oci ghcr.io/wyre-ai/meraki-mcp:v1.1.9stdioupdated 8d ago
A Model Context Protocol (MCP) server that provides AI assistants with structured access to the Cisco Meraki Dashboard โ organizations, networks, devices, clients, wireless, switching, and appliance operations.
What can you do with Cisco Meraki?
Meraki MCP Server
A Model Context Protocol (MCP) server that provides AI assistants with structured access to the Cisco Meraki Dashboard โ organizations, networks, devices, clients, wireless, switching, and appliance operations.
Note: This project is maintained by Wyre Technology.
Quick Start
Claude Code (CLI):
claude mcp add meraki-mcp \
-e MERAKI_API_KEY=your-api-key \
-e MERAKI_ORG_ID=your-org-id \
-- npx -y github:WYRE-AI/meraki-mcp
See Installation for Docker and from-source methods.
Features
- ๐ MCP Protocol Compliance: Full support for MCP tools over stdio and HTTP transports
- ๐ Network Coverage: Tools spanning organizations, networks, devices, clients, wireless, switching, and appliance (MX) operations
- ๐ Flattened Navigation:
meraki_navigateandmeraki_statusare stateless discovery aids โ every tool is callable at any time - ๐ Safety by Default: Read-only mode is ON by default; writes are gated and destructive actions require explicit confirmation
- ๐ผ๏ธ Interactive Device Card (MCP Apps):
meraki_devices_getrenders as a read-only interactive card in MCP Apps hosts (SEP-1865) โ neutral by default, brandable viawindow.__BRAND__injection orMCP_BRAND_*env vars - ๐งฐ Long-Tail Escape Hatch:
meraki_raw_requestreaches any Meraki v1 endpoint not covered by a curated tool - ๐ณ Docker Ready: Containerized deployment with HTTP transport and health checks
- ๐ Structured Logging: Configurable log levels
Installation
Option 1: Docker
docker run -d \
-e MERAKI_API_KEY=your-key \
-e MERAKI_ORG_ID=your-org-id \
-p 8080:8080 \
ghcr.io/wyre-ai/meraki-mcp:latest
Option 2: From Source
git clone https://github.com/WYRE-AI/meraki-mcp.git
cd meraki-mcp
npm ci
npm run build
Configuration
| Variable | Description | Default |
|---|---|---|
MERAKI_API_KEY |
Meraki Dashboard API key | โ |
MERAKI_ORG_ID |
Default organization ID (optional) | โ |
MERAKI_BASE_URL |
Override the Meraki API base URL (optional) | โ |
READ_ONLY_MODE |
Safety switch โ blocks all writes when true |
true |
MCP_TRANSPORT |
Transport mode (stdio or http) |
stdio |
MCP_HTTP_PORT |
HTTP server port | 8080 |
AUTH_MODE |
Auth mode (env or gateway) |
env |
LOG_LEVEL |
Log level (debug, info, warn, error) |
info |
The legacy
READ_ONLYvariable is also honored;READ_ONLY_MODEtakes precedence.
Safety Model
This server defaults to read-only. Write operations (updates, reboots, deletions) are blocked unless you explicitly set READ_ONLY_MODE=false.
- Read tools (
*_list,*_get) are always available. - High-impact writes (e.g.
meraki_networks_update,meraki_clients_update_policy) are gated by read-only mode. - Confirmation-gated tools additionally require a
confirm_destructive_action: trueargument, even onceREAD_ONLY_MODE=false. The confirmation flag is never forwarded to the Meraki API. Two groups qualify:- Irreversible โ
meraki_networks_delete,meraki_devices_remove. - High blast radius โ
meraki_appliance_firewall_l3_update,meraki_switch_ports_update,meraki_wireless_ssids_update,meraki_devices_reboot. These are reversible in principle, but each is applied over the same network link the change can break, so an operator can lose the connectivity needed to undo it.meraki_appliance_firewall_l3_updatealso replaces the rule set โ any rule not in the payload is deleted โ andmeraki_wireless_ssids_updatedrops every client on the SSID when the PSK or auth mode changes.
- Irreversible โ
- Confirmation is not an escape hatch from read-only mode: while
READ_ONLY_MODEis on, a confirmed call is still blocked. - The
meraki_raw_requestescape hatch classifies the call by HTTP method:GETis a read;POST/PUT/DELETEare writes;DELETEis destructive.
Domains
All tools are returned upfront. Use meraki_navigate to explore a domain's tools, or meraki_status to check connectivity and the configured organization.
| Domain | Tools |
|---|---|
| organizations | meraki_organizations_list, meraki_organizations_get, meraki_organizations_inventory_list |
| networks | meraki_networks_list, meraki_networks_get, meraki_networks_update โ , meraki_networks_delete โ โ |
| devices | meraki_devices_list, meraki_devices_get, meraki_devices_reboot โ โ , meraki_devices_remove โ โ |
| clients | meraki_clients_list, meraki_clients_get, meraki_clients_get_policy, meraki_clients_update_policy โ |
| wireless | meraki_wireless_ssids_list, meraki_wireless_ssids_update โ โ , meraki_wireless_rf_profiles_list |
| switch | meraki_switch_ports_list, meraki_switch_ports_update โ โ , meraki_switch_port_statuses_list |
| appliance | meraki_appliance_firewall_l3_get, meraki_appliance_firewall_l3_update โ โ , meraki_appliance_vpn_status_get |
| (long tail) | meraki_raw_request โ โ (on DELETE) |
โ = high-impact write, gated by read-only mode ยท โ โ = additionally requires confirm_destructive_action: true
Docker Deployment
Copy .env.example to .env and fill in your credentials:
cp .env.example .env
# Edit .env with your Meraki API key (and org ID)
docker run --env-file .env -p 8080:8080 ghcr.io/wyre-ai/meraki-mcp:latest
Development
npm ci
npm run build # Build the project
npm run start # Run over stdio
npm run start:http # Run the HTTP transport
npm run test # Run tests
Testing
npm test
The test suite covers the safety contract: read-only enforcement, destructive confirmation, and that confirm_destructive_action is never forwarded to the SDK.
License
Apache 2.0 โ Copyright WYRE Technology
Install
Add Cisco Meraki to your client. Pick the one you use.
claude mcp add ghcr-io-wyre-ai-meraki-mcp-v1-1-9 -- docker run -i --rm ghcr.io/wyre-ai/meraki-mcp:v1.1.9codex mcp add ghcr-io-wyre-ai-meraki-mcp-v1-1-9 -- docker run -i --rm ghcr.io/wyre-ai/meraki-mcp:v1.1.9amp mcp add ghcr-io-wyre-ai-meraki-mcp-v1-1-9 -- docker run -i --rm ghcr.io/wyre-ai/meraki-mcp:v1.1.9{
"mcpServers": {
"ghcr-io-wyre-ai-meraki-mcp-v1-1-9": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-ai/meraki-mcp:v1.1.9"
]
}
}
}Add to `claude_desktop_config.json`, then restart Claude Desktop.
{
"mcpServers": {
"ghcr-io-wyre-ai-meraki-mcp-v1-1-9": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-ai/meraki-mcp:v1.1.9"
]
}
}
}Add to `~/.cursor/mcp.json`, or `.cursor/mcp.json` for a single project.
code --add-mcp '{"name":"ghcr-io-wyre-ai-meraki-mcp-v1-1-9","command":"docker","args":["run","-i","--rm","ghcr.io/wyre-ai/meraki-mcp:v1.1.9"]}'Or add the block manually to `.vscode/mcp.json` under `servers`.
{
"mcpServers": {
"ghcr-io-wyre-ai-meraki-mcp-v1-1-9": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-ai/meraki-mcp:v1.1.9"
]
}
}
}Add to `~/.codeium/windsurf/mcp_config.json`.
{
"mcpServers": {
"ghcr-io-wyre-ai-meraki-mcp-v1-1-9": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-ai/meraki-mcp:v1.1.9"
]
}
}
}Add to `cline_mcp_settings.json` via the MCP Servers panel.
{
"mcpServers": {
"ghcr-io-wyre-ai-meraki-mcp-v1-1-9": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-ai/meraki-mcp:v1.1.9"
]
}
}
}Add to `~/.gemini/settings.json`.
{
"mcpServers": {
"ghcr-io-wyre-ai-meraki-mcp-v1-1-9": {
"type": "local",
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-ai/meraki-mcp:v1.1.9"
],
"tools": [
"*"
]
}
}
}Add to `~/.copilot/mcp-config.json`, or run `/mcp add` inside the CLI.
{
"context_servers": {
"ghcr-io-wyre-ai-meraki-mcp-v1-1-9": {
"command": {
"path": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/wyre-ai/meraki-mcp:v1.1.9"
]
}
}
}
}Add to your Zed `settings.json`.
docker run -i --rm ghcr.io/wyre-ai/meraki-mcp:v1.1.9Run `goose configure`, choose **Add Extension โ Command-line Extension**, and paste this command.
Score
39 / 100
Incomplete
- Documentation25/25
- Maintenance25/25
- Trust9/20
- Capability0/15
- Install experience12/15
- Documents what it does and how to connect
- Has a resolvable package or endpoint
- Exposes at least one tool, prompt or resource
- README has substantive content
- Includes a code example
- Documents its configuration
- Mentions credentials or security posture
- Last commit 1 days ago
- Has a release history
- Repository is not archived
- No licence detected
- Namespace verified in the official MCP registry
- Claimed by its owner
- Published under an organisation
- 0 tool(s) documented
- Provides prompt templates
- Provides resources
- 12 documented install method(s)
- Published to a package registry
- Offers a hosted endpoint โ no local install
Version history
| Versions | Published |
|---|---|
| 1.1.9Latest | Aug 29, 2026 |
| 1.1.8 | Aug 28, 2026 |
| 1.1.7 | Aug 28, 2026 |
| 1.0.0 | Aug 28, 2026 |
| 1.1.6 | Aug 26, 2026 |