Tool Manifest
Auto-generated by scripts/generate_tool_manifest.py. One row per registered tool, sorted alphabetically. Re-run the generator after changing any tool’s registration; the pre-commit hook enforces this.
Total tools: 129
| Tool | Summary |
|---|---|
audit_expiring_credentials |
Return credentials expiring within days_ahead days. |
audit_network_drift |
Compare current controller state to a declared YAML spec. |
audit_open_ports |
Audit WAN-facing exposure (port forwards and WAN_IN accept rules). |
backup_config |
Snapshot every persistent resource on the controller into one envelope. |
block_client |
Block a client by MAC so it cannot rejoin until unblocked. |
confirm_destructive_action |
Execute a queued destructive action by its preview token. |
create_dynamic_dns |
Create a Dynamic DNS update configuration. |
create_firewall_group |
Create a reusable firewall group of addresses, IPv6 addresses, or ports. |
create_firewall_rule |
Create a firewall rule on the controller. |
create_guest_network |
Provision an isolated guest network end-to-end: VLAN + guest SSID + drop rule. |
create_honeypot |
Add a honeypot trap to a network. |
create_iot_network |
Provision an isolated IoT network end-to-end: VLAN + SSID + drop rule. |
create_port_forward |
Create a port-forward (DNAT) rule on the WAN. |
create_port_profile |
Create a switch port profile. |
create_route |
Create a static next-hop route. |
create_static_dhcp_lease |
Reserve a fixed IP for a client by MAC. |
create_traffic_rule |
Create a v2 traffic rule from a full rule object. |
create_vlan |
Create a VLAN-tagged network on the controller. |
create_wlan |
Create a WiFi SSID bound to an existing network/VLAN. |
delete_content_filter |
Preview deletion of a content-filtering profile. |
delete_dynamic_dns |
Preview deletion of a Dynamic DNS config. |
delete_firewall_group |
Preview deletion of a firewall group. |
delete_firewall_rule |
Preview deletion of a firewall rule. |
delete_honeypot |
Preview deletion of a honeypot entry. |
delete_port_forward |
Preview deletion of a port-forward (DNAT) rule. |
delete_port_profile |
Preview deletion of a switch port profile. |
delete_route |
Preview deletion of a static route. |
delete_static_dhcp_lease |
Preview deletion of a static DHCP reservation. |
delete_vlan |
Preview deletion of a VLAN/network. |
delete_wlan |
Preview deletion of a WiFi SSID. |
get_access_device |
Fetch one Access device’s full record by ID. |
get_access_policy |
Fetch one access policy’s full record by ID. |
get_access_system_info |
Return controller version, license tier, and capacity. |
get_anomalies |
List client-impacting anomalies the controller has detected. |
get_camera |
Fetch a single camera’s full record by ID. |
get_client_sessions |
List recent client connection sessions over a time window. |
get_client_stats |
Report per-client traffic, signal, and uptime for one client by MAC. |
get_content_filter_details |
Show one content-filtering profile’s full record by _id. |
get_credential |
Fetch one credential’s full record by ID. |
get_device_radios |
Show per-radio RF settings for an access point. |
get_device_stats |
Report per-device stats for one UniFi device by MAC. |
get_door |
Fetch one door’s full record by ID. |
get_dynamic_dns_details |
Show one Dynamic DNS config’s full record by _id. |
get_event_thumbnail |
Fetch the JPEG thumbnail for a Protect event, base64-encoded. |
get_firewall_group_details |
Show one firewall group’s full record by _id. |
get_gateway_stats |
Report gateway resource stats: CPU, memory, temperature, throughput. |
get_network_details |
Show one network’s full record, grouped into readable sections. |
get_recent_access_events |
Return the most recent N events across every door. |
get_route_details |
Show one static route’s full record by _id. |
get_site_health |
Report per-subsystem health (wan, lan, wlan, www, vpn). |
get_snapshot |
Fetch a current JPEG snapshot from a camera, base64-encoded. |
get_speedtest_results |
List recent speed-test results, newest first. |
get_system_info |
Report controller/system info: version, uptime, device type. |
get_teleport_config |
Return Teleport VPN state and any wireguard-server networks. |
get_threat_management |
Return current Threat Management (IDS/IPS) configuration. |
get_traffic_route_details |
Show one traffic route’s full record by _id. |
get_traffic_rule_details |
Show one traffic rule’s full record by _id. |
get_visitor |
Fetch one visitor pass’s full record by ID. |
get_wan_ipv6 |
Show the current IPv6 configuration of the WAN uplink(s). |
get_wan_status |
Report current WAN status: link, ISP, public IP, throughput, latency. |
list_access_devices |
List hubs, readers, relays, and intercoms bonded to the controller. |
list_access_events |
List badge-scan / door events with filters. |
list_access_policies |
List every access policy on the controller. |
list_access_users |
List every user enrolled in the Access system. |
list_alarms |
List controller alarms, active or archived. |
list_ap_groups |
List access-point groups configured on the controller. |
list_cameras |
List every camera bonded to the Protect controller. |
list_clients |
List currently active wireless and wired clients. |
list_content_filters |
List DNS content-filtering profiles (category blocking, safe-search). |
list_credentials |
List every credential enrolled in the Access controller. |
list_devices |
List every UniFi device adopted by this controller. |
list_dhcp_leases |
List static DHCP reservations on the controller. |
list_door_groups |
List every door group defined on the controller. |
list_doorbell_messages |
List doorbell cameras (those with isDoorbell=True). |
list_doors |
List every door bonded to the Access controller. |
list_dynamic_dns |
List Dynamic DNS update configurations on the controller. |
list_events |
List recent controller events (connections, disconnections, etc.). |
list_failed_access_attempts |
Return only result == "denied" events within the window. |
list_firewall_groups |
List reusable firewall groups (address, IPv6-address, and port groups). |
list_firewall_rules |
List every firewall rule on the controller. |
list_honeypots |
List configured honeypots and the global honeypot toggle. |
list_motion_events |
List motion events in the last hours_back hours. |
list_networks |
List every network/VLAN configured on the controller. |
list_port_forwards |
List every port-forward (DNAT) rule on the controller. |
list_port_profiles |
List switch port profiles configured on the controller. |
list_recordings |
List Protect recordings for one camera over the last hours_back hours. |
list_routes |
List user-defined static (next-hop) routes on the controller. |
list_smart_detections |
List smart-detection events (person, vehicle, animal, package). |
list_top_talkers |
List top clients by total bytes (DPI by-station report). |
list_traffic_routes |
List v2 traffic routes (policy-based routing, e.g. VPN-client routes). |
list_traffic_rules |
List v2 traffic rules (app/domain/IP-based allow & block policies). |
list_visitors |
List every visitor pass on the controller (active and expired). |
list_wlans |
List every WiFi SSID configured on the controller. |
locate_device |
Toggle the LED locate beacon on a device. |
provision_camera |
Configure a camera end-to-end: recording mode + sensitivity + privacy. |
provision_homelab_service |
Stand up a homelab service: DHCP lease + firewall allow + (optional) port forwards. |
quarantine_client |
Block a client and log the quarantine action with a reason. |
reconnect_client |
Force a client to reconnect (kick-sta). |
rename_device |
Rename an adopted UniFi device (AP, switch, or gateway). |
restart_device |
Restart an adopted UniFi device (gateway, AP, or switch). |
restore_config |
Restore controller state from a backup_config envelope. |
set_camera_privacy_mode |
Toggle a camera’s privacy mask (lens cover) on or off. |
set_camera_recording_mode |
Set a camera’s recording mode (always, motion, or never). |
set_lan_ipv6 |
Set the IPv6 configuration of one LAN/VLAN network. |
set_motion_sensitivity |
Set a camera’s motion sensitivity (0-100). |
set_port_state |
Override settings on a single switch port. |
set_radio_channel |
Set the channel and/or channel width of one radio on an AP. |
set_radio_min_rssi |
Enable, tune, or disable minimum RSSI on one radio of an AP. |
set_radio_tx_power |
Set the transmit power mode of one radio on an access point. |
set_teleport_enabled |
Toggle the Teleport VPN listener. |
set_threat_management |
Update Threat Management (IDS/IPS) configuration. |
set_wan_ipv6 |
Set the WAN uplink’s IPv6 connection type and prefix delegation. |
summarize_access_activity |
Aggregate badge events by door, user, and outcome. |
toggle_traffic_route |
Enable or disable a traffic route without editing its other fields. |
toggle_traffic_rule |
Enable or disable a traffic rule without editing its other fields. |
trigger_speedtest |
Kick off a UniFi speed test on the WAN link. |
unblock_client |
Unblock a previously-blocked client by MAC. |
update_content_filter |
Patch fields on an existing content-filtering profile (read-modify-write). |
update_dynamic_dns |
Patch fields on an existing Dynamic DNS config. |
update_firewall_group |
Rename a firewall group or replace its members (read-modify-write). |
update_firewall_rule |
Patch fields on an existing firewall rule. |
update_port_forward |
Patch fields on an existing port-forward rule. |
update_port_profile |
Patch fields on an existing port profile. |
update_route |
Patch fields on an existing static route. |
update_static_dhcp_lease |
Convert or update an existing client to a fixed-IP reservation. |
update_traffic_route |
Patch fields on an existing traffic route (read-modify-write). |
update_traffic_rule |
Patch fields on an existing traffic rule (read-modify-write). |
update_vlan |
Patch fields on an existing VLAN/network record. |
update_wlan |
Patch fields on an existing WiFi SSID. |