# NetBird MCP for AI Agents AI Agent Connect

> NetBird MCP lets you manage your private Zero Trust network through an AI agent. You can handle user onboarding, set up network policies, create resources, and manage MSP tenants without jumping between tabs. It turns your agent into a network administrator for your private infrastructure.

## Overview
- **Category:** cloud-infrastructure
- **Price:** Free
- **Endpoint:** https://edge.vinkius.com/vk_preview_4bouBTXHFMgVmBLmbgMfSxtgydYvSEl3iC2a6uIM/ai-agent-connect
- **Tags:** zero-trust, vpn, network-management, access-control, mesh-network

## Description

NetBird lets you manage your private network infrastructure directly through natural conversation with your AI agent. Instead of hunting through a dashboard to toggle permissions or find specific peer statuses, you can just tell your agent what needs to happen. You can handle the heavy lifting of user administration, like inviting new team members or blocking access, while also managing the underlying network resources. Whether you need to create a new network, set up specific routing policies, or verify DNS settings for an MSP tenant, this Connector puts the controls in your hands. It is built for teams that need to move fast without sacrificing security. By connecting this to the Vinkius catalog, you get a unified way to manage your Zero Trust environment. You can quickly swap out user roles, generate setup keys, and monitor audit events to keep your network tight. It turns complex infrastructure management into a series of simple, conversational tasks.

## Tools

### delete_peer
Delete a peer from your network. Use this to remove disconnected or unauthorized devices.

### get_network
Retrieve details for a specific network. Use this to see the overall status of your infrastructure.

### list_all_network_routers
List all routers across all networks. Use this for a high-level view of your hardware.

### list_posture_checks
List all posture checks. Use this to see your current device compliance rules.

### list_routes
List all routes in your network. Note that this tool is currently deprecated.

### list_setup_keys
List all setup keys. Use this to see all available join keys.

### list_user_invites
List pending user invites. Use this to see who is waiting to join your network.

### list_user_tokens
List all tokens for a specific user. Use this to manage a user's personal access keys.

### list_users
List all users in your account. Use this to see every identity in your network.

### update_account
Update account settings like peer login expiration. Use this to modify core account rules.

### update_policy
Update a policy. Use this to modify existing security rules for your network.

### change_user_password
Change a user password for the embedded IdP. This is helpful for quick credential resets.

### create_group
Create a new group for your network. Use this to organize users into different departments.

### create_msp_tenant
Create a new MSP tenant. Use this to set up dedicated environments for your partners.

### create_nameserver
Create a nameserver group. This helps you manage custom DNS settings for your network.

### create_network_resource
Create a resource like a host, subnet, or domain. Use this to expand your network footprint.

### create_network_router
Create a router in a network. This helps you define the traffic flow between different zones.

### create_network
Create a new network. Use this to start a fresh Zero Trust environment.

### create_policy
Create a policy with specific rules. Use this to define which ports and protocols are allowed.

### create_posture_check
Create a posture check for OS or geo-location. This ensures only compliant devices can connect.

### create_route
Create a route for your network traffic. Note that this tool is currently deprecated.

### create_setup_key
Create a setup key for new peers. Use this to provide secure, one-off join instructions.

### create_temporary_access_peer
Create a temporary access peer. Use this for short-term guest access to your infrastructure.

### create_user_invite
Create a user invite link. Use this to send a join request to a new team member.

### create_user_token
Create a new personal access token. This allows for programmatic interaction with your account.

### create_user
Create a service user or invite a regular user. Use this to add new identities to your network.

### delete_account
Delete a NetBird account and all its resources. Use this for complete account cleanup.

### delete_group
Delete a group from your network. Use this to remove old organizational structures.

### delete_network_resource
Delete a network resource. Use this to remove old hosts or subnets from your plan.

### delete_network_router
Delete a network router. Use this to clean up old routing hardware.

### delete_network
Delete a network. Use this to remove an entire Zero Trust environment.

### delete_policy
Delete a policy. Use this to remove outdated security rules.

### delete_posture_check
Delete a posture check. Use this to remove old compliance requirements.

### delete_route
Delete a route from your network. Note that this tool is currently deprecated.

### delete_user_token
Delete a specific user token. Use this to revoke access for specific scripts or apps.

### get_nameserver
Retrieve nameserver group details. Use this to check your custom DNS configurations.

### get_network_resource
Retrieve details for a network resource. Use this to see the status of a specific host or subnet.

### get_network_router
Retrieve details for a network router. Use this to check the status of your routing hardware.

### get_peer
Retrieve details for a specific peer. Use this to check if a device is online or its current IP.

### get_policy
Retrieve details for a policy. Use this to see exactly what rules are currently in place.

### get_posture_check
Retrieve details for a posture check. Use this to see what compliance rules are active.

### get_public_user_invite
Get public invite info without being authenticated. Use this to check public join links.

### get_setup_key
Retrieve details for a setup key. Use this to check the status of your join keys.

### get_user_token
Retrieve a specific user token. Use this to check the status of a personal access token.

### invite_msp_tenant
Invite an existing account to become a tenant. Use this for partner onboarding.

### list_accessible_peers
List peers accessible by your current peer. Use this to see who you can connect with.

### list_accounts
List all NetBird accounts in your organization. Use this to see the full scope of your managed accounts.

### list_audit_events
List all audit events. Use this to see activity logs for security monitoring.

### list_cities
List city names for a specific country. Use this for geo-location configuration.

### list_countries
List all ISO 3166-1 alpha-2 country codes. Use this for configuring geo-fencing.

### list_groups
List all groups in your network. Use this to see how your organization is structured.

### regenerate_user_invite
Regenerate an invite token. Use this if a user lost their original join link.

### reject_user
Reject a pending user request. Use this to block someone from joining your network.

### resend_user_invite
Resend a user invitation. Use this to prompt a user to join your network again.

### respond_msp_tenant_invite
Accept or decline an MSP invitation. Use this to manage your partner relationships.

### unlink_msp_tenant
Unlink a tenant to a new owner. Use this to transfer ownership of a managed environment.

### update_dns_settings
Update DNS settings. Use this to change global naming or management groups.

### update_group
Update group name, peers, or resources. Use this to reorganize your network structure.

### update_msp_tenant_subscription
Create or update a tenant subscription. Use this to manage partner billing cycles.

### update_msp_tenant
Update tenant name or access groups. Use this to modify partner environment details.

### update_nameserver
Update nameserver group details. Use this to modify your custom DNS configurations.

### update_network_router
Update a network router. Use this to change the configuration of your routing hardware.

### update_network
Update the network name or description. Use this to keep your infrastructure organized.

### update_peer
Update peer name, SSH status, or IP. Use this to modify specific device details.

### update_posture_check
Update a posture check. Use this to modify the compliance requirements for devices.

### update_route
Update a route in your network. Note that this tool is currently deprecated.

### update_setup_key
Update a setup key to revoke it or change auto-groups. Use this to manage join keys.

### update_user
Update user role, auto-groups, or block status. Use this to manage user permissions.

### verify_msp_tenant_dns
Verify a tenant domain DNS challenge. Use this to ensure your partner's DNS is correct.

### accept_user_invite
Accept a user invite and set a password. This helps you finalize the onboarding process for new members.

### approve_user
Approve a pending user request. Use this to grant access to people waiting in your queue.

### delete_nameserver
Delete a nameserver group. Use this to remove old DNS configurations.

### delete_setup_key
Delete a setup key. Use this to revoke access keys that are no longer needed.

### delete_user_invite
Delete a user invite. Use this to remove expired or unused join links.

### delete_user
Remove a user from your account. Use this to offboard employees or delete service accounts.

### get_current_user
Retrieve the info for the current user. Use this to check your own permissions and status.

### get_dns_settings
Retrieve global DNS settings. Use this to check your current network naming configurations.

### get_group
Retrieve details for a specific group. Use this to see which peers are in a certain department.

### get_route
Retrieve route details (Deprecated)

### list_msp_tenants
List all MSP tenants. Use this to see which partners are currently connected.

### list_nameservers
List all nameserver groups. Use this to check your global DNS configurations.

### list_network_resources
List resources in a specific network. Use this to see the hosts and subnets in a zone.

### list_network_routers
List routers in a specific network. Use this to see the routing hardware for a zone.

### list_network_traffic_events
List network traffic events. Use this for experimental traffic monitoring.

### list_networks
List all networks. Use this to see every environment you manage.

### list_peers
List all network peers. Use this to see every device connected to your mesh.

### list_policies
List all policies. Use this to see every security rule currently in effect.

### list_proxy_events
List reverse proxy access logs. Use this to monitor traffic through your proxy.

### update_network_resource
Update a network resource. Use this to modify existing host or subnet details.

## Prompt Examples

**Prompt:** 
```
I need to onboard a new developer named Alex to our engineering network.
```

**Response:** 
```
I've started the onboarding process for Alex. Here is what I've done:

* **Invite Created**: A new join link has been generated.
* **Group Assignment**: I've added them to the 'Engineering' group.
* **Access Granted**: They are now set to have standard dev permissions.

Would you like me to send the invite link to their email now?
```

**Prompt:** 
```
Can you show me the last few security audit events?
```

**Response:** 
```
Here are the most recent activity logs:

| Time | Action | Initiator | Target |
| :--- | :--- | :--- | :--- |
| 10:15 AM | Login | user_dev_01 | Network_A |
| 10:22 AM | Policy Update | admin_user | Network_B |
| 10:45 AM | Peer Connect | user_dev_02 | Network_A |

Everything looks normal. Let me know if you want to see more details on any of these.
```

**Prompt:** 
```
Create a new network for our marketing team's project.
```

**Response:** 
```
I've created a new network for the Marketing project. 

* **Network Name**: Marketing_Project_Alpha
* **Status**: Active
* **Resources**: Initial subnet and routing rules have been applied.

I can also create a specific group for the marketing team members if you'd like.
```

## Capabilities

### Manage user access
Invite new members, approve pending requests, and block users from the network instantly.

### Configure network policies
Create and update rules for protocols, ports, and specific sources or destinations.

### Provision network resources
Add hosts, subnets, and domains to your existing network infrastructure.

### Handle MSP tenants
Create, update, and verify DNS settings for managed service provider tenants.

### Monitor audit logs
Retrieve activity logs to see who initiated what action and when it happened.

## Use Cases

### Onboarding a new remote employee
A manager asks their agent to invite a new hire. The agent uses create_user_invite to generate a link and then uses create_group to assign them to the correct department.

### Responding to a security alert
A security lead sees an alert and asks the agent to check the logs. The agent uses list_audit_events to find the source and update_user to block the compromised account.

### Expanding the dev environment
A developer needs a new subnet for a project. They ask the agent to create_network_resource for a new host range and create_policy to allow traffic.

### Managing a partner's DNS
An IT admin needs to verify a partner's setup. They ask the agent to verify_msp_tenant_dns and update_dns_settings to ensure everything is correctly routed.

## Benefits

- Automate user onboarding by using create_user_invite to send links and approve_user to grant access instantly.
- Enforce stricter security by using create_posture_check to ensure only healthy devices can enter your mesh network.
- Simplify infrastructure management by using create_network_resource to add hosts and subnets without manual configuration.
- Gain full visibility into your network by using list_audit_events to monitor every action taken by your users.
- Scale your partner operations using create_msp_tenant and update_msp_tenant to manage multiple client environments.
- Control traffic flow precisely by using create_policy to define specific rules for protocols and ports.

## How It Works

The bottom line is you get a conversational interface for your entire Zero Trust network.

1. Subscribe to the NetBird MCP in your Vinkius dashboard.
2. Provide your NetBird API Token to your AI client.
3. Ask your agent to list users, create policies, or manage network resources.

## Frequently Asked Questions

**How does the NetBird MCP help with team security?**
It lets you use your AI agent to enforce security rules instantly. You can create posture checks to ensure only healthy devices connect and use audit events to monitor every action on your network.

**Can I use NetBird MCP to manage my MSP clients?**
Yes. You can use it to create, update, and verify DNS settings for your MSP tenants, making it much easier to manage multiple partner environments through a single conversation.

**Will NetBird MCP make it easier to onboard new employees?**
Absolutely. You can ask your agent to generate invites, create user accounts, and assign roles in seconds, removing the need to manually click through admin dashboards.

**What kind of network resources can I manage with NetBird MCP?**
You can manage hosts, subnets, and domains. Your agent can help you provision these resources across your private infrastructure as your needs grow.

**Is NetBird MCP good for monitoring network traffic?**
Yes, it provides access to audit events and proxy logs. This allows you to see who is accessing what and identify any unusual activity on your network.

**Can I use NetBird MCP to set up custom routing rules?**
Yes. You can create and update policies that define exactly which protocols, ports, and sources are allowed to communicate with your network resources.

**How can I see all users currently registered in my NetBird network?**
You can use the `list_users` tool. It will return a complete list of users, including their IDs, roles, and current status.

**Is it possible to invite a new user to the network via AI?**
Yes! Use the `create_user_invite` tool to generate an invitation link, or `create_user` to invite a regular user directly by providing the necessary JSON payload.

**Can I manage pending user approvals through this integration?**
Absolutely. Use `approve_user` to grant access to a pending user or `reject_user` to deny their request using their specific User ID.