New Your team’s decisions, in one playbook every coding agent works from. Never answer your agent twice

API-Central

590 tools. 220 can modify or destroy data without limits.

42 destructive tools with no built-in limits. Policy required.

Last updated:

220 can modify or destroy data
370 read-only
590 tools total

Community server · catalogue entry checked 14/08/2026

How to control API-Central ↓

What API-Central exposes to your agents

Read (370) Write / Execute (178) Destructive / Financial (42)
Critical Risk

The most dangerous API-Central tools

220 of API-Central's 590 tools can modify, destroy, or commit something on every call — and an agent calls them with no built-in limits.

How to control API-Central

PolicyLayer is an MCP gateway — it sits between your AI agents and API-Central, and nothing reaches the server without passing your rules. These are the rules we recommend:

Deny destructive operations
{
  "aos8_execute_migration_rollback": {
    "deny_if": [
      {
        "conditions": [],
        "on_deny": "Blocked by default. Requires approval."
      }
    ]
  }
}

Destructive tools should never be available to autonomous agents without human approval.

Rate limit write operations
{
  "acknowledge_alert": {
    "limits": [
      {
        "counter": "acknowledge_alert_per_hour",
        "window": "hour",
        "max": 30,
        "scope": "grant"
      }
    ]
  }
}

Prevents bulk unintended modifications from agents caught in loops.

Cap read operations
{
  "aos_s_arp": {
    "limits": [
      {
        "counter": "aos_s_arp_per_minute",
        "window": "minute",
        "max": 60,
        "scope": "grant"
      }
    ]
  }
}

Controls API costs and prevents retry loops from exhausting upstream rate limits.

  1. Create a free account and register API-Central — nothing to install.
  2. Add these rules — paste them, or build them visually. Tune the limits to your setup.
  3. Point your MCP client (Claude, Cursor, anything) at your gateway URL.
ENFORCE POLICY ON API-CENTRAL →

Instant setup, no code required.

All 590 API-Central tools

DESTRUCTIVE 42 tools
Destructive aos8_execute_migration_rollback aos8_execute_migration_rollback Destructive aos8_logout Log out of AOS8/Mobility Conductor and clear the cached session, if any. Destructive apstra_delete_connectivity_template Delete one Apstra connectivity template by ID. Destructive clear_alerts Clear one or more alerts by key. Returns the Central async task payload. Destructive clearpass_delete_endpoint Delete a ClearPass endpoint by MAC address. Destructive clearpass_delete_guest Delete a ClearPass guest account by username or ID. Destructive delete_aaa_profile Delete an AAA profile by name. Destructive delete_auth_profile Delete a Central NAC authentication profile by UUID. Destructive delete_auth_server Delete a RADIUS/auth server profile by name. Destructive delete_authz_policy Delete a CNAC authz policy by ID. Destructive delete_config_assignment delete_config_assignment Destructive delete_device_groups Bulk-delete device groups by scope ID list. Destructive delete_device_notes Clear notes on a device by serial number (sets notes to an empty string). Destructive delete_glp_role_assignment Delete an RBAC role assignment by ID. Destructive delete_glp_scope_group Delete an RBAC scope group by ID. Destructive delete_glp_scope_group_scopes delete_glp_scope_group_scopes Destructive delete_gw_policy Delete a GW security policy by name. Destructive delete_mac_registration Delete a MAC registration by ID. Destructive delete_mpsk_registration Delete a Named MPSK registration by ID. Destructive delete_network_profile Delete a network-config library profile by name. See get_network_profile for profile_type. Destructive delete_notification_rule Delete a notification rule by ID. UNCONFIRMED endpoint shape — see module note above. Destructive delete_overlay_ssid delete_overlay_ssid Destructive delete_report delete_report Destructive delete_report_run delete_report_run Destructive delete_role delete_role Destructive delete_role_acl Delete a role ACL policy by name. Must precede delete_role. Destructive delete_server_group Delete an auth server group by name. Destructive delete_site_collections_bulk delete_site_collections_bulk Destructive delete_sites_bulk delete_sites_bulk Destructive delete_static_tag Delete a static classification tag by UUID. Destructive delete_underlay_ssid Delete an underlay SSID and its scope-map. Destructive delete_visitor Delete a visitor account by ID. Destructive delete_vsf_template delete_vsf_template Destructive delete_webhook Delete a webhook by ID. Destructive disassociate_glp_user Remove (disassociate) a user from the GLP workspace. Destructive edgeconnect_delete_address_group Delete an EdgeConnect ACL address group by name with write guards. Destructive edgeconnect_delete_service_group Delete an EdgeConnect ACL service group by name with write guards. Destructive gateway_halt Halt an Aruba gateway (POST .../halt). Requires elicited confirmation — this stops Destructive glp_archive_device glp_archive_device Destructive mist_delete_wlan Delete one Mist site WLAN. Destructive uxi_delete_agent Delete/decommission a UXI agent by ID; requires read-write access. Destructive uxi_delete_group Delete a UXI group by ID; requires read-write access.
EXECUTE 48 tools
Execute aos_s_ping Ping a destination from an AOS-S switch (async, polls ~60s). Execute aos_s_traceroute Run a traceroute from an AOS-S switch (async, polls ~60s). Execute aos8_apply_migration_run aos8_apply_migration_run Execute aos8_create_migration_run aos8_create_migration_run Execute aos8_migration_batch_plan aos8_migration_batch_plan Execute aos8_plan_migration_rollback aos8_plan_migration_rollback Execute aos8_show_command Run a read-only AOS8 show ... command through the showcommand API. Execute ap_http Test an HTTP GET from an AP's perspective (async, polls ~60s). timeout: 1-10s. Execute ap_https Test an HTTPS GET from an AP's perspective (async, polls ~60s). timeout: 1-10s. Execute ap_nslookup Resolve a hostname from an AP's perspective (async, polls ~60s). Execute ap_ping Ping a destination from an AP and return the result (async, polls ~60s). Execute ap_show Run 'show' commands on an AP (all must start with 'show ', max 20, async polls ~60s). Execute ap_tcp Test TCP connectivity to host:port from an AP (async, polls ~60s). timeout: 1-10s. Execute ap_traceroute Run a traceroute from an AP (async, polls ~60s). Execute apstra_wait_for_task Poll an Apstra blueprint task until it reaches a terminal state. Execute build_bgp_overlay build_bgp_overlay Execute build_ospf_overlay build_ospf_overlay Execute build_underlay_ssid build_underlay_ssid Execute build_vsf_template build_vsf_template Execute cable_test Run a cable/TDR test on CX or AOS-S switch ports (async, polls ~60s). Execute clearpass_disconnect_session Disconnect an active ClearPass session via Change of Authorization. Execute cx_ping Ping a destination from a CX switch and return the result (async, polls ~60s). Execute cx_show Run 'show' commands on a CX switch (all must start with 'show ', max 20, async polls ~60s). Execute cx_traceroute Run a traceroute from a CX switch (async, polls ~60s). Execute disconnect_client Force-disconnect a wireless client by MAC address. ap_serial auto-looked up if omitted. Execute edgeconnect_run_link_integrity_test Start an EdgeConnect link-integrity iperf/tcpperf test with write guards. Execute execute_config_health_remediation execute_config_health_remediation Execute gateway_iperf Run an iperf throughput test from an Aruba gateway (async, polls ~60s). Execute gateway_ping_sweep Run a ping sweep (a range of packet sizes) from an Aruba gateway (async, polls ~60s). Execute gateway_show Run 'show' commands on an Aruba gateway via async troubleshooting API. Each must start with 'show '. Execute invoke_tool invoke_tool Execute locate_aos_s_switch Blink an AOS-S switch's locate LED (POST .../locate). Execute locate_ap Blink an AP's locate LED (POST .../locate). Non-disruptive — no confirmation required. Execute locate_cx_switch Blink a CX switch's locate LED (POST .../locate). Execute poe_bounce Power-cycle PoE on switch/gateway ports (async, polls ~60s). Execute port_bounce Link-reset (bounce) switch/gateway ports (async, polls ~60s). Execute reboot_ap_swarm Reboot an entire AP swarm/cluster via one member's serial (POST .../rebootSwarm). Execute reboot_device Reboot an AP, CX switch, AOS-S switch, or gateway. device_type auto-detected if omitted. Execute resync_device_config resync_device_config Execute run_firmware_compliance_campaign run_firmware_compliance_campaign Execute run_glp_backup_protection_job run_glp_backup_protection_job Execute run_speed_test Run a speed test from an AP to measure uplink bandwidth. Execute run_troubleshooting_bundle run_troubleshooting_bundle Execute set_firmware_compliance Create or update a firmware compliance policy (triggers upgrade). Execute set_glp_virtual_machine_power set_glp_virtual_machine_power Execute set_glp_virtual_machines_power_bulk set_glp_virtual_machines_power_bulk Execute test_aaa Test AAA connectivity from an AP or CX switch (async, polls ~60s). Execute trigger_device_upgrade trigger_device_upgrade
WRITE 130 tools
Write acknowledge_alert Acknowledge, clear, or resolve an active alert. action: ACK/CLEAR/RESOLVE. Write add_devices_to_group Add devices to an existing device group by scope ID. Write add_glp_scope_group_scopes Add scopes to an existing RBAC scope group. Write add_mac_registration Register a MAC address for Central NAC. mac_address e.g. 'aa:bb:cc:dd:ee:ff'. Write add_mpsk_registration Create a Named MPSK registration. network = SSID; password_policy default "WORDS". Write add_visitor Create a Central NAC visitor account. name=login username; expire_at ISO 8601. Write aos8_export_all aos8_export_all Write aos8_login aos8_login Write aos8_manage_ap_group Create, update, or delete an AOS8 AP group; requires write memory. Write aos8_manage_ssid_profile Create, update, or delete an AOS8 SSID profile; requires write memory. Write aos8_manage_user_role Create, update, or delete an AOS8 user role; requires write memory. Write aos8_manage_virtual_ap Create, update, or delete an AOS8 virtual AP profile; requires write memory. Write aos8_manage_vlan Create, update, or delete an AOS8 VLAN; requires write memory. Write aos8_migration_dependency_plan aos8_migration_dependency_plan Write aos8_migration_plan aos8_migration_plan Write aos8_write aos8_write Write aos8_write_memory Persist staged AOS8 configuration for a hierarchy node. Write apstra_create_connectivity_template Guarded create/update for one Apstra connectivity template. Write apstra_login apstra_login Write apstra_set_application_point_assignment apstra_set_application_point_assignment Write apstra_write apstra_write Write assign_device_to_site Assign or move a device to a site. device_type hint: SWITCH/AP/GATEWAY. Write build_config_checkpoint_policy build_config_checkpoint_policy Write build_overlay_ssid build_overlay_ssid Write build_vrf_overlay Create a LOCAL-scoped VRF bound to scope_id + device_function. Write clearpass_create_guest Create a ClearPass guest account. Write clearpass_set_guest_enabled Enable or disable a ClearPass guest account by username or ID. Write clearpass_set_service_enabled Enable or disable a ClearPass authentication service by name. Write clearpass_update_endpoint_attributes Patch ClearPass endpoint attributes by MAC for lab workflows. Write clearpass_write Perform a lab write request to ClearPass with a preview-first guard. Write configure_application_experience configure_application_experience Write configure_high_availability configure_high_availability Write create_aaa_dot1xauth_profile create_aaa_dot1xauth_profile Write create_aaa_macauth_profile create_aaa_macauth_profile Write create_aaa_profile create_aaa_profile Write create_allow_all_role Create a permit-all wireless role and scope-map it. Write create_auth_server create_auth_server Write create_authz_policy create_authz_policy Write create_config_assignment create_config_assignment Write create_device_group Create a device group, optionally pre-populated with device serial numbers. Write create_dot1x_auth_profile create_dot1x_auth_profile Write create_glp_role_assignment create_glp_role_assignment Write create_glp_scope_group create_glp_scope_group Write create_gw_cluster Create an empty gateway cluster profile shell (add members via gateway_join_cluster). Write create_gw_policy create_gw_policy Write create_mac_auth_profile create_mac_auth_profile Write create_notification_rule create_notification_rule Write create_port_profile Create or update a switch port profile and scope-map it. Write create_report create_report Write create_role create_role Write create_server_group create_server_group Write create_site Create a new site (mandatory geographic scope). Only name is required; name must be unique. Write create_static_tag Create a static classification tag (UUID auto-generated). Used in authz policies to assign roles. Write create_vlan Create an L2 VLAN and scope-map it (org-wide if scope_id omitted). Write create_vlan_interface Create an L3 SVI at device scope (global L2 VLAN shell is auto-confirmed). Write create_webhook create_webhook Write defer_alerts Defer one or more alerts until an absolute ISO-8601 timestamp. Write edgeconnect_acknowledge_alarm edgeconnect_acknowledge_alarm Write edgeconnect_apply_interface_labels Push active EdgeConnect interface labels to one appliance with write guards. Write edgeconnect_clear_alarm Clear a GMS-level EdgeConnect alarm. Write edgeconnect_save_changes Persist pending EdgeConnect appliance configuration changes with write guards. Write edgeconnect_set_address_group Create/update or replace an EdgeConnect ACL address group with write guards. Write edgeconnect_set_appliance_network_role_site Update EdgeConnect appliance network role and site assignment with write guards. Write edgeconnect_set_bypass_mode Enable or disable EdgeConnect bypass mode on appliances with write guards. Write edgeconnect_set_interface_labels Replace EdgeConnect interface labels with write guards. Write edgeconnect_set_maintenance_mode Configure EdgeConnect appliance maintenance mode with write guards. Write edgeconnect_set_next_zone_id Set the next available EdgeConnect firewall-zone ID with write guards. Write edgeconnect_set_route_labels Create or update EdgeConnect route labels with write guards. Write edgeconnect_set_service_group Create/update or replace an EdgeConnect ACL service group with write guards. Write edgeconnect_set_services Replace EdgeConnect overlay internet services with write guards. Write edgeconnect_set_zone_firewall_status Enable or disable EdgeConnect End-to-End Zone-Based Firewall with write guards. Write edgeconnect_set_zones Replace EdgeConnect firewall zones with write guards. Write edgeconnect_write Perform a lab write request to EdgeConnect with a preview-first guard. Write enable_telemetry Create a LOCAL-scoped telemetry profile (streaming/export destinations) Write export_graphviz_topology export_graphviz_topology Write export_next_ui_topology export_next_ui_topology Write gateway_config_interface PATCH ethernet interface config on an Aruba gateway at device scope. Write gateway_config_static_route Create or replace a static route on an Aruba gateway at device scope. Write gateway_join_cluster Add/update gateway cluster membership (POST to create, PATCH if duplicate). Write glp_add_device Add a device to the GLP workspace (async task, polls until complete, ~5min max). Write glp_add_devices_bulk Bulk add devices to GLP. devices: dicts with 'serialNumber' and 'macAddress'. Write glp_add_subscriptions glp_add_subscriptions Write glp_assign_subscription glp_assign_subscription Write group_glp_devices Group GLP devices by a documented v2beta1 attribute. Write invite_glp_user Invite a user to the GLP workspace by email. Write mist_ack_alarm Acknowledge one Mist site alarm. Write mist_claim_devices mist_claim_devices Write mist_set_marvis_settings mist_set_marvis_settings Write mist_unack_alarm Unacknowledge one Mist site alarm. Write mist_upsert_user_mac mist_upsert_user_mac Write mist_write Perform a lab write request to Mist with a preview-first guard. Write plan_config_health_remediation plan_config_health_remediation Write plan_glp_reconciliation plan_glp_reconciliation Write plan_reconciliation_schedule plan_reconciliation_schedule Write plan_tool_workflow plan_tool_workflow Write push_aruba_device_profiles Ensure the four standard Aruba LLDP device profiles exist at library level (idempotent). Write reactivate_alerts Reactivate cleared or deferred alerts by key. Write remove_devices_from_group Remove devices from their current device group. Write resolve_diagram_icon Resolve the best local diagram icon path for a vendor + role pair. Write rotate_webhook_key Rotate the HMAC key for a webhook. Write set_alert_priority Set operator priority for one or more alerts. Write set_hostname Set the hostname alias on a device. Write set_network_profile set_network_profile Write set_notification_rule_enabled Enable or disable a notification rule by ID. Write set_port_auth PATCH a sw-port-profile to bind mac-auth / dot1x / server-group / role. Write update_device_notes Set free-text notes on a device by serial number (max 256 chars). Write update_device_settings Update device metadata (name, location, notes, banner). device_scope_id required for switch-system path. Write update_glp_auto_subscription_settings update_glp_auto_subscription_settings Write update_glp_role_assignment update_glp_role_assignment Write update_glp_scope_group Update an RBAC scope group by ID. Write update_glp_user_preferences Update a GLP user's preferences (idle timeout, language). Write update_glp_workspace_contact PATCH the contact record for a GLP workspace. Write update_mac_registration Update an existing MAC registration. mac_address required even for updates. Write update_mpsk_registration Update an existing Named MPSK registration. registration_id (the record's id) is required. Write update_notification_rule Update a notification rule by ID (alert-config). Write update_port_config PATCH ethernet interface config on a CX switch at device scope. Write update_report update_report Write update_role PUT-update an existing wireless role in the Central Library. target: see create_role. Write update_ssid PATCH an existing SSID — only provided fields change. scope_id for LOCAL override. Write update_visitor Update an existing visitor account. visitor_id (the record's id) is required. Write update_webhook PATCH an existing webhook — only provided fields are changed. Write uxi_assign_agent_to_group Assign a UXI agent to a group; requires read-write access. Write uxi_assign_network_to_group Assign a UXI wired/wireless network to a group; requires read-write access. Write uxi_assign_sensor_to_group Assign a UXI sensor to a group; requires read-write access. Write uxi_assign_service_test_to_group Assign a UXI service test to a group; requires read-write access. Write uxi_create_group Create a UXI group; requires CENTRALMCP_PRODUCT_ACCESS=read-write. Write uxi_update_agent Patch a UXI agent's editable fields (e.g. notes) by ID. Write uxi_update_group Update a UXI group's name by ID; requires read-write access. Write uxi_update_sensor Patch a UXI sensor's editable fields (e.g. notes, addressNote) by ID. Write uxi_write uxi_write
READ 370 tools
Read aos_s_arp Get the ARP table from an AOS-S switch (async, polls ~60s). Read aos_s_show Run 'show' commands on an AOS-S switch (all must start with 'show ', async polls ~60s). Read aos8_export_wlans Export AOS8 WLANs as merged SSID-profile + virtual-AP records for migration planning. Read aos8_find_client Find one AOS8 client by MAC, IP, or username from show user-table. Read aos8_get Perform a read-only GET request to ArubaOS 8 API. Read aos8_get_alarms List active AOS8 alarms from show alarms. Read aos8_get_ap_arm_history Get AOS8 Adaptive Radio Management history for AP/radio troubleshooting. Read aos8_get_ap_monitor_stats Get AOS8 AP monitor statistics for RF/debug investigations. Read aos8_get_ap_wired_ports Get wired-port status for one AP from show ap port status ap-name. Read aos8_get_audit_trail Get AOS8 controller-wide audit trail from show audit-trail. Read aos8_get_client_detail Get verbose AOS8 client detail from show user-table verbose mac. Read aos8_get_client_history Get AOS8 AP association history for a client MAC. Read aos8_get_cluster_state Get AOS8 LC-cluster membership and failover state. Read aos8_get_events Get recent AOS8 events from show events. Read aos8_get_ipsec_tunnels Get site-to-site and Remote AP IPsec tunnel state. Read aos8_get_md_hierarchy Get Mobility Conductor hierarchy from show configuration node-hierarchy. Read aos8_get_migration_run Get bounded candidate state, results, and verification for one migration run. Read aos8_get_policies aos8_get_policies Read aos8_get_radio_summary Get AOS8 AP radio summary from show ap radio-summary. Read aos8_get_rf_neighbors Get ARM RF neighbors for an AP by name. Read aos8_get_system_logs Get recent AOS8 system log entries with a capped show-command count. Read aos8_get_version Get AOS8 Mobility Conductor software version from show version. Read aos8_get_vlans List VLAN configuration objects at an AOS8 hierarchy node. Read aos8_list_active_aps List active AOS8 APs from show ap active with bounded output. Read aos8_list_ap_groups List AP-group configuration objects at an AOS8 hierarchy node. Read aos8_list_aps List AOS8 AP inventory from show ap database with bounded output. Read aos8_list_bss List AOS8 BSS table entries from show ap bss-table. Read aos8_list_clients List AOS8 clients from show user-table with bounded output. Read aos8_list_controllers List AOS8 Mobility Conductor controllers from show switches. Read aos8_list_licenses List AOS8 Mobility Conductor licenses from show license. Read aos8_list_migration_runs List bounded migration-run summaries, reporting malformed state without crashing. Read aos8_list_ssid_profiles List SSID profile configuration objects at an AOS8 hierarchy node. Read aos8_list_user_roles List user-role configuration objects at an AOS8 hierarchy node. Read aos8_list_virtual_aps aos8_list_virtual_aps Read aos8_preview_migration_run aos8_preview_migration_run Read aos8_status Report whether the AOS8 backend is configured and the current session state. Read aos8_verify_migration_run Read target objects and record bounded identity/field verification comparisons. Read apstra_get apstra_get Read apstra_get_connectivity_template Get one Apstra connectivity template by ID with compact fields. Read apstra_get_diff_status Get compact staging-vs-active diff status for one Apstra blueprint. Read apstra_get_system_info Get compact system/device information for one Apstra blueprint. Read apstra_get_task Get one Apstra asynchronous blueprint task. Read apstra_list_anomalies List anomalies for one Apstra blueprint with compact health fields. Read apstra_list_application_endpoints List interfaces that can receive connectivity-template assignments. Read apstra_list_blueprints List Apstra blueprints with compact ID/name/status fields. Read apstra_list_connectivity_templates List connectivity templates visible in one Apstra blueprint. Read apstra_list_protocol_sessions List protocol sessions in one Apstra blueprint with compact status fields. Read apstra_list_racks List racks in one Apstra blueprint with compact topology fields. Read apstra_list_remote_gateways List remote EVPN gateways in one Apstra blueprint with compact fields. Read apstra_list_routing_zones List routing/security zones in one Apstra blueprint with compact fields. Read apstra_list_templates List Apstra design templates available for blueprint creation. Read apstra_list_virtual_networks List virtual networks in one Apstra blueprint with compact bindings. Read apstra_status apstra_status Read ask_docs ask_docs Read central_get central_get Read check_product_lifecycle check_product_lifecycle Read clearpass_find_guest Find ClearPass guest accounts by username, email, visitor_name, or name. Read clearpass_get Perform a read-only GET request to ClearPass REST API. Read clearpass_get_access_tracker_session Get one ClearPass Access Tracker session by ID. Read clearpass_get_endpoint_by_mac Look up one ClearPass endpoint by MAC address. Read clearpass_get_enforcement_policy Get one ClearPass enforcement policy by name. Read clearpass_get_insight_endpoint Get documented ClearPass Insight endpoint data by MAC address. Read clearpass_get_network_device Get a ClearPass network device (NAD) by name or numeric ID. Read clearpass_get_onguard_activity_by_mac Get documented ClearPass OnGuard activity for one endpoint MAC. Read clearpass_get_server_version Get the ClearPass server version. Read clearpass_get_service Get one ClearPass authentication service by name. Read clearpass_list_access_tracker_sessions clearpass_list_access_tracker_sessions Read clearpass_list_auth_failures List recent ClearPass authentication failures. Read clearpass_list_cluster_servers List ClearPass cluster server nodes with bounded pagination. Read clearpass_list_endpoints List ClearPass endpoints with optional status filter and bounded pagination. Read clearpass_list_enforcement_policies List ClearPass enforcement policies with bounded pagination. Read clearpass_list_guests List ClearPass guest accounts with bounded pagination. Read clearpass_list_onguard_activity List documented ClearPass OnGuard activity records. Read clearpass_list_roles List ClearPass roles with bounded pagination. Read clearpass_list_services List ClearPass authentication services with bounded pagination. Read clearpass_list_syslog_export_filters List ClearPass syslog export filters with bounded pagination. Read clearpass_list_syslog_targets List ClearPass syslog targets with bounded pagination. Read clearpass_status Report whether ClearPass backend is configured. Read correlate_advisory_lifecycle correlate_advisory_lifecycle Read detect_client_flapping detect_client_flapping Read detect_ssh_brute_force detect_ssh_brute_force Read drawio_network_design_diagram drawio_network_design_diagram Read edgeconnect_alarm_summary Get EdgeConnect alarm summary counts from Orchestrator. Read edgeconnect_doctor edgeconnect_doctor Read edgeconnect_get Perform a read-only GET request to EdgeConnect Orchestrator API. Read edgeconnect_get_appliance_network_role_site Get compact EdgeConnect appliance network role and site assignment. Read edgeconnect_get_appliance_reachability Get compact EdgeConnect reachability for one appliance from Orchestrator. Read edgeconnect_get_bypass_mode Get compact EdgeConnect bypass-mode state for an appliance. Read edgeconnect_get_disk_report Get compact EdgeConnect appliance disk and storage-controller report. Read edgeconnect_get_flow_stats edgeconnect_get_flow_stats Read edgeconnect_get_interface_state Get compact EdgeConnect appliance interface state by appliance nePk. Read edgeconnect_get_link_integrity_status Get compact EdgeConnect link-integrity test status for an appliance. Read edgeconnect_get_maintenance_mode List EdgeConnect appliances currently configured for maintenance mode. Read edgeconnect_get_next_zone_id Get the next available EdgeConnect firewall-zone ID. Read edgeconnect_get_overlay_priority Get EdgeConnect overlay priority order mapping. Read edgeconnect_get_route_maps Get EdgeConnect route policy settings for an appliance. Read edgeconnect_get_system_info Get compact system information from an EdgeConnect appliance API. Read edgeconnect_get_topology_link_info Get sparse EdgeConnect topology link status for an overlay. Read edgeconnect_get_tunnel_metadata Get EdgeConnect tunnel count metadata from Orchestrator. Read edgeconnect_get_zone_firewall_status Get EdgeConnect End-to-End Zone-Based Firewall status. Read edgeconnect_list_address_groups List EdgeConnect ACL address groups with compact fields. Read edgeconnect_list_alarms List outstanding EdgeConnect appliance alarms with compact fields. Read edgeconnect_list_appliance_reachability List compact EdgeConnect appliance reachability from Orchestrator. Read edgeconnect_list_appliances List EdgeConnect Orchestrator appliances with compact inventory fields. Read edgeconnect_list_flows edgeconnect_list_flows Read edgeconnect_list_interface_labels List EdgeConnect interface labels with compact WAN/LAN fields. Read edgeconnect_list_overlays List EdgeConnect overlay configurations with compact fields. Read edgeconnect_list_route_labels List EdgeConnect route labels with compact fields. Read edgeconnect_list_service_groups List EdgeConnect ACL service groups with compact fields. Read edgeconnect_list_services List EdgeConnect overlay internet services with compact fields. Read edgeconnect_list_third_party_services List EdgeConnect third-party cloud services with compact fields. Read edgeconnect_list_tunnels List EdgeConnect physical tunnels with compact health/status fields. Read edgeconnect_list_vrf_segment_zones List EdgeConnect firewall zones across VRF segments with compact fields. Read edgeconnect_list_vrf_segments List EdgeConnect routing/VRF segments with compact fields. Read edgeconnect_list_vrf_zone_map List EdgeConnect VRF-to-firewall-zone mappings with compact fields. Read edgeconnect_list_zones List EdgeConnect firewall zones with compact fields. Read edgeconnect_status Report whether EdgeConnect backend is configured. Read evaluate_compliance_policy evaluate_compliance_policy Read find_client Find a connected client by MAC address or IP address. Read find_device Find a single device by serial number. Returns the device record or None. Read find_mac_on_switch Find which port a MAC address is learned on for a CX switch. Read find_scope Find scopes by name or ID substring, optionally narrowed by scope_type. Read find_tool find_tool Read get_aaa_profile Get a single AAA profile by name. Read get_air_quality get_air_quality Read get_alert_action_status Return async status for clear/defer/reactivate/priority alert actions. Read get_ap_neighbors Get neighboring APs visible to this AP with RSSI and channel. Read get_ap_ports List wired ports on an AP with link state, speed, VLAN, and duplex. Read get_ap_radios List radios on an AP with band, channel, power, utilization, and mode. Read get_ap_tunnel Fetch detail for a single AP tunnel by ID. Read get_ap_tunnel_throughput Time-series throughput for a single AP tunnel over a time window. Read get_audit_log Audit logs are not available on New Central instances. Read get_auth_profile Get a single Central NAC auth profile by UUID. Read get_auth_server Get a single RADIUS/auth server profile by name. Read get_authz_policy Get a single CNAC authz policy by ID. Read get_channel_utilization Get per-radio channel utilization and noise floor for an AP. Read get_client_details Fetch detailed info (usage, bandwidth, auth) for a single client by MAC address. Read get_client_roaming_history get_client_roaming_history Read get_client_signal_history get_client_signal_history Read get_cluster_members List members of a gateway cluster. Read get_cluster_tunnel_health Get tunnel health summary (up/down counts) for a gateway cluster. Read get_cluster_tunnels List tunnels for a gateway cluster. Read get_config_rollback_status get_config_rollback_status Read get_cx_arp_table Get the ARP table from a CX switch. Read get_cx_mac_table Get the MAC address table from a CX switch. Read get_device_config_issues Return active configuration issues and recommended actions for one device. Read get_device_health Fetch config-health or monitoring health state for a device. Read get_device_running_config Download the running configuration for a device. Read get_device_trends Time-series utilization trends for an AP or switch. Read get_events_count Count events for a device over the past N hours (default 24). Read get_firmware Fetch current firmware details (version, compliance status, upgrades available) for a device. Read get_firmware_compliance Read the current firmware compliance policy at a given scope. Read get_global_scope_id Return the org-wide scope ID from GET /network-config/v1/global. Read get_glp_audit_log_detail get_glp_audit_log_detail Read get_glp_audit_log_v2 Fetch a single GLP audit-log entry by ID via the v2beta1 Audit Log service. Read get_glp_audit_log_v2_detail Fetch full detail for a v2beta1 GLP audit-log entry (entries with details enabled). Read get_glp_auto_subscription_setting Fetch one configured auto-subscription setting by ID. Read get_glp_backup_protection_job Fetch one Backup & Recovery protection job by ID. Read get_glp_block_storage_volume Fetch one Block Storage volume by ID. Read get_glp_compute_server Fetch one HPE Compute Ops Management server by ID. Read get_glp_data_services_issue Fetch one Data Services issue by ID. Read get_glp_device Fetch a single device from GLP by serial number. Read get_glp_device_by_id Fetch a GLP device by its official device resource ID. Read get_glp_device_v2 Fetch a single device via the GLP Devices v2beta1 collection by GLP device ID. Read get_glp_event_webhook Fetch one workspace event webhook by ID. Read get_glp_location Fetch one workspace location by ID. Read get_glp_location_tags Fetch location-management tags assigned to one location. Read get_glp_reporting_status Fetch a single GreenLake reporting status record by ID. Read get_glp_role_assignment Fetch one RBAC role assignment by ID. Read get_glp_scim_group Fetch one SCIM user group by ID. Read get_glp_scim_user Fetch one SCIM user by ID. Read get_glp_scope_group Fetch one RBAC scope group by ID. Read get_glp_service_manager Fetch a GreenLake service manager by ID. Read get_glp_service_manager_provision Fetch a GreenLake service-manager provision by ID. Read get_glp_service_managers_for_region Fetch GreenLake service managers available for a region mapping ID. Read get_glp_service_offer Fetch a GreenLake service-catalog offer by ID. Read get_glp_service_offer_region Fetch a GreenLake service-offer region by ID. Read get_glp_service_provision Fetch a GreenLake service provision by ID. Read get_glp_storage_system Fetch one Storage Fleet system by ID. Read get_glp_subscription Fetch a single GLP subscription by ID. Read get_glp_user Fetch a single GLP identity user by ID. Read get_glp_virtual_machine Fetch one GLP-managed virtual machine by ID. Read get_glp_workspace Fetch basic GreenLake workspace information by workspace ID. Read get_glp_workspace_contact Fetch detailed GreenLake workspace contact information. Read get_lldp_neighbors Get LLDP neighbor table from a CX switch. Read get_network_profile get_network_profile Read get_passpoint_identity_profile Fetch a Passpoint identity / ANQP NAI realm profile by name. Read get_passpoint_profile Fetch a Passpoint / 802.11u provider profile by name. Read get_report Fetch a single saved report by ID. Read get_report_run_download_link get_report_run_download_link Read get_reporting_service_health Fetch reporting-service health status from network-reporting/v1alpha1/reports/health. Read get_reports_metadata Fetch reporting metadata (available report types/fields). Read get_scope_maps Return scope-map entries, optionally filtered by resource name (bounded by default). Read get_server_group Get a single auth server group by name. Read get_site Find a site by name (case-insensitive). Returns None if not found. Read get_site_health_summary Return a single-view health summary for a site. Read get_ssid Fetch an existing SSID config by name. Returns None if not found. Read get_swarm Fetch a single AP swarm/cluster by ID from network-monitoring/v1/swarms/{cluster-id}. Read get_switch_details Fetch full monitoring details for a switch (status, uptime, CPU, memory, VLANs). Read get_switch_interface_counters Get Tx/Rx byte and packet counters for CX switch interfaces. Read get_switch_interface_poe Fetch PoE state and power draw for all ports on a switch. Read get_switch_interface_trends Throughput trends for switch interfaces over a time window. Read get_switch_port_errors Get error counters for CX switch ports. Read get_switch_spanning_tree get_switch_spanning_tree Read get_switch_stacking_info get_switch_stacking_info Read get_switch_vlans List VLANs active on a switch (status, membership). filter: OData e.g. "status in ('Up')". Read get_tenant_health Return tenant-wide device and client health summaries. Read get_topology Fetch the network topology (nodes + links) for a site. Read get_webhook Fetch details for a single webhook by ID. Read get_wireless_metrics Fetch AP wireless metrics: RF stats, client count, utilization, channel. Read get_wlan Fetch monitoring details for a single WLAN by name. Read glp_get glp_get Read glp_write_status Report whether guarded GLP v2beta1 write tools are enabled. Read invoke_read_tool invoke_read_tool Read invoke_read_tool_batch invoke_read_tool_batch Read list_aaa_profiles List AAA profiles (bounded by default). Read list_active_alerts list_active_alerts Read list_advisories list_advisories Read list_alert_classifications List alert classification metadata from network-notifications/v1/alerts/classification. Read list_alert_configs List alert configuration definitions for a Central scope. Read list_alerts list_alerts Read list_ap_tunnels list_ap_tunnels Read list_ap_wlans List WLANs currently active on a specific AP. Read list_applications list_applications Read list_audit_logs Audit logs are not available on New Central instances. Read list_auth_profiles List Central NAC authentication profiles (bounded by default). Read list_auth_servers List RADIUS/auth server profiles (bounded by default). Read list_authz_policies List CNAC authorization policies (bounded by default). Read list_bssids list_bssids Read list_central_get_prefixes list_central_get_prefixes Read list_client_onboarding_events List 'Client Onboarding' events for a device over the past N hours (bounded by default). Read list_clients list_clients Read list_config_assignments list_config_assignments Read list_config_templates list_config_templates Read list_device_groups List all device groups (scopeId, scopeName, description). Read list_devices list_devices Read list_devices_config_health List fleet config-health summaries, optionally sorted/filtered/searched. Read list_diagram_icons List diagram icon pack inventory (SVG/PNG/VSS) for network drawings. Read list_diagram_roles_and_vendors List accepted diagram node roles/vendors and export approaches (Draw.io, Graphviz, NeXt). Read list_events List bounded device events and auto-resolve the device type and site. Read list_fingerprinting_profiles List device-fingerprinting wireless profiles (bounded by default). Read list_fingerprinting_switch_profiles List device-fingerprinting switch profiles (bounded by default). Read list_firmware_upgrades list_firmware_upgrades Read list_gateways List gateway inventory from network-monitoring/v1/gateways. Read list_glp_api_families List guarded GLP GET path-prefixes reachable via glp_get, and note which Read list_glp_audit_logs list_glp_audit_logs Read list_glp_audit_logs_v2 List GLP audit log entries via the v2beta1 Audit Log service. Read list_glp_auto_subscription_settings List all configured auto-subscription settings in the GLP workspace. Read list_glp_backup_protection_jobs List Backup & Recovery protection jobs and their run status. Read list_glp_backup_protection_stores List Backup & Recovery protection stores (backup target capacity/health). Read list_glp_backup_storeonces List registered HPE StoreOnce appliances under Backup & Recovery. Read list_glp_backup_vm_protection_groups List virtual-machine protection groups under Backup & Recovery. Read list_glp_block_storage_hosts List Block Storage host initiators (registered application hosts). Read list_glp_block_storage_volumes List HPE GreenLake Block Storage volumes across the fleet. Read list_glp_compute_groups List Compute Ops Management server groups. Read list_glp_compute_jobs List Compute Ops Management jobs (firmware/config actions) and their status. Read list_glp_compute_server_alerts List active alerts for one Compute Ops Management server. Read list_glp_compute_servers List HPE Compute Ops Management servers (iLO-managed compute inventory). Read list_glp_data_services_async_operations List Data Services async-operation status (job tracking). Read list_glp_data_services_issues List open Data Services issues (cross-resource health/status feed). Read list_glp_data_services_storage_locations List Data Services storage locations (no server-side pagination per the manifest). Read list_glp_datastores List datastores visible to GLP Virtualization. Read list_glp_devices List devices in the GLP workspace (warranty, subscription state, lifecycle). Read list_glp_devices_v2 list_glp_devices_v2 Read list_glp_event_subscriptions List event subscriptions for a webhook. Read list_glp_event_webhooks List workspace event webhooks, newest first. Read list_glp_hypervisor_clusters List hypervisor clusters visible to GLP Virtualization. Read list_glp_hypervisor_managers List registered hypervisor managers (e.g. vCenter instances). Read list_glp_location_tags List location-management tags for the workspace. Read list_glp_locations List workspace locations; the documented filter supports location name. Read list_glp_per_region_service_managers List GreenLake per-region service-manager mappings. Read list_glp_reporting_statuses List GreenLake reporting status records with bounded pagination. Read list_glp_role_assignments List RBAC role assignments with bounded offset pagination. Read list_glp_scim_group_users List SCIM users assigned to a user group. Read list_glp_scim_groups List SCIM user groups with 1-based pagination. Read list_glp_scim_user_groups List SCIM groups assigned to a user. Read list_glp_scim_users List SCIM users with 1-based pagination. Read list_glp_scope_group_scopes List scopes assigned to an RBAC scope group. Read list_glp_scope_groups List RBAC scope groups with bounded offset pagination. Read list_glp_service_manager_provisions List GreenLake service-manager provisions. Read list_glp_service_managers List GreenLake service managers. Read list_glp_service_offer_regions List GreenLake service-offer regions with cursor pagination. Read list_glp_service_offers List GreenLake service-catalog offers with cursor pagination. Read list_glp_service_provisions List GreenLake service provisions, optionally scoped by workspace ID. Read list_glp_storage_system_types List the storage device types supported by Storage Fleet. Read list_glp_storage_systems List HPE GreenLake Storage Fleet systems (cross-device-type inventory). Read list_glp_subscriptions List subscriptions with limit / offset pagination. Read list_glp_tag_resources List tagged workspace resources with bounded pagination. Read list_glp_tags List workspace tags with filter, sort, projection, and bounded pagination. Read list_glp_users List users with access to the GLP workspace using limit / offset pagination. Read list_glp_virtual_machines List virtual machines managed via the GLP Virtualization service. Read list_glp_webhook_deliveries List recent delivery attempts for a workspace event webhook. Read list_gw_clusters List gateway clusters for overlay/tunneled SSIDs (bounded by default). Read list_gw_policies List GW security policies (bounded by default). Read list_identity_stores List Central NAC identity stores (bounded by default). Read list_insights List Central Insights recommendation-style observations. Read list_inventory list_inventory Read list_lifecycle_events list_lifecycle_events Read list_mac_registrations List Central NAC MAC address registrations (bounded by default). Read list_mpsk_registrations List Central NAC Named MPSK registrations (bounded by default). Read list_named_vlans List named VLANs configured at the group/scope level in Central. Read list_overlay_wlans List overlay (tunneled/GRE) WLAN profiles (bounded by default). Read list_passpoint_identity_profiles List Passpoint identity / ANQP NAI realm profiles (bounded by default). Read list_passpoint_profiles List Passpoint / 802.11u provider profiles (bounded by default). Read list_radios list_radios Read list_report_runs List report-run history for a saved report. Read list_reports List saved Central reports from network-reporting/v1/reports. Read list_rogue_aps list_rogue_aps Read list_role_acls List role ACL policies (bounded by default). Read list_roles List wireless/gateway roles (bounded by default). Read list_scope_devices list_scope_devices Read list_scopes list_scopes Read list_server_groups List RADIUS/TACACS auth server groups (bounded by default). Read list_show_commands list_show_commands Read list_sites Return sites with IDs, names, and location fields (paginated). Read list_sites_client_health list_sites_client_health Read list_skills list_skills Read list_ssid_clients List all clients currently connected to a specific SSID. Read list_ssids Return wlan-ssid objects from Aruba New Central (bounded by default). Read list_static_tags List user-created static classification tags (bounded). System tags (e.g. IoT) not returned. Read list_swarms list_swarms Read list_switch_ports List switch interfaces with optional OData filtering. Read list_visitors List Central NAC visitor accounts (bounded by default). Read list_webhooks List configured webhooks (bounded by default). Read list_wlans List all WLANs visible in New Central monitoring. Read load_skill Load one skill's full markdown runbook body by name. Read locate_client Get the approximate physical location of a client. Read lookup_advisory lookup_advisory Read lookup_api lookup_api Read mist_collect_diagnostic_results mist_collect_diagnostic_results Read mist_get Perform a read-only GET request to Mist API. Read mist_get_client Look up Mist wireless client health by site ID and MAC address. Read mist_get_client_insights Get Marvis client experience insights/metrics for one wireless client. Read mist_get_gateway Get one Mist WAN Edge gateway (SRX or SSR) with compact status fields. Read mist_get_marvis_settings mist_get_marvis_settings Read mist_get_org_sle_overview mist_get_org_sle_overview Read mist_get_site_assurance_snapshot mist_get_site_assurance_snapshot Read mist_get_site_sle_metric_summary mist_get_site_sle_metric_summary Read mist_list_alarms List recent Mist site alarms with compact severity/time fields. Read mist_list_gateways mist_list_gateways Read mist_list_nac_idps mist_list_nac_idps Read mist_list_nac_portals List Mist org NAC (guest/BYOD) portals. Read mist_list_nac_tags List Mist org NAC tags used by Access Assurance policy rules. Read mist_list_org_inventory mist_list_org_inventory Read mist_list_sites List Mist org sites with compact ID, name, timezone, and location fields. Read mist_list_switch_ports mist_list_switch_ports Read mist_list_switches mist_list_switches Read mist_list_user_macs mist_list_user_macs Read mist_list_wlans List Mist site WLANs with compact SSID, status, auth, and VLAN fields. Read mist_search_events mist_search_events Read mist_search_marvis_clients mist_search_marvis_clients Read mist_status Report whether Mist backend is configured. Read rag_diagnostics rag_diagnostics Read resolve_stack_serial Resolve a CX switch serial to its stack conductor's serial, if it is a stack member. Read reverse_geocode_glp_location Resolve latitude/longitude to a location, optionally using an ISO language code. Read search_docs search_docs Read uxi_get Perform a guarded read-only GET against selected UXI v1alpha1 paths. Read uxi_get_sensor_status Get online/testing status and active issues for a UXI sensor. Read uxi_list_agent_group_assignments List UXI agent-to-group assignments. Read uxi_list_agents List UXI agents with compact identity, model, MAC, group, and notes fields. Read uxi_list_groups List UXI groups with id, name, path, and parent group. Read uxi_list_network_group_assignments List UXI network-to-group assignments. Read uxi_list_sensor_group_assignments List UXI sensor-to-group assignments. Read uxi_list_sensors List UXI sensors with compact identity, model, MAC, group, and location fields. Read uxi_list_service_test_group_assignments List UXI service-test-to-group assignments. Read uxi_list_service_tests List UXI service tests. Read uxi_list_wired_networks List UXI wired networks. Read uxi_list_wireless_networks List UXI wireless networks. Read uxi_status Report whether the optional UXI backend has OAuth credentials configured. Read validate_diagram_model Validate a network design diagram model before Draw.io/Graphviz export.

Related servers

Other MCP servers with similar tools — same risk classification, starter policies for each.

Questions about API-Central

Can an AI agent delete data through the API-Central MCP server? +

Yes. The API-Central server exposes 42 destructive tools including aos8_execute_migration_rollback, aos8_logout, apstra_delete_connectivity_template. These permanently remove resources with no undo. PolicyLayer blocks destructive tools by default so they never reach the upstream server.

How do I prevent bulk modifications through API-Central? +

The API-Central server has 130 write tools including acknowledge_alert, add_devices_to_group, add_glp_scope_group_scopes. Set a rate limit in your policy -- for example, 10 calls per hour prevents an agent from making more than 10 modifications per hour. PolicyLayer enforces this at the gateway, before calls reach API-Central.

How many tools does the API-Central MCP server expose? +

590 tools across 4 categories: Destructive, Execute, Read, Write. 370 are read-only. 220 can modify, create, or delete data.

How do I enforce a policy on API-Central? +

Register the API-Central MCP server in PolicyLayer, apply the suggested rules above (adjust the limits to your use case), and point your AI client at the PolicyLayer proxy URL instead of the server directly. Your agents keep the same tools; PolicyLayer evaluates every call against policy before it executes. Nothing to install, live in minutes.

Enforce policy on every API-Central tool call.

Deterministic rules across all 590 API-Central tools. Per-identity grants. Full audit log. Live in minutes. Nothing to install.

Instant setup, no code required.

590 API-Central tools catalogued and risk-classified — across an index of 46,500+ MCP servers.

// WHERE THIS COMES FROM

These policies come from API-Central's registry record.

The record behind this page: verified identity, auth posture, risk grade, every tool classified, recommended policy — re-checked continuously.

Teams ship this data inside their own products. See what a licence covers →

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.