The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Genieacs MCP listing page.
A tiny bridge that exposes any GenieACS instance as an MCP v1 (JSON-RPC for LLMs) server written in Go.
| Type | What for | MCP URI / Tool id |
|---|---|---|
| Resources | Consume GenieACS data read-only | genieacs://device/{id}genieacs://file/{name}genieacs://tasks/{id}genieacs://devices/listgenieacs://presets/listgenieacs://provisions/listgenieacs://faults/{id} |
| Tools | Invoke actions on a CPE through GenieACS | reboot_devicedownload_firmwarerefresh_parameterset_parameterget_parametermanage_presetmanage_provisionsearch_devicestag_deviceconnection_requestdelete_taskretry_task |
Everything is exposed over a single JSON-RPC endpoint (/mcp).
LLMs / Agents can: initialize → readResource → listTools → callTool … and so on.
Follow instructions from https://github.com/GeiserX/genieacs-container, it is included in the docker compose file there.
Or install globally:
This downloads the pre-built Go binary for your platform and runs it with stdio transport, compatible with any MCP client.
| Variable | Default | Description |
|---|---|---|
ACS_URL | http://localhost:7557 | GenieACS NBI endpoint (without trailing /) |
ACS_USER | (empty) | GenieACS NBI basic-auth username |
ACS_PASS | (empty) | GenieACS NBI basic-auth password |
TRANSPORT | (empty = HTTP) | Set to stdio for stdio transport |
DEVICE_LIMIT | 500 | Max devices returned by genieacs://devices/list |
MCP_LISTEN_ADDR | 127.0.0.1:8080 | HTTP listen address (only used when TRANSPORT is not stdio) |
MCP_AUTH_TOKEN | (empty) | Bearer token for HTTP transport auth. Required when MCP_LISTEN_ADDR is non-loopback |
MCP_ALLOWED_HOSTS | (empty) | Comma-separated extra Host header values to accept (e.g. a reverse-proxy domain). Loopback names on the listen port are always allowed |
MCP_ALLOWED_ORIGINS | (empty) | Comma-separated extra browser Origin values to accept (e.g. https://my-ai-app.com) |
Security — HTTP transport. The HTTP transport validates the
HostandOriginheaders on every request to prevent DNS rebinding from a malicious web page reaching a local listener. Requests with an untrustedHost, or a present-but-untrustedOrigin, are rejected with403. Loopback access works with no configuration; if you expose the server through a reverse proxy or a hostname, add that name toMCP_ALLOWED_HOSTS(andMCP_ALLOWED_ORIGINSfor browser clients). Thestdiotransport is unaffected and remains the recommended mode for local MCP clients.
Put them in a .env file (from .env.example) or set them in the environment.
Tested with Inspector and it is currently fully working. Before making a PR, make sure this MCP server behaves well via this medium.
Lacks Testing with actual MCP clients (client LLMs), so please, submit your PRs to improve descriptions in case it fails to adequately match the services offered by this MCP server.
GenieACS – the best open-source ACS
MCP-GO – modern MCP implementation
GoReleaser – painless multi-arch releases
Feel free to dive in! Open an issue or submit PRs.
GenieACS-MCP follows the Contributor Covenant Code of Conduct.
This project is part of a broader set of tools for working with GenieACS:
| Project | Type | Description |
|---|---|---|
| genieacs-docker | Docker + Helm | Production-ready multi-arch Docker image and Helm chart |
| genieacs-ansible | Ansible Collection | Dynamic inventory plugin and device management modules |
| genieacs-ha | HA Integration | Home Assistant integration for TR-069 monitoring |
| n8n-nodes-genieacs | n8n Node | Workflow automation for GenieACS |
| genieacs-services | Service Defs | Systemd/Supervisord service definitions |
| genieacs-sim-container | Simulator | Docker-based GenieACS simulator for testing |