run opnsense_dns_apply afterwards to activate.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_firmware_info","description":"Get firmware version, architecture, and update status of the OPNsense system","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_firmware_install","description":"Install an OPNsense plugin package by name (e.g. 'os-acme-client'). May require a service restart.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_firmware_list_plugins","description":"List all available and installed OPNsense plugins with their versions and status","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_firmware_remove","description":"Remove an installed OPNsense plugin package. DESTRUCTIVE: requires explicit confirmation.","write_action":true,"price_micros":0,"input_schema":null},{"name":"opnsense_firmware_status","description":"Check for available firmware upgrades and their status (running, pending, done)","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_fw_add_rule","description":"Add a new firewall filter rule. Run opnsense_fw_apply afterwards to activate.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_fw_apply","description":"Apply pending firewall configuration changes","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_fw_delete_rule","description":"Delete a firewall filter rule by UUID. Run opnsense_fw_apply afterwards to activate.","write_action":true,"price_micros":0,"input_schema":null},{"name":"opnsense_fw_drift_check","description":"Audit firewall filter rules for description hygiene. Returns rules whose description does not match the given regex (default: '^#\\d+:' — issue-reference prefix) and rules with empty descriptions. Read-only.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_fw_list_aliases","description":"List all firewall aliases (host groups, networks, ports, URLs)","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_fw_list_rules","description":"List all firewall filter rules","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_fw_manage_alias","description":"Create, update, or delete a firewall alias. Run opnsense_fw_apply afterwards to activate.","write_action":true,"price_micros":0,"input_schema":null},{"name":"opnsense_fw_reorder_rules","description":"Change the sequence (ordering) of a firewall filter rule by UUID. Rules with lower sequence values are evaluated first. Use this to enforce whitelist-before-deny ordering. Run opnsense_fw_apply afterwards to activate.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_fw_toggle_rule","description":"Enable or disable a firewall rule by UUID. Run opnsense_fw_apply afterwards to activate.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_fw_update_rule","description":"Update an existing firewall filter rule by UUID. Run opnsense_fw_apply afterwards to activate.","write_action":true,"price_micros":0,"input_schema":null},{"name":"opnsense_if_assign","description":"Assign an existing VLAN or NIC device to a free optN slot via SSH. Requires OPNSENSE_SSH_ENABLED=true and the opnsense-helpers/if_assign.php script installed on the target host. Fills the gap where the OPNsense REST API has no 'Interfaces → Assignments' endpoint.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_if_configure","description":"Configure IPv4/IPv6 on an already-assigned optN slot via SSH. Supports static, dhcp, dhcp6, track6, and 'none'. Requires OPNSENSE_SSH_ENABLED=true and the opnsense-helpers/if_configure.php script installed on the target host.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_if_get","description":"Get detailed configuration for a specific network interface (IP addresses, status, MTU, etc.)","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_if_list","description":"List all network interface names and their device mappings","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_if_stats","description":"Get traffic statistics for all interfaces (bytes, packets, errors, collisions)","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_kea_apply","description":"Apply pending Kea DHCP configuration changes (reconfigure service). Run after subnet or reservation changes.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_kea_subnet_create","description":"Create a new Kea DHCPv4 subnet. Run opnsense_kea_apply afterwards to activate.","write_action":true,"price_micros":0,"input_schema":null},{"name":"opnsense_kea_subnet_delete","description":"Delete a Kea DHCPv4 subnet by UUID. Run opnsense_kea_apply afterwards to activate.","write_action":true,"price_micros":0,"input_schema":null},{"name":"opnsense_kea_subnet_get","description":"Get detailed configuration of a specific Kea DHCPv4 subnet by UUID.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_kea_subnet_list","description":"List all Kea DHCPv4 subnets with their pools, options, and reservation counts.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_kea_subnet_update","description":"Update an existing Kea DHCPv4 subnet. Run opnsense_kea_apply afterwards to activate.","write_action":true,"price_micros":0,"input_schema":null},{"name":"opnsense_route_add","description":"Add a static route. The gateway parameter must be a gateway name from opnsense_route_gateway_list. Run opnsense_route_apply afterwards to activate.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_route_apply","description":"Apply static route configuration changes (reconfigure routing)","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_route_delete","description":"Delete a static route. Run opnsense_route_apply afterwards to activate.","write_action":true,"price_micros":0,"input_schema":null},{"name":"opnsense_route_gateway_list","description":"List all available gateways (used as targets for static routes)","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_route_list","description":"List all configured static routes","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_route_update","description":"Update an existing static route. Run opnsense_route_apply afterwards to activate.","write_action":true,"price_micros":0,"input_schema":null},{"name":"opnsense_svc_control","description":"Start, stop, or restart a service by name","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_svc_list","description":"List all services and their running status","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_sys_backup_download","description":"Download an OPNsense configuration backup as XML. Downloads the current running config if no backup_id is specified.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_sys_backup_list","description":"List all configuration backups stored on the OPNsense filesystem with timestamps, descriptions, and file sizes","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_sys_backup_revert","description":"Revert OPNsense configuration to a previous backup. DESTRUCTIVE: replaces the running config with the specified backup.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_sys_info","description":"Get system status information (hostname, versions, CPU, memory, uptime, disk usage)","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_sys_list_certs","description":"List all certificates in the OPNsense trust store with their refids, descriptions, and validity dates","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_tailscale_service_control","description":"Control the Tailscale service: start, stop, restart, or reconfigure (apply settings changes).","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_tailscale_service_status","description":"Check if the Tailscale service (tailscaled) is running.","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_tailscale_settings_get","description":"Get current Tailscale plugin settings (enabled, port, auth-key, advertise-routes, accept-routes, accept-dns, exit-node).","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_tailscale_settings_set","description":"Update Tailscale plugin settings. Only provided fields are changed. Run opnsense_tailscale_service_control with action 'reconfigure' afterwards to apply.","write_action":true,"price_micros":0,"input_schema":null},{"name":"opnsense_vlan_create","description":"Create a new 802.1Q VLAN interface on a parent interface. After create, run opnsense_if_assign to bind the VLAN to a logical interface (opt1, opt2, ...) and opnsense_if_configure to assign an IP.","write_action":true,"price_micros":0,"input_schema":null},{"name":"opnsense_vlan_delete","description":"Delete a VLAN interface by UUID. Fails if the VLAN is still assigned to a logical interface — unassign it first via opnsense_if_assign.","write_action":true,"price_micros":0,"input_schema":null},{"name":"opnsense_vlan_list","description":"List all configured 802.1Q VLAN interfaces (parent interface, VLAN tag, description, priority)","write_action":false,"price_micros":0,"input_schema":null},{"name":"opnsense_vlan_update","description":"Update an existing VLAN interface by UUID. Only provided fields are changed.","write_action":true,"price_micros":0,"input_schema":null}],"scan":{"score":65,"grade":"C","scanned_at":"2026-09-27T22:35:51.204Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-27T22:35:51.248Z","components":{"code":{"score":25,"max":25,"notes":["41 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":12,"max":15,"notes":["local package, no credentials required"]},"maintenance":{"score":3,"max":15,"notes":["repository not readable: repo not found"]},"identity":{"score":2,"max":10,"notes":["no repository or website to verify"]}},"findings":[],"inputs":{"packages":[{"registryType":"npm","identifier":"@itunified.io/mcp-opnsense","version":"2026.4.10-4","found":true,"license":"AGPL-3.0-only","hasInstallScripts":false,"dependencyCount":3,"publishedAt":"2026-04-10T06:36:04.274Z","repositoryUrl":"git+https://github.com/itunified-io/mcp-opnsense.git"}],"repo":{"found":false,"owner":"itunified-io","repo":"mcp-opnsense","error":"repo not found"},"icon":{"url":null,"source":"none"},"presence":{"stars":null,"forks":null,"downloadsWeek":null,"license":"AGPL-3.0-only","lastPushAt":null,"score":0}}}},"grade_history":[],"reviews":[]}