plugins/unifi-access/skills/unifi-access/SKILL.md
How to manage UniFi Access door control — locks, credentials, visitors, access policies, and events. Use this skill when the user mentions UniFi Access, door locks, door access, building access, NFC cards, PIN codes, visitor passes, access policies, access schedules, door readers, or any UniFi Access task.
npx skillsauth add sirkirby/unifi-network-mcp unifi-accessInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
You have access to a UniFi Access MCP server that lets you query and manage a UniFi Access controller. It provides 34 tools covering doors, locks, credentials, visitors, access policies, events, devices, and system health.
The server uses lazy loading by default — only meta-tools are registered initially:
| Meta-Tool | Purpose |
|-----------|---------|
| access_tool_index | Discover tools by name/description; use category, search, or include_schemas to filter |
| access_execute | Call any tool by name (essential in lazy mode) |
| access_batch | Run multiple tools in parallel |
| access_batch_status | Check async batch job status |
Workflow: Call access_tool_index to find the right tool, then access_execute to call it. Use access_batch for multiple independent queries.
All mutations are disabled by default because Access controls physical door locks and building entry.
Read operations — always available. Listing doors, events, users, credentials — all work without permissions.
Mutations require explicit opt-in via env vars:
UNIFI_POLICY_ACCESS_DOORS_UPDATE=true — lock/unlock doorsUNIFI_POLICY_ACCESS_CREDENTIALS_CREATE=true — create NFC/PIN/mobile credentialsUNIFI_POLICY_ACCESS_CREDENTIALS_DELETE=true — revoke credentialsUNIFI_POLICY_ACCESS_VISITORS_CREATE=true — create visitor passesUNIFI_POLICY_ACCESS_VISITORS_DELETE=true — delete visitor passesUNIFI_POLICY_ACCESS_POLICIES_UPDATE=true — update access policiesUNIFI_POLICY_ACCESS_DEVICES_UPDATE=true — reboot devicesConfirmation flow — every mutation uses preview-then-confirm:
confirm=true → executes the mutationDoor lock/unlock operations are physical real-world actions — always preview first.
All tools return: {"success": true, "data": ...}, {"success": false, "error": "..."}, or {"success": true, "requires_confirmation": true, "preview": ...}. Always check success first.
Redacted secrets: Credential token and pin_code values come back as ***REDACTED*** by default in reads, lists, and create previews. Pass include_sensitive=true to a read tool only when the user genuinely needs the raw value. Never echo ***REDACTED*** back into a create/update — it is rejected so the placeholder can't be stored as a real credential.
access_lock_door / access_unlock_door — unlock relocks automatically after duration (default 2 seconds)access_recent_events reads from websocket buffer instantly. Event types: door_open, door_close, access_granted, access_denied, door_alarmaccess_list_events with time/door/user filters. Topics: admin or admin_activityaccess_get_activity_summary aggregates events over a time period — useful for security audits{user_id, token}), PIN ({user_id, pin_code}), or mobile ({user_id}) credentialsAccess has two independent auth paths:
Either can work independently. For full functionality, configure both. If mutations fail with auth errors, the user needs username+password (API key alone is not enough for write operations).
To configure, run /unifi-access:unifi-access-setup or set env vars manually:
UNIFI_ACCESS_HOST=192.168.1.1
UNIFI_ACCESS_API_KEY=your-api-key
UNIFI_ACCESS_USERNAME=admin
UNIFI_ACCESS_PASSWORD=your-password
If the user also has networking or cameras, other UniFi MCP plugins are available:
unifi-network — network devices, clients, firewall, VPN, routingunifi-protect — security cameras, NVR, recordings, smart detectionsAccess readers are network clients — if a reader appears offline, the Network server can help check connectivity via unifi_lookup_by_ip.
For the complete list of all 34 tools organized by category with descriptions, tips, and common scenarios, read references/access-tools.md.
tools
How to manage UniFi network infrastructure — devices, clients, firewall, VPN, routing, WLANs, Traffic Flows, and statistics. Use this skill when the user mentions UniFi, Ubiquiti, network management, WiFi configuration, firewall rules, port forwarding, VPN, QoS, bandwidth, traffic flows, connected clients, network devices, or any UniFi networking task.
tools
Configure the UniFi Protect MCP server for Claude Code, Codex, or OpenClaw — set NVR host, credentials, and permissions
tools
Configure the UniFi Network MCP server for Claude Code, Codex, or OpenClaw — set controller host, credentials, and permissions
tools
Configure the UniFi Access MCP server for Claude Code, Codex, or OpenClaw — set controller host, credentials, API key, and permissions