Production adapter

Ubiquiti UniFi

Read UniFi sites, devices, clients, networks, and WLANs and run dual-gated writes (VLANs, port profile, PoE, WLAN PSK, client block) through one API. Production: reads live-validated on real UCG hardware.

Vendor: UbiquitiCategory: NetworkingProduction

Production: full gold-standard contract, with reads and device discovery live-validated on a real UCG Fiber across both the classic (v1) and modern (v2) API lanes.

The UniFi adapter manages Ubiquiti UniFi controller-managed switches, access points, and security gateways. It supports both the classic UniFi Network Application and UniFi OS consoles (UDM, UDM-Pro, Cloud Key Gen2+), auto-detecting the auth mode at init. It is Production: the gold-standard contract is enforced, and reads plus device discovery are live-validated on a real UCG Fiber (UniFi OS 5.1.19 / UniFi Network 10.4.57) across both the classic and modern (zone-based-firewall) API lanes.

What you can do

Ubiquiti UniFi capabilities

Classic and UniFi OS, auto-detected

Works against the classic Network Application on port 8443 and modern UniFi OS consoles (UDM, UDM-Pro, Cloud Key Gen2+) behind the network proxy, picking the right auth flow automatically.

Dual-gated, audit-logged writes

Every write requires read-only mode off and a per-call force flag, requires site-admin, and emits a structured audit line. WLAN PSKs are never logged.

Validated on real hardware

Reads and device discovery are live-validated on a real UCG Fiber (UniFi OS 5.1.19 / UniFi Network 10.4.57) across both the classic and modern API lanes. Writes are staged and dual-gated; VLAN/network create+delete is proven live with a persisted cassette, and the broader write surface is exercised live. Field reports remain welcome through GitHub Issues.

19 read methods, all redacting secrets on returnSites and site health, devices and port overridesClients, networks (VLANs, subnets, DHCP scopes), and WLANs (PSK stripped on read)Firewall rules and groups, port forwards, RADIUS and VPN clientsController info, sysinfo, and alertsDual-gated writes across VLANs/networks, WLANs/SSIDs, per-port PoE and port-override profiles, device restart/disable/locate, client block/unblock/forget/reconnect, firewall groups, RADIUS, and hotspot vouchersAuto-detects classic Network Application vs UniFi OS console auth
How it connects
  • Connects to the UniFi Network Application (classic, port 8443) or a UniFi OS console.
  • Authenticates with a controller username and password stored as an encrypted credential.
  • No dedicated UI yet: operators consume the REST endpoints directly (a UniFi UI is on the roadmap).
Tier
Production (live-validated on real UCG)
Category
Networking
Transport
UniFi Network / UniFi OS REST
Auth
Controller username + password (auto-detect)
Reads / Writes
Full read surface; dual-gated writes across VLANs, WLANs, PoE, clients, devices, firewall, RADIUS, and hotspot
UI
UniFi controller page + REST
Good to know
  • Reads and device discovery are live-validated on a real UCG Fiber, across both the classic (v1) and modern (v2) API lanes.
  • VLAN/network create+delete is proven live with a persisted cassette; the broader write surface (WLANs, PoE, clients, devices, firewall groups, RADIUS, hotspot vouchers) is staged + dual-gated and was exercised live but not yet persisted per domain.
  • Zone-based-firewall (v2) zone create/delete is implemented but unexercised on this non-ZBF-migrated controller.
Powers these modules

See it running in your browser

Explore the full FreeSDN dashboard with realistic sample data, no signup, no backend. Then install it in minutes.