Configuration¶
| Variable | Default | Description |
|---|---|---|
ACS_URL |
http://localhost:7557 | GenieACS NBI endpoint (without trailing /) |
ACS_USER |
(empty) | GenieACS NBI basic-auth username |
ACS_PASS |
(empty) | GenieACS NBI basic-auth password |
TRANSPORT |
(empty = HTTP) | Set to stdio for stdio transport |
DEVICE_LIMIT |
500 | Max devices returned by genieacs://devices/list |
MCP_LISTEN_ADDR |
127.0.0.1:8080 | HTTP listen address (only used when TRANSPORT is not stdio) |
MCP_AUTH_TOKEN |
(empty) | Bearer token for HTTP transport auth. Required when MCP_LISTEN_ADDR is non-loopback |
MCP_ALLOWED_HOSTS |
(empty) | Comma-separated extra Host header values to accept (e.g. a reverse-proxy domain). Loopback names on the listen port are always allowed |
MCP_ALLOWED_ORIGINS |
(empty) | Comma-separated extra browser Origin values to accept (e.g. https://my-ai-app.com) |
Security — HTTP transport. The HTTP transport validates the
HostandOriginheaders on every request to prevent DNS rebinding from a malicious web page reaching a local listener. Requests with an untrustedHost, or a present-but-untrustedOrigin, are rejected with403. Loopback access works with no configuration; if you expose the server through a reverse proxy or a hostname, add that name toMCP_ALLOWED_HOSTS(andMCP_ALLOWED_ORIGINSfor browser clients). Thestdiotransport is unaffected and remains the recommended mode for local MCP clients.
There is no read-only mode. Ten of the twelve tools act on a device or change the ACS; the tool list is the same for every client, so approval prompts belong in the client.
Put them in a .env file (from .env.example) or set them in the environment.
Client configuration¶
Over stdio, which the npm package always uses, a client that reads an mcpServers block starts the
server itself:
{
"mcpServers": {
"genieacs": {
"command": "npx",
"args": ["-y", "genieacs-mcp"],
"env": { "ACS_URL": "http://localhost:7557" }
}
}
}
Add ACS_USER and ACS_PASS only if you put basic auth in front of the NBI; GenieACS itself ships the NBI
without authentication, and the admin / admin login of the web UI is not an NBI credential.
Over HTTP, for a server you already run (the Docker image, or the binary without TRANSPORT=stdio), a
client that supports remote servers connects to the /mcp endpoint. Drop headers if you did not set
MCP_AUTH_TOKEN: