Ccu MCP runs on your own machine — the client starts it, so there is no endpoint to ping. 73 installs a week from npm. Last commit 16 Sep 2026.
MCP server for controlling HomeMatic smart home devices via the CCU JSON-RPC API
We read the source, 22 h ago · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
for (const key of Object.keys(process.env)) {
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add ccu-mcp -- npx -y ccu-mcp
{
"mcpServers": {
"ccu-mcp": {
"args": [
"-y",
"ccu-mcp"
],
"command": "npx"
}
}
}
[mcp_servers.ccu-mcp]
command = "npx"
args = ["-y", "ccu-mcp"]
{
"mcpServers": {
"ccu-mcp": {
"args": [
"-y",
"ccu-mcp"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"ccu-mcp": {
"args": [
"-y",
"ccu-mcp"
],
"command": "npx"
}
}
}
This one needs environment variables set before it will start:
CCU_HOST (Hostname or IP of your HomeMatic CCU (debmatic, CCU3, or OpenCCU/RaspberryMatic)), CCU_PASSWORD (CCU admin password (same as the WebUI login). Must be set; the value may be empty for a CCU with no password), CCU_USER (CCU username), CCU_HTTPS (Connect to the CCU via HTTPS (self-signed certificates supported)), CCU_PORT (CCU API port (80 for HTTP, 443 for HTTPS)), CACHE_DIR (Directory for the device type cache and session persistence), MCP_ALLOWED_ORIGINS (Comma-separated allowlist of browser origins. Unset = no cross-origin browser access (default-deny). An allowlisted origin is reflected exactly in Access-Control-Allow-Origin (never '*'); the list also drives DNS-rebinding origin checks), MCP_ALLOWED_HOSTS (Extra Host header values accepted by DNS-rebinding protection (comma-separated host:port); add your hostname when behind a proxy or container DNS name), CCU_PROFILES (Comma-separated names of multiple CCU targets (e.g. 'prod,dev'). Each profile takes the flat CCU_* settings prefixed CCU_<NAME>_ (CCU_PROD_HOST, ...), plus policy flags CCU_<NAME>_PROTECTED (writes need confirm:true) and CCU_<NAME>_READONLY. Unset = single default profile from the flat CCU_* vars), CCU_DEFAULT_PROFILE (Which profile from CCU_PROFILES is active at startup (default: the first listed)), CCU_TLS_VERIFY (Verify the CCU's TLS certificate against the system trust store. Only meaningful with CCU_HTTPS=true. Default false, because a CCU ships a self-signed certificate — prefer CCU_TLS_FINGERPRINT or CCU_CA_CERT to verify one of those), CCU_TLS_FINGERPRINT (Pin the CCU's self-signed leaf certificate by its SHA-256 fingerprint (hex, colons optional). The strongest option for an appliance: the connection is rejected unless the presented certificate matches. Takes precedence over CCU_CA_CERT), CCU_CA_CERT (Path to a PEM file holding the CCU's CA or self-signed certificate. The connection is then validated against it with standard chain verification), CCU_TIMEOUT (Timeout for a CCU JSON-RPC call, in MILLISECONDS), CCU_SCRIPT_TIMEOUT (Timeout for HomeMatic Script execution (ReGa), in MILLISECONDS — scripts are slower than plain API calls), CACHE_TTL (Lifetime of the on-disk device-type schema cache, in SECONDS), CCU_RATE_LIMIT_BURST (Token-bucket burst size for CCU requests — how many may be issued back to back), CCU_RATE_LIMIT_RATE (Sustained CCU request rate, in requests per second), RESOURCE_POLL_INTERVAL (How often MCP resources are polled for change notifications, in SECONDS), LOG_LEVEL (error | warn | info | debug. Logs are structured JSON on stderr).
The author declared them in the registry entry; get the values from the project itself.
MCP server for controlling HomeMatic smart home devices via the CCU JSON-RPC API
MCP server for discovering and controlling TP-Link Tapo smart home devices via AI Agents
Local-first MCP server for Shelly smart-home devices (Gen1-Gen4): control, energy, automation.
MCP server for controlling Discord servers via bot token
MCP server for Android device control via ADB and scrcpy
MCP server for controlling the Xojo IDE on macOS
MCP server for the Auvik network monitoring API — devices, alerts, statistics, billing.
MCP server for the Auvik network monitoring API — devices, alerts, statistics, billing.
Answers built from our own checks of this server.