MCP server for Juniper Networks device operations via junos-ops
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
English | ζ₯ζ¬θͺ
MCP (Model Context Protocol) server for junos-ops.
Exposes Juniper Networks device operations to MCP-compatible AI assistants (Claude Desktop, Claude Code, etc.) via STDIO transport. While junos-ops is the CLI tool for humans, junos-mcp is the AI-facing interface to the same powerful engine.
| Tool | Description | Connection |
|---|---|---|
get_device_facts | Get basic device information (model, hostname, serial, version) | Yes |
get_version | Get JUNOS version with upgrade status | Yes |
get_router_list | List routers from config.ini (optionally filtered by tags) | No |
health_check | Report server version + config status (router count, distinct tags). Lightweight; does NOT connect to any device | No |
| Tool | Description | Connection |
|---|---|---|
run_show_command | Run a single CLI show command (output_format: text/json/xml) | Yes |
run_show_commands | Run multiple CLI commands in a single session (output_format: text/json/xml) | Yes |
run_show_command_batch | Run a command on multiple devices in parallel (supports tag filter and grep_pattern) | Yes |
| Tool | Description | Connection |
|---|---|---|
get_config | Get device configuration (text/set/xml format) | Yes |
get_config_diff | Show config diff against a rollback version | Yes |
push_config | Push config with commit confirmed + health check | Yes |
| Tool | Description | Connection |
|---|---|---|
check_upgrade_readiness | Check if device is ready for upgrade | Yes |
compare_version | Compare two JUNOS version strings | No |
get_package_info | Get model-specific package file and hash | No |
list_remote_files | List files on remote device path | Yes |
copy_package | Copy firmware package via SCP with checksum | Yes |
install_package | Install firmware with pre-flight checks (unlink flag for EX2300/EX3400) | Yes |
rollback_package | Rollback to previous package version | Yes |
schedule_reboot | Schedule device reboot at specified time | Yes |
| Tool | Description | Connection |
|---|---|---|
collect_rsi | Collect RSI/SCF with model-specific timeouts | Yes |
collect_rsi_batch | Collect RSI/SCF from multiple devices in parallel (supports tag filter) | Yes |
Equivalent to the junos-ops check subcommand modes. All three reuse the
junos-ops display layer for table rendering.
| Tool | Description | Connection |
|---|---|---|
check_reachability | Probe NETCONF reachability + available disk space per host (fast: no facts, 5s TCP probe) | Yes |
check_local_inventory | Verify local firmware checksums against config.ini inventory | No |
check_remote_packages | Verify staged firmware checksum + available disk space on devices (post-SCP verification) | Yes |
| Tool | Description | Connection |
|---|---|---|
daily_brief | Morning health check across multiple devices in parallel β alarms, interface up/down, syslog alert patterns within a look-back window (since_hours, default 18 h), dual-RE faults ([RE_FAULT]; skipped on SRX chassis clusters, whose facts misreport RE status β a failed cluster node surfaces via chassis alarms instead), and an optional inet.0 route-count baseline (route_baseline, e.g. tags=["main"], route_baseline=152). Returns a CRITICAL/WARNING/OK Markdown summary. | Yes |
All destructive operations (push_config, copy_package, install_package,
rollback_package, schedule_reboot) default to dry-run mode (dry_run=True).
The AI assistant must explicitly set dry_run=False to make changes.
push_config provides additional safety features not found in other Junos MCP servers:
no_commit=True β issues commit confirmed but intentionally skips the final commit.
JUNOS auto-rolls back after confirm_timeout minutes. Useful for restarting services that
lack a request ...restart command (e.g. syslog daemon on EX3400 post-upgrade).config.iniOr for development:
| Option | Description |
|---|---|
-V, --version | Print version and exit |
--check | Load config.ini, list routers, and exit (exit code 1 on error) |
--check-host HOSTNAME | With --check, also open a NETCONF session to verify reachability/auth |
--transport {stdio,streamable-http} | Transport protocol (default: stdio) |
--check is handy to verify JUNOS_OPS_CONFIG and config.ini are reachable before registering the server with an AI assistant. Combine with --check-host rt1 to also confirm that credentials actually authenticate against a real device.
run_show_command_batch, collect_rsi_batch, and get_router_list accept an optional tags argument. The grammar matches the junos-ops --tags CLI flag (since junos-mcp 0.9.0 / junos-ops 0.16.6):
hostnames on batch tools, the result is the intersection (tags filter further narrowed by names). An empty intersection returns an error.See the junos-ops tag documentation for how to tag sections in config.ini and for the matching CLI grammar.
run_show_command and run_show_commands accept an optional output_format parameter:
| Value | Description |
|---|---|
"text" | Default. Plain-text CLI output (same as typing the command) |
"json" | NETCONF JSON output β device returns a structured dict |
"xml" | NETCONF XML output β device returns pretty-printed XML |
Note: CLI pipe stages (| match, | last, | count, etc.) are silently dropped
regardless of output_format. PyEZ's Device.cli() sends the command over NETCONF
RPC, which JunOS does not pipe-process. Run the command without pipes and filter
client-side instead. For a single command, run_show_command_batch's grep_pattern
argument (see below) offers server-side-style filtering β even against a single
host, by passing a one-element hostnames list β but it always fetches plain-text
output internally (it cannot be combined with output_format="json"/"xml"), and
it only accepts one command at a time, so it isn't a drop-in workaround for
run_show_commands' multi-command case.
run_show_command_batch accepts an optional grep_pattern argument (Python re pattern). When set, only lines matching the pattern are kept from each host's output. Header lines (starting with #) are always preserved. Hosts with no matching lines show (no match).
This reduces large batch results β for example, 93 routers Γ show route summary β from hundreds of KB to a few hundred bytes by extracting just the relevant lines:
junos-mcp maintains a per-host NETCONF connection pool. Reusing an idle
Device avoids the TCP/NETCONF handshake on every tool call; the pool
serialises concurrent operations on the same host through a per-host lock.
| Environment variable | Default | Description |
|---|---|---|
JUNOS_MCP_POOL | 1 (enabled) | Set to 0 to disable the pool and open a fresh connection per call |
JUNOS_MCP_POOL_IDLE | 60 | Idle timeout in seconds. Connections unused longer than this are closed on the next call. Set to 0 to disable eviction |
Security note: pooled connections are long-lived SSH sessions. In
environments where session duration is restricted by policy, set
JUNOS_MCP_POOL_IDLE to a value shorter than the inactivity limit, or set
JUNOS_MCP_POOL=0 to disable the pool entirely.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/junos-mcp)<a href="https://allmcps.com/mcp/junos-mcp"><img src="https://allmcps.com/api/badge/junos-mcp?style=directory" alt="Junos MCP on AllMCPs" /></a>