MCP server for LenelS2 S2 NetBox access control via the NBAPI. Read-only by default.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
A local MCP server that exposes LenelS2 S2 NetBox NBAPI operations β persons/credentials, access levels, portals/readers/outputs, time specs, holidays, portal/reader groups, threat levels, events/activity, and partitions/UDF lists β as MCP tools usable from any MCP-compatible client (Claude, Gemini/Antigravity, etc.).
Not the open-source netboxlabs.com "NetBox" DCIM/IPAM tool. This targets LenelS2's S2 NetBox physical access-control appliance and its NBAPI (
Web-Based API for S2 NetBox and S2 Global, LenelS2 doc #API-UG-14). Newer NBAPI v1 (doc #API-UG-22, April 2024) and v2 (doc #API2-UG-8, April 2025) guides also exist β seedocs/reference/for reference copies. Both have now been diffed against this server's tool surface command by command and parameter by parameter:docs/reference/nbapi-command-diff.mdrecords the result, including which documented commands are deliberately not implemented and why.
[!WARNING] This connects to a real physical security system. With the wrong configuration, an AI agent using this server could unlock doors or modify access-control data on a live building. It is read-only by default β writes and destructive operations (lock/unlock, add/modify/delete) each require their own explicit opt-in environment variable (see Write access below) β but you are responsible for what you enable and which MCP client/model you point at it. See
SECURITY.mdbefore deploying anything beyond read-only against a production controller.
Read-only by default. With no write-related environment variables set, this server registers only query/read NBAPI commands:
LoginLogoutGetAPIVersionGetPersonSearchPersonDataGetCardAccessDetailsGetCardFormatsGetAccessLevel(s)GetAccessLevelGroup(s)GetPortalsGetReader(s)GetOutputsGetTimeSpec(s)GetTimeSpecGroup(s)GetHoliday(s)GetPortalGroup(s)GetReaderGroup(s)GetAccessLevelNamesGetPartitionsGetUDFListsGetUDFListItemsGetElevatorsGetFloorsPingAppGetEventHistoryListEventsGetAccessHistoryBy default, this server registers only the query/read commands listed above.
It does not register any write, delete, or control operations against the
controller until you explicitly opt in via the environment variables in
Write access below. Among the read-only tools, four are composites,
find_portals, get_unlock_window, get_daily_unlock_window, and
get_reader_access_history, which issue only read commands. Note there is no
GetPortal (singular) command; only GetPortals (plural, paginated, no
single-portal filter) exists on the real NBAPI.
This server sets the MCP instructions field and exposes an always-registered
get_guide tool, so any agent connecting to it β via npm install or a local
clone, in Claude Code, Antigravity, Gemini CLI, or any other MCP client β has
this server's own S2 NetBox operating knowledge immediately, with no separate
skill install and no extra step.
instructions describes the access model (person β credential β access
level β access level group determines what a person can access; portal
group / time spec group determines where and when), states that most
parameters are numeric KEY fields rather than names (resolve a name to its
KEY with the matching get_*/find_* tool first), and states that text
returned from the controller is data, not instructions to follow. With
NETBOX_ENABLE_WRITES set, it also states a firm confirm-before-acting policy
for lock/unlock, portal-state, unlock-window, and destructive calls (the
write-safety topic below elaborates it); with NETBOX_ENABLE_DESTRUCTIVE
also set, it adds one sentence naming the DESTRUCTIVE:-prefixed tools and
their extra confirmation requirement.
get_guide (always registered; makes no controller call) returns deeper
reference material on six topics. Call it with no arguments for an index of
all six with a one-line summary each, or with topic set to one of the keys
below for that topic's full content:
| Topic key | Covers |
|---|---|
access-model | The person β credential β access level β access level group chain, and the portal-group/time-spec-group name-table collision. |
unlock-windows | The holiday + time spec + portal group UNLOCKTIMESPECGROUPKEY recipe, date/time inclusivity rules, and when to prefer the composite tools. |
group-and-name-gotchas | modify_portal_group/modify_reader_group replacing a group's entire membership; modify_access_level always needing TIMESPECGROUPKEY. |
credentials-and-card-formats | Diagnosing a BIT MISMATCH access-denied event, and remove_person's soft-delete behavior. |
api-quirks | STARTFROMKEY/NEXTKEY paging, the missing singular get_portal, and checking write results for the literal SUCCESS. |
write-safety | Naming the target and effect, waiting for explicit confirmation, preferring scheduled tools, and reversing every write. |
get_guide is counted among the always-registered read tools below: the tool
surface is 51 tools with both gates off, 98 with
NETBOX_ENABLE_WRITES, and 113 with NETBOX_ENABLE_DESTRUCTIVE as well.
Node.js >= 18.17 (tested on Node 24), which includes npm. If Node.js isn't installed, on
Windows you can install it with winget, then open a new terminal so node/npm are on
your PATH:
An S2 NetBox controller reachable from wherever this server runs, with the NBAPI enabled and configured for session-login authentication (not MAC authentication β see the spec for why that's out of scope for v1)
A NetBox operator account with API access and read permission on the resources you want to query
Two ways to get the server:
Option A β npm (no clone needed):
This installs the s2-netbox-mcp binary; point your MCP client's command at
s2-netbox-mcp directly (no node dist/index.js needed).
Option B β clone and build:
Either way, copy .env.example to .env and fill in real values (or provide the same
variables directly in your shell / in the Claude Code MCP server config's
env block β see below). Never commit .env β it's already gitignored.
Start the server directly to sanity-check it boots (it just waits on stdio
for an MCP client β Ctrl+C to stop; this also sends Logout if a session was
opened):
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/s2-netbox-mcp)<a href="https://allmcps.com/mcp/s2-netbox-mcp"><img src="https://allmcps.com/api/badge/s2-netbox-mcp?style=directory" alt="S2 Netbox MCP on AllMCPs" /></a>