UniFi Protect MCP demonstrates strong definition quality with comprehensive tool coverage (22 tools), well-structured parameter schemas using proper JSON Schema types, and detailed descriptions that explain purpose, prerequisites, and limitations. Tool naming follows verb_noun conventions consistently (protect_list_*, protect_create_*, protect_update_*, protect_delete_*, protect_get_*, protect_enable_*, protect_disable_*). Most parameters include type declarations and descriptions. However, several tools lack complete output schema documentation, and some parameter descriptions could be more explicit about constraints and error conditions. Error handling guidance is minimal across most tools. The server demonstrates awareness of security concerns (dryRun patterns, irreversible operation confirmation) but lacks comprehensive audit trail and permission-gate patterns.
Control a relay output. Set state to "on"/"off" to set explicitly, or omit to toggle. When state is "on", pulseDuration auto-turns off after the given milliseconds.
Create a new arm profile. Only available when using local alarm manager.
Create an RTSPS stream session for a camera
Create a talkback (two-way audio) session for a camera. Returns: url, codec, samplingRate, bitsPerSample (the audio config for encoding outbound audio).
Delete an arm profile by ID. Only available when using local alarm manager.
Stop and delete an active RTSPS stream session for a camera
Output schemas not documented in tool descriptions. Tools return complex objects (e.g., arm profiles with automations[], schedules[], timestamps) but descriptions do not specify return fields, types, or structure. LLMs cannot plan downstream tool calls without knowing what fields to extract.
Limited error recovery guidance. Most tools lack descriptions of failure modes, recovery steps, or what the LLM should do if a call fails. E.g., protect_update_camera says 'Partial camera settings to update' but does not document which fields are valid, what constraints apply, or what happens if an invalid field is passed.
Parameter constraints not fully explicit in descriptions. Many numeric/enum parameters lack concrete examples or constraint documentation in descriptions. E.g., activationDelay enum values (0|60000|300000|600000) are stated but not explained as ms durations; status values (CONNECTED/DISCONNECTED) are mentioned but not documented as exhaustive.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 72 | 2025-06-18+ | v2 |
| 2026-03-09 | D | 54 | - | v1 |
Disable the arm alarm. Only available when using local alarm manager.
IRREVERSIBLE: Permanently disable the microphone on a camera. Can only be re-enabled by factory resetting the camera.
Enable the arm alarm using the currently selected arm profile. Only available when using local alarm manager.
Get details for a specific camera by ID. The Protect Integration API returns the SAME field set as protect_list_cameras entries (id, mac, name, modelKey, state, type, guid, activePatrolSlot, hasPackageCamera, hdrType, isMicEnabled, micVolume, videoMode, featureFlags, lcdMessage, ledSettings, osdSettings, smartDetectSettings) — there is no extended/by-id-only payload (confirmed live on 7.3.47). Recording state, motion events, zones, and channel/RTSP config are NOT exposed by this API surface.
Get active RTSPS stream sessions for a camera. Returns the per-quality stream URLs currently published (keys typically: high, medium, low, package). Empty/missing keys mean no session is currently active at that quality — use protect_create_rtsp_stream to start one.
Get a JPEG snapshot from a camera. Returns a base64-encoded image/jpeg (rendered directly by MCP clients). Use highQuality=true for full-resolution capture; set channel=package to capture from the secondary package camera on doorbells with hasPackageCamera=true.
List all arm profiles (only available when using the local alarm manager — the standalone NVR alarm system, not Protect cloud alerts). Returns array; each profile (7.1.83 docs): id, name, automations[], creator, schedules[], recordEverything, activationDelay (0 | 60000 | 300000 | 600000), createdAt, updatedAt.
List all cameras managed by UniFi Protect. Returns array; each camera includes (Integration API 7.3.47-verified fields): id, mac, name, modelKey, state (CONNECTED/DISCONNECTED), type (hardware model name, e.g. UVC G6 Turret), guid (hardware MODEL GUID — every camera of the same model returns the same value, so it is NOT a per-camera identifier; use id), activePatrolSlot, hasPackageCamera, hdrType, isMicEnabled, micVolume, videoMode, featureFlags (hasHdr, hasMic, hasSpeaker, hasLedStatus, smartDetectTypes[], smartDetectAudioTypes[], videoModes[], supportFullHdSnapshot), lcdMessage (type, resetAt, text), ledSettings (isEnabled, floodLed, welcomeLed), osdSettings (isNameEnabled, isDateEnabled, isLogoEnabled, isDebugEnabled, overlayLocation), smartDetectSettings (objectTypes[], audioTypes[]). The Integration API does NOT expose recording state, motion timestamps, connection/last-seen, firmware, host, or per-channel stream config.
Activate the siren alarm for a duration. Tracks status and can be stopped early.
Set the current arm profile to be used when enabling the arm alarm. Only available when using local alarm manager.
Stop an active siren
Test the siren sound for 5 seconds at the specified volume
Test the speaker sound at the specified volume
Trigger an alarm hub output channel. Used to turn on/off connected sirens, lights, or other actuators.
Update an existing arm profile (partial update via PATCH). Only available when using local alarm manager.
Update camera settings (partial update via PATCH)
Inconsistent parameter naming conventions. Some tools use descriptive field names (e.g., dryRun as boolean) but parameter consistency across similar tools is not validated. E.g., some tools have outputId (number), others have similar but differently-named params. This can confuse LLMs when composing related calls.
No explicit pagination support documented for list operations. protect_list_cameras and protect_list_arm_profiles return arrays without documented limit/offset parameters or total count fields. If a user has hundreds of cameras, the entire list is returned, risking context window overflow.
Scope/permission declarations absent. Tools perform sensitive operations (disable_mic, delete_arm_profile, trigger_alarm) but do not declare required permissions. Cannot implement least-privilege agent configs or audit which tools require what access.
Irreversible operations lack comprehensive confirmation patterns. protect_disable_mic includes a confirm parameter, but protect_delete_arm_profile and protect_delete_rtsp_stream only support dryRun boolean, not a require-explicit-confirmation pattern. No guidance on how to prevent accidental calls.