Welcome to DeviceShelf Server
This server continuously scans your local network…
- Devices appear below as they’re discovered.
- Set up alerts under Settings › Notifications.
| Status | Device | IP | MAC | Vendor | Ports | Response | Availability |
|---|
Active alarms
Current warnings and failures across built-in checks and custom monitors.
| Status | Monitor | Active since | Message | 30-day trend | Actions |
|---|
General
Server information
License
Already have a license? Enter its key here to activate this server.
Updates
Checks a single static version file on deviceshelf.app and compares locally — no identifiers are sent, and the server never installs anything by itself. When a newer version exists you get the exact upgrade command for your install.
Configuration backup
Export your settings + monitors as a JSON file (no secrets), or restore one. Restore replaces all monitors.
Access & sharing
API token
The token this dashboard and the API require. Change it here at runtime — no restart, no env file.
Connect your phone
Open the DeviceShelf app on your phone, tap “Add server”, and scan this code to add this server — no typing the address or token.
Public status page
Serve a read-only status page at /status (no login) so others can see overall health without access to the dashboard. Off by default.
AI assistant
AI provider
Configure the provider used by the assistant. The API key is stored locally as a protected secret and is never returned by the server.
AI assistant access (MCP)
Let an AI assistant such as Claude, ChatGPT or Codex read this server's live inventory, alarms and security findings over the Model Context Protocol. Nothing leaves this server until an assistant you connect asks for it — and it is off until you switch it on here.
Clients sign in with the API token from the Access & sharing section as a bearer token. Changes take effect at once — no restart.
Scanning & discovery
Scanning
Router & controller
Connect the router or network controller to enrich device names, clients, access points and switch ports.
Network & cross-subnet discovery
By default this collector only sees the LAN segment it sits on. To inventory devices on other subnets/VLANs, point it at your routers/switches via SNMP — it reads their ARP tables, no agent needed on those segments.
Server environment credentials currently override these saved values.
Credentials are stored encrypted and are never returned by the API. Leaving a saved secret blank keeps it unchanged.
Identification rules
Standing decisions for devices the scan cannot place by itself: when a signal matches, the device is filed as that type. A rule only fills what you have left empty, so it never overrules something you typed. Rules are tried in order and the first matching one decides the type; every matching rule may add tags.
Data sources
Proxmox VE connection
Connect with a read-only API token. The secret is stored locally and is never returned by the server.
Custom certificate authority
VMware vSphere connection
Names the ESXi host behind each VMware virtual machine. Works with vCenter and with a standalone ESXi. A read-only account is enough; the password is stored locally and is never returned by the server.
Synology Virtual Machine Manager
Identifies VMM guests by their MAC address and attributes them on a single-host NAS. The documented API does not expose VM placement in a multi-host cluster, so DeviceShelf does not guess there.
QNAP NAS & containers
Choose your QNAP. In Container Station, download the Docker certificate under Preferences → Certificates, then enter the extracted folder on this server. DeviceShelf will attribute Qnet/LAN containers automatically.
Proxmox overview contents
Controls the summary shown under Infrastructure › Proxmox VE › Overview. Detailed tabs remain available; cluster health and active alarms are always shown.
Alarm thresholds
Home Assistant
Publishes your devices to Home Assistant over MQTT. Home Assistant discovers them automatically — no add-on or custom component needed. Favorites and infrastructure (router, switches, NAS, printers) are exported by default; you can override this per device.
Topic prefixes
Only change these if your Home Assistant uses a non-standard MQTT discovery prefix.
Alerts & notifications
Alerts
Choose which events trigger a notification. They always appear in the timeline; these toggles control what gets pushed to your channels.
Notifications
Get alerted when devices join, come online or go offline. Add a channel below — no URL syntax needed.
Your channels
Advanced — edit raw Apprise / webhook URLs
External watchdog
Every alert above runs on this machine, so none of them can reach you when the machine itself is down. Paste a heartbeat URL from a monitoring service and DeviceShelf pings it regularly — when the pings stop, that service alerts you. This is how you learn about a power cut or a dead internet connection at home while you are away.
Works with Healthchecks.io, UptimeRobot (Heartbeat monitor), Better Stack, Cronitor and any self-hosted receiver. Set the grace period there to about three times the interval below. How to set it up →
DEVICESHELF_HEARTBEAT_URL is set — it overwrites this field on every restart.
E-mail notification
Sends alerts from one mailbox to any recipient(s). Only the sending account needs credentials (SMTP login + password); the recipients need none.
Sending account (SMTP)
Leave the SMTP server empty for common providers (Gmail, Yahoo, Outlook, iCloud …) — it is auto-detected. Those need an app password (not your normal one); for any other provider, fill it in. How it works →
Events from one scan cycle are bundled into a single e-mail, so a busy network never floods your inbox.
Alerts arriving inside the gap are held and delivered as one combined e-mail; push channels are never delayed.
Maintenance & quiet hours
Silence notifications during planned work or at night. Quiet hours and maintenance windows suppress all alerts, including recovery.
Maintenance windows
Weekly change report
Takes one snapshot of your network every night and sends a summary of what changed against the week before: devices that appeared, devices not seen for a week, and open ports that came or went. Snapshots stay on this machine; the summary goes to your configured notification channels.
The hour and the day follow the timezone set above.
Checks & monitors
Connectivity & expiry checks
Periodically verify your internet, DNS, TLS certificates and domains — alerts fire on failure or upcoming expiry. Each list is comma-separated; a check runs only when its list is filled.
What does “internet / WAN unreachable” mean — and will I be told?
The server periodically probes well-known internet endpoints (1.1.1.1, 8.8.8.8, 9.9.9.9). If none respond, your connection counts as down: one alert fires, plus a recovery alert when it returns. Whether that alert actually reaches you depends on where you are:
- 🏠 At home, phone on the same Wi-Fi, with a LAN channel (self-hosted ntfy): you get the alert instantly — it needs no internet.
- ☁️ Internet-based channels (Telegram, Discord, e-mail, ntfy.sh) cannot deliver while the internet is down — that one alert fails, and is not retried.
- 🚶 Away from home: no channel can reach you in real time during the outage — but you will get the “internet is back” recovery alert once it recovers.
- 🛰️ To be notified while away, add an external uptime monitor (e.g. UptimeRobot) that watches your connection from outside your network.
Host load (CPU / RAM / disk)
Watch CPU, memory and disk usage on SNMP-capable hosts (servers, NAS, hypervisors). Requires SNMP targets above and the host's SNMP agent (Host Resources MIB). An alert fires once a reading crosses its threshold and recovers when it drops back.
0 turns that alert off; leave a field empty for the default.
Internet connection record
The outage list needs nothing switched on — it comes from the connectivity check above. The two below reach outside your network, so each is its own decision.
A measurement moves real traffic over the line it is measuring. A failed attempt is recorded too, with its reason — a gap in the history cannot tell "the collector was off" from "the line was too broken to measure".
DHCP pool
Nothing on the network announces the range the router hands out, so this is the one address fact a scan cannot measure. Left empty, the range is worked out from the leases seen — enough to say a fixed address sits inside the pool, not enough to say how full it is, so the fill-level notice needs the real range here.
Monitors
Watch any metric — ping latency, TCP response time, an HTTP/REST value, or an SNMP OID — and get alerted when it crosses a warning or error threshold.
Add a monitor
Set “Error if above” to the max silence in seconds (e.g. 90). The monitor goes down when no ping arrives within that window. Save first to get the URL.
Thresholds (blank = ignore)
Security
Topology (L2)
Physical links from LLDP/CDP + bridge FDB. Needs SNMP-capable switches and credentials configured under Settings.
Diagnostics
On-demand network tools that run from the server itself.
Measures WAN throughput against Cloudflare (a few seconds).
Live bandwidth
Per-device throughput from live packet capture. Needs host networking and a capture-enabled build.
Addresses
Three things the scan already knows and nothing was saying: an address answered by two machines, how full the DHCP pool is, and addresses configured by hand inside that pool.
Measurements
Latest channels from custom traffic, protocol, REST, MQTT, SNTP and file monitors.
Host health (SNMP)
CPU, RAM, disk, temperature and fan readings from the last SNMP health sweep. Enable it under Settings › Host load and configure SNMP targets under Network & cross-subnet discovery.
Containers (Docker)
Containers from the local Docker Engine. Mount /var/run/docker.sock into the server container (read-only) or set DEVICESHELF_DOCKER.
Proxmox VE
Syslog
Inbound messages from routers/switches/APs. Enable with DEVICESHELF_SYSLOG_PORT.
SLA & Uptime
Uptime is computed from collected samples; periods when the server was offline are not counted.
Internet connection
Every episode the uplink was unreachable, with its date and how long it lasted. This is the list to attach to a support ticket — it is recorded from the connectivity check and needs nothing switched on.
| Started | Ended | Duration |
|---|
The same list as a document for the provider: period, every episode with its duration, the throughput measurements including the failed ones — and, stated on the page, what it cannot know (hours the collector itself was off are not outages).
Devices
Monitors
Daily availability
One bar per monitor; each segment is a day. Hover a segment for that day.
Monitor history
Each segment represents one day: green is stable, amber is degraded, red contains outages, grey has no measurements.
Export
Device inventory in your preferred format.
Device labels
A printable sheet of QR stickers, one per device. Scanned with the mobile app, a sticker opens that device — so the box on the shelf answers the question "which one is this?" without anyone tracing a cable.
The QR carries a code, not the MAC address: scanned by anyone else it resolves to nothing. The codes belong to this collector's data — restoring a backup keeps them working, a fresh install prints new ones.
Public status page
Enable a read-only public status page under Settings → Status page.
Open status pageThe year in review
Every completed day is folded into a handful of numbers and kept for years — long after the events, samples and outage lists it was worked out from have been pruned. It starts on the first full day this collector runs; there is nothing to reconstruct for the days before that.