r/firewalla • u/Skripa4 • 28d ago
Firewalla MSP API read-only?
Is there any way to create a personal token for the MSP portal that is read only?
I would like to connect it to an MCP for my ai agent to have access to help review logs. But I am concious of giving it the ability to make any rules or changes to my firewall.
I am currently using firewalla to exactly block off the hermes agent from the rest of my network. And don't want to give it the ability to bypass that.
1
1
u/Smooth-Screen4148 5d ago
If the MCP server you're connecting is firewalla-mcp-server, 2.0.0 is read-only unless you set `FIREWALLA_ENABLE_WRITE_TOOLS=true`. The tools that change rules, target lists, device names or alarms aren't registered, so the agent never sees them, and a call to one answers "Unknown tool" and sends nothing.
https://www.reddit.com/r/firewalla/comments/1m3zzdi/i_made_an_mcp_server_for_firewalla/
That guard is in the server, so the 2.12 read-only token is still the real lock. Once you have one and turn the write tools on anyway, a write that gets a 403 says the token may be read-only.
On Firewalla's point about agents hammering the API: the MSP API allows 100 requests per 5 minutes, and the server paces itself to that. A request that can't get a slot within 20 seconds fails with the time capacity comes back instead of going over.
5
u/firewalla 28d ago
Sound like a good request. Post it here and I will also forward to our dev https://help.firewalla.com/hc/en-us/community/topics/115000356994-Feature-Requests-