Tool Manifest
Auto-generated by scripts/generate_tool_manifest.py. One row per registered tool, sorted alphabetically. Re-run the generator after changing any tool’s registration; the pre-commit hook enforces this.
Total tools: 129
| Tool | Summary |
|---|---|
audit_expiring_credentials | Return credentials expiring within days_ahead days. |
audit_network_drift | Compare current controller state to a declared YAML spec. |
audit_open_ports | Audit WAN-facing exposure (port forwards and WAN_IN accept rules). |
backup_config | Snapshot every persistent resource on the controller into one envelope. |
block_client | Block a client by MAC so it cannot rejoin until unblocked. |
confirm_destructive_action | Execute a queued destructive action by its preview token. |
create_dynamic_dns | Create a Dynamic DNS update configuration. |
create_firewall_group | Create a reusable firewall group of addresses, IPv6 addresses, or ports. |
create_firewall_rule | Create a firewall rule on the controller. |
create_guest_network | Provision an isolated guest network end-to-end: VLAN + guest SSID + drop rule. |
create_honeypot | Add a honeypot trap to a network. |
create_iot_network | Provision an isolated IoT network end-to-end: VLAN + SSID + drop rule. |
create_port_forward | Create a port-forward (DNAT) rule on the WAN. |
create_port_profile | Create a switch port profile. |
create_route | Create a static next-hop route. |
create_static_dhcp_lease | Reserve a fixed IP for a client by MAC. |
create_traffic_rule | Create a v2 traffic rule from a full rule object. |
create_vlan | Create a VLAN-tagged network on the controller. |
create_wlan | Create a WiFi SSID bound to an existing network/VLAN. |
delete_content_filter | Preview deletion of a content-filtering profile. |
delete_dynamic_dns | Preview deletion of a Dynamic DNS config. |
delete_firewall_group | Preview deletion of a firewall group. |
delete_firewall_rule | Preview deletion of a firewall rule. |
delete_honeypot | Preview deletion of a honeypot entry. |
delete_port_forward | Preview deletion of a port-forward (DNAT) rule. |
delete_port_profile | Preview deletion of a switch port profile. |
delete_route | Preview deletion of a static route. |
delete_static_dhcp_lease | Preview deletion of a static DHCP reservation. |
delete_vlan | Preview deletion of a VLAN/network. |
delete_wlan | Preview deletion of a WiFi SSID. |
get_access_device | Fetch one Access device’s full record by ID. |
get_access_policy | Fetch one access policy’s full record by ID. |
get_access_system_info | Return controller version, license tier, and capacity. |
get_anomalies | List client-impacting anomalies the controller has detected. |
get_camera | Fetch a single camera’s full record by ID. |
get_client_sessions | List recent client connection sessions over a time window. |
get_client_stats | Report per-client traffic, signal, and uptime for one client by MAC. |
get_content_filter_details | Show one content-filtering profile’s full record by _id. |
get_credential | Fetch one credential’s full record by ID. |
get_device_radios | Show per-radio RF settings for an access point. |
get_device_stats | Report per-device stats for one UniFi device by MAC. |
get_door | Fetch one door’s full record by ID. |
get_dynamic_dns_details | Show one Dynamic DNS config’s full record by _id. |
get_event_thumbnail | Fetch the JPEG thumbnail for a Protect event, base64-encoded. |
get_firewall_group_details | Show one firewall group’s full record by _id. |
get_gateway_stats | Report gateway resource stats: CPU, memory, temperature, throughput. |
get_network_details | Show one network’s full record, grouped into readable sections. |
get_recent_access_events | Return the most recent N events across every door. |
get_route_details | Show one static route’s full record by _id. |
get_site_health | Report per-subsystem health (wan, lan, wlan, www, vpn). |
get_snapshot | Fetch a current JPEG snapshot from a camera, base64-encoded. |
get_speedtest_results | List recent speed-test results, newest first. |
get_system_info | Report controller/system info: version, uptime, device type. |
get_teleport_config | Return Teleport VPN state and any wireguard-server networks. |
get_threat_management | Return current Threat Management (IDS/IPS) configuration. |
get_traffic_route_details | Show one traffic route’s full record by _id. |
get_traffic_rule_details | Show one traffic rule’s full record by _id. |
get_visitor | Fetch one visitor pass’s full record by ID. |
get_wan_ipv6 | Show the current IPv6 configuration of the WAN uplink(s). |
get_wan_status | Report current WAN status: link, ISP, public IP, throughput, latency. |
list_access_devices | List hubs, readers, relays, and intercoms bonded to the controller. |
list_access_events | List badge-scan / door events with filters. |
list_access_policies | List every access policy on the controller. |
list_access_users | List every user enrolled in the Access system. |
list_alarms | List controller alarms, active or archived. |
list_ap_groups | List access-point groups configured on the controller. |
list_cameras | List every camera bonded to the Protect controller. |
list_clients | List currently active wireless and wired clients. |
list_content_filters | List DNS content-filtering profiles (category blocking, safe-search). |
list_credentials | List every credential enrolled in the Access controller. |
list_devices | List every UniFi device adopted by this controller. |
list_dhcp_leases | List static DHCP reservations on the controller. |
list_door_groups | List every door group defined on the controller. |
list_doorbell_messages | List doorbell cameras (those with isDoorbell=True). |
list_doors | List every door bonded to the Access controller. |
list_dynamic_dns | List Dynamic DNS update configurations on the controller. |
list_events | List recent controller events (connections, disconnections, etc.). |
list_failed_access_attempts | Return only result == "denied" events within the window. |
list_firewall_groups | List reusable firewall groups (address, IPv6-address, and port groups). |
list_firewall_rules | List every firewall rule on the controller. |
list_honeypots | List configured honeypots and the global honeypot toggle. |
list_motion_events | List motion events in the last hours_back hours. |
list_networks | List every network/VLAN configured on the controller. |
list_port_forwards | List every port-forward (DNAT) rule on the controller. |
list_port_profiles | List switch port profiles configured on the controller. |
list_recordings | List Protect recordings for one camera over the last hours_back hours. |
list_routes | List user-defined static (next-hop) routes on the controller. |
list_smart_detections | List smart-detection events (person, vehicle, animal, package). |
list_top_talkers | List top clients by total bytes (DPI by-station report). |
list_traffic_routes | List v2 traffic routes (policy-based routing, e.g. VPN-client routes). |
list_traffic_rules | List v2 traffic rules (app/domain/IP-based allow & block policies). |
list_visitors | List every visitor pass on the controller (active and expired). |
list_wlans | List every WiFi SSID configured on the controller. |
locate_device | Toggle the LED locate beacon on a device. |
provision_camera | Configure a camera end-to-end: recording mode + sensitivity + privacy. |
provision_homelab_service | Stand up a homelab service: DHCP lease + firewall allow + (optional) port forwards. |
quarantine_client | Block a client and log the quarantine action with a reason. |
reconnect_client | Force a client to reconnect (kick-sta). |
rename_device | Rename an adopted UniFi device (AP, switch, or gateway). |
restart_device | Restart an adopted UniFi device (gateway, AP, or switch). |
restore_config | Restore controller state from a backup_config envelope. |
set_camera_privacy_mode | Toggle a camera’s privacy mask (lens cover) on or off. |
set_camera_recording_mode | Set a camera’s recording mode (always, motion, or never). |
set_lan_ipv6 | Set the IPv6 configuration of one LAN/VLAN network. |
set_motion_sensitivity | Set a camera’s motion sensitivity (0-100). |
set_port_state | Override settings on a single switch port. |
set_radio_channel | Set the channel and/or channel width of one radio on an AP. |
set_radio_min_rssi | Enable, tune, or disable minimum RSSI on one radio of an AP. |
set_radio_tx_power | Set the transmit power mode of one radio on an access point. |
set_teleport_enabled | Toggle the Teleport VPN listener. |
set_threat_management | Update Threat Management (IDS/IPS) configuration. |
set_wan_ipv6 | Set the WAN uplink’s IPv6 connection type and prefix delegation. |
summarize_access_activity | Aggregate badge events by door, user, and outcome. |
toggle_traffic_route | Enable or disable a traffic route without editing its other fields. |
toggle_traffic_rule | Enable or disable a traffic rule without editing its other fields. |
trigger_speedtest | Kick off a UniFi speed test on the WAN link. |
unblock_client | Unblock a previously-blocked client by MAC. |
update_content_filter | Patch fields on an existing content-filtering profile (read-modify-write). |
update_dynamic_dns | Patch fields on an existing Dynamic DNS config. |
update_firewall_group | Rename a firewall group or replace its members (read-modify-write). |
update_firewall_rule | Patch fields on an existing firewall rule. |
update_port_forward | Patch fields on an existing port-forward rule. |
update_port_profile | Patch fields on an existing port profile. |
update_route | Patch fields on an existing static route. |
update_static_dhcp_lease | Convert or update an existing client to a fixed-IP reservation. |
update_traffic_route | Patch fields on an existing traffic route (read-modify-write). |
update_traffic_rule | Patch fields on an existing traffic rule (read-modify-write). |
update_vlan | Patch fields on an existing VLAN/network record. |
update_wlan | Patch fields on an existing WiFi SSID. |