hpe-networking-mcp

hpe-networking-mcp

Low-token MCP server for HPE Networking automation, enabling search of Aruba/HPE docs, OpenAPI details, Central health checks, troubleshooting workflows, configuration management, and guarded ArubaOS 8 migrations and GreenLake Platform operations across platforms like Aruba Central, ClearPass, Mist, and Apstra.

Category
Visit Server

README

hpe-networking-mcp — HPE Networking MCP toolkit

License Python MCP CI Docs Release

hpe-networking-mcp banner showing 6,144 generated operations, 6,715 backend tools, 3 minimal router tools, and nine platform surfaces with embedded RAG

The banner tracks the current backend catalog: a large tool surface stays available on demand, while the MCP client itself only ever sees three router tools by default.

Low-token Model Context Protocol (MCP) server for HPE Networking automation: Aruba Central, HPE GreenLake Platform (GLP), ClearPass, Juniper Mist, Apstra, ArubaOS 8 migration automation, EdgeConnect, HPE Aruba UXI, and Axis Atmos Cloud.

hpe-networking-mcp gives MCP-capable AI clients a low-token way to search Aruba/HPE docs, look up exact OpenAPI details, inspect Central health, run troubleshooting workflows, manage configuration, execute guarded ArubaOS 8 migrations, and use guarded GreenLake Platform operations. It is built around direct REST calls with httpx.

For the full visual walkthrough of this same information — audience picker, diagrams, and write-safety flow — see the hpe-networking-mcp GitHub Pages site. This README stays intentionally short; canonical guides live under docs/.

Who it's for

You are... Start with
A first-time MCP user The five-minute credential-free quickstart below, then Getting started
An Aruba network operator Example prompts and typed product workflows
An hpe-networking-mcp developer Architecture overview and Contributing guide

Five-minute credential-free quickstart

Verify the install, build the router catalog, and start the MCP HTTP server before adding any Aruba Central or GreenLake Platform credentials:

git clone https://github.com/secure-ssid/hpe-networking-mcp.git
cd hpe-networking-mcp
python3 scripts/setup_wizard.py --yes --skip-credentials
uv run hpe-mcp-doctor
MCP_PORT=8010 bash scripts/run_http_router.sh

Expected outcomes:

  • The wizard prints each completed phase and ends with a setup-complete summary; no Central/GLP calls are made.
  • doctor.py reports local dependency, config-path, and index checks — everything reads OK or lists what to fix, without calling any vendor API.
  • The HTTP router prints a Uvicorn running on http://127.0.0.1:8010 line and keeps running in the foreground.

<figure> <img src="docs/assets/diagrams/quickstart-journey.svg" alt="Six steps from cloning hpe-networking-mcp through setup, doctor checks, MCP connection, tool discovery, and a safe read-only call"> </figure>

The same six steps this diagram shows — clone, run the wizard, check the doctor, connect, discover, and call safely — are exactly what the commands above walk through.

Connect any MCP-capable client to http://127.0.0.1:8010/mcp, then try a credential-free discovery call:

find_tool("ask Aruba docs with citations")
invoke_read_tool("ask_docs", {"question": "WPA3 SAE transition mode", "top_k": 5})

Expected outcome: a short, cited answer from the embedded docs index — this call only reaches the local RAG index, never Central or GLP.

Write safety at a glance

  • find_tool only searches the local tool catalog; it never calls a vendor API.
  • invoke_read_tool blocks any backend tool that is not annotated read-only.
  • invoke_tool is deliberately marked destructive because it can also dispatch write/destructive backend tools — use it only when a write is intended.
  • Use dry_run=True first when supported; real execution then requires either confirm=True or MCP elicitation, depending on the tool schema.
  • HPE_MCP_ACCESS_PROFILE=custom preserves the current per-platform behavior; use safe-read-only to block every write or full-read-write to enable ordinary writes on every loaded platform.
  • Full read/write mode does not bypass dry-run, confirmation, elicitation, or dedicated safeguards such as the separate AOS8 rollback gate.
  • Credentials stay in config/credentials.yaml or environment variables and are never committed.

See Tool router for the complete discovery/dispatch/write-safety model.

Project snapshot

Area Current snapshot
Tool catalog Non-additive profiles: 368 core tools / 2829 read-only optional starters / 5809 read-write optional starters; platform API backend total: 6,703; complete backend index: 6,715; direct-all: 6,722
RAG 96,256 prose chunks; 4,106 endpoints, 8,890 schemas, 50,675 fields, 104 advisories, 346 lifecycle records
Optional platforms ClearPass, Mist, Apstra, AOS8, EdgeConnect, UXI, Axis Atmos Cloud
Safety Per-platform write gates, dry-run + confirmation, HTTP host/origin and bearer controls, credential-gated live-test config

Full per-backend counts live in Tool catalog. See the 0.8.0 release notes for everything added in the current release, and the capability gap matrix for reproducible tool/benchmark comparisons.

Why the router matters

Point your MCP client at one server: src/hpe_networking_mcp/mcp_servers/tool_router.py. The recommended minimal profile keeps the client-visible tool list at three entries while still reaching the full backend catalog:

  1. find_tool — discover the right backend tool.
  2. invoke_read_tool — dispatch read-only calls.
  3. invoke_tool — dispatch intentional write/destructive calls only.

Task-oriented guides

Need Guide
Full setup, credentials, and MCP client connection Getting started
Copy/paste stdio or streamable HTTP client config MCP client recipes
Router modes, toolsets, and safe dispatch in depth Tool router
Real prompts with expected call shapes Example prompts
Enable ClearPass, Mist, Apstra, AOS8, EdgeConnect, UXI, or Axis Optional product starters
Typed product-specific workflow roadmap Product workflows
Fix setup, credential, HTTP, or catalog issues Troubleshooting
Architecture, data flow, and safety diagrams System overview
Every backend's tool counts and coverage Tool catalog
The complete task-based visual gateway hpe-networking-mcp GitHub Pages
Every documentation page, grouped by purpose docs/README.md
Migrating from secure-ssid/centralmcp MIGRATION.md
Contribute, get support, or report a security issue CONTRIBUTING.md, SUPPORT.md, SECURITY.md
Version history CHANGELOG.md

Local setup essentials

The default MCP client profile stays lean:

HPE_MCP_ROUTER_MODE=minimal
HPE_MCP_TOOLSETS=central,glp,rag

Enable optional products only when needed:

HPE_MCP_ACCESS_PROFILE=custom
HPE_MCP_PRODUCTS=clearpass,mist,apstra,aos8,edgeconnect,uxi,axis,design
HPE_MCP_PRODUCT_ACCESS=read-only

For a trusted, fully write-capable session, use python3 scripts/setup_wizard.py --access-profile full-read-write so all legacy gates are aligned, or use the self-contained examples/mcp-clients/stdio/full-read-write.mcp.json.

.claude/launch.json ships a matching minimal hpe-networking-mcp launch profile for daily use. find_tool omits full JSON schemas by default; request include_schema=true only when a client needs the full parameter shape.

Build or refresh the router tool index, and download the prebuilt RAG/OpenAPI indexes instead of scraping locally:

uv run python scripts/ingest_tools.py --products all
uv run python scripts/download_indexes.py

See Getting started for credentials, region selection, optional-product env vars, and the full ingestion/refresh path.

Streamable HTTP mode

MCP_PORT=8010 bash scripts/run_http_router.sh

Then point any MCP-capable client at http://127.0.0.1:8010/mcp. The server also exposes /livez, /readyz, and /healthz. Non-loopback binds require explicit MCP_ALLOWED_HOSTS/MCP_ALLOWED_ORIGINS and can be protected with MCP_HTTP_BEARER_TOKEN. See MCP client recipes for copy/paste stdio and HTTP configs.

Project layout

src/hpe_networking_mcp/mcp_servers/     Low-token router + Central/GLP/RAG/optional-product servers
src/hpe_networking_mcp/pipeline/        httpx clients, 8-stage migration pipeline, SSID helpers
ingestion/       Docs/API scraping and LanceDB + SQLite index builders
docs/            Setup, router, architecture, product, and release guides
scripts/         Setup wizard, doctor wrapper, HTTP router helper, release validation
tests/           Unit, integration, and RAG eval coverage
config/          Credentials template; real credentials stay git-ignored
examples/        Tested, non-secret MCP client/prompt/runbook configuration examples
run_pipeline.py  Checkout wrapper for `hpe-mcp-run-pipeline`
run_ssid.py      Checkout wrapper for `hpe-mcp-run-ssid`

The full repository map, including generated/git-ignored paths, lives in System overview.

Validation

uv run pytest tests/unit -q
uv run python scripts/validate_release.py --catalog-products all --strict-rag --strict-tool-index --min-tools 6703

--min-tools 6703 is the platform API compatibility floor (the 6,703 vendor-facing platform API tools), not the complete registered backend total of 6,715 — validation passes at or above the floor. See Tool catalog for both totals.

The release helper runs unit tests, optional RAG/API eval when indexes exist, tool catalog floor checks, and local tool-index freshness checks. Unit tests also include static guards for the active MCP/pipeline code, committed low-token MCP config examples, local-only config files, router product/toolset docs, bounded generic read-only GET tools, MCP list default bounds, RAG/search top_k bounds, public tool-count claims, tool-count docstrings, rendered RAG/index doc-fact claims, tracked Markdown local links and images, Pages sitemap and robots metadata, documented router example arguments, product workflow tool-name tables, and wizard optional-product env tables.

Related projects and thanks

hpe-networking-mcp is an independent HPE Networking MCP toolkit, improved by watching the official MCP ecosystem and community work:

Disclaimer

hpe-networking-mcp is an independent community project. It is not an official HPE or HPE Aruba Networking product and is not endorsed by or supported by HPE.

License

MIT - see the repository license. Generated API metadata and upstream implementation references are documented in THIRD_PARTY_NOTICES.md.

Recommended Servers

playwright-mcp

playwright-mcp

A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.

Official
Featured
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.

Official
Featured
Local
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.

Official
Featured
Local
TypeScript
VeyraX MCP

VeyraX MCP

Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.

Official
Featured
Local
graphlit-mcp-server

graphlit-mcp-server

The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.

Official
Featured
TypeScript
Kagi MCP Server

Kagi MCP Server

An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.

Official
Featured
Python
E2B

E2B

Using MCP to run code via e2b.

Official
Featured
Neon Database

Neon Database

MCP server for interacting with Neon Management API and databases

Official
Featured
Exa Search

Exa Search

A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.

Official
Featured
Qdrant Server

Qdrant Server

This repository is an example of how to create a MCP server for Qdrant, a vector search engine.

Official
Featured