npm · ccu-mcp
CCU_HOST (required) — Hostname or IP of your HomeMatic CCU (debmatic, CCU3, or OpenCCU/RaspberryMatic)
CCU_PASSWORD (required) · secret — CCU admin password (same as the WebUI login). Must be set; the value may be empty for a CCU with no password
CCU_USER — CCU username
CCU_HTTPS — Connect to the CCU via HTTPS (self-signed certificates supported)
CCU_PORT — CCU API port (80 for HTTP, 443 for HTTPS)
CACHE_DIR — Directory for the device type cache and session persistence
MCP_ALLOWED_ORIGINS — Comma-separated allowlist of browser origins. Unset = no cross-origin browser access (default-deny). An allowlisted origin is reflected exactly in Access-Control-Allow-Origin (never '*'); the list also drives DNS-rebinding origin checks
MCP_ALLOWED_HOSTS — Extra Host header values accepted by DNS-rebinding protection (comma-separated host:port); add your hostname when behind a proxy or container DNS name
CCU_PROFILES — Comma-separated names of multiple CCU targets (e.g. 'prod,dev'). Each profile takes the flat CCU_* settings prefixed CCU_<NAME>_ (CCU_PROD_HOST, ...), plus policy flags CCU_<NAME>_PROTECTED (writes need confirm:true) and CCU_<NAME>_READONLY. Unset = single default profile from the flat CCU_* vars
CCU_DEFAULT_PROFILE — Which profile from CCU_PROFILES is active at startup (default: the first listed)
CCU_TLS_VERIFY — Verify the CCU's TLS certificate against the system trust store. Only meaningful with CCU_HTTPS=true. Default false, because a CCU ships a self-signed certificate — prefer CCU_TLS_FINGERPRINT or CCU_CA_CERT to verify one of those
CCU_TLS_FINGERPRINT — Pin the CCU's self-signed leaf certificate by its SHA-256 fingerprint (hex, colons optional). The strongest option for an appliance: the connection is rejected unless the presented certificate matches. Takes precedence over CCU_CA_CERT
CCU_CA_CERT — Path to a PEM file holding the CCU's CA or self-signed certificate. The connection is then validated against it with standard chain verification
CCU_TIMEOUT — Timeout for a CCU JSON-RPC call, in MILLISECONDS
CCU_SCRIPT_TIMEOUT — Timeout for HomeMatic Script execution (ReGa), in MILLISECONDS — scripts are slower than plain API calls
CACHE_TTL — Lifetime of the on-disk device-type schema cache, in SECONDS
CCU_RATE_LIMIT_BURST — Token-bucket burst size for CCU requests — how many may be issued back to back
CCU_RATE_LIMIT_RATE — Sustained CCU request rate, in requests per second
RESOURCE_POLL_INTERVAL — How often MCP resources are polled for change notifications, in SECONDS
LOG_LEVEL — error | warn | info | debug. Logs are structured JSON on stderr