The agent reads your NetBox, Nautobot, and live CLIs — read-only — and builds runnable labs from real data.
Describe a network — or point the agent at your NetBox — and get a running multi-vendor lab you can SSH into.
Trusted by network engineers worldwide
Three MCP connectors ship in the product — read-only by design, wired for the change-rehearsal loop.
The agent is granted an allow-list of read tools — exact names, never a wildcard. Write and delete tools are never attached.
The alternative
DIY agent wiring hands the model a full API token and hopes the system prompt says “don't write.”
NetBox/Nautobot records become a deployed multi-vendor lab you can SSH into — rehearse the change before production.
The alternative
Topology exporters hand you YAML to maintain; model-based twins can't run a single show command.
show-command access via Nornir with credentials brokered from your Nautobot at call time — NetPilot never stores them.
The alternative
Homegrown scripts with device passwords in env vars and nothing between the model and enable mode.
NetBox, Nautobot, and Nornir ship in-product on every plan. Any MCP-enabled tool connects on Signature & Enterprise.
The alternative
Point integrations cover one inventory tool; every new system in your stack means more glue code for your team.
Every connector exposes a curated, read-only tool surface to the agent — nothing more.
Speaks to the official read-only NetBox MCP server you host: devices, sites, prefixes, object search, and changelogs. Ask “what changed this week?” or “build a lab from site DC-East” — the agent reads the records and does the rest.
The full read surface of your Nautobot MCP server: devices, interfaces, racks, IPAM, circuits, tenants, GraphQL queries, and job logs. The mutating tools — create, update, delete, run-job — are never attached.
Live read-only CLI access to your real network: show commands only, enforced server-side. Inventory and credentials are brokered from your Nautobot at call time and executed in your environment — NetPilot never stores them.
These three are the starting point, not the list. With Signature & Enterprise, NetPilot connects to anything MCP-enabled — and every integration is custom-built to fit your workflow: if it has an API, NetPilot connects to it. Talk to us about your stack →
The agent turns source-of-truth data into a deployed, verifiable lab — and checks it against reality.
Devices, interfaces, prefixes, free IPs, changelogs — the agent queries your NetBox or Nautobot directly in chat and designs the matching topology from what's really there.
Per-vendor configs generated to match the deployed reality — then the lab boots on real network OSes (9+ and growing) you can SSH into and verify by hand.
Snapshot and diff lab state, spot-check the live network with read-only show commands, and catch drift between intended and actual before it bites a change window.
Ask in plain English — the agent picks the right read-only tools, and everything it builds is verifiable on real CLIs.
“Build a lab from my NetBox site DC-East” — the agent pulls devices, interfaces, and prefixes, then deploys a matching multi-vendor lab on real NOSes.
Free /28s, available IPs, VLAN and VRF lookups straight from Nautobot — asked and answered in the same chat that builds the lab.
Pull the affected segment from your source of truth, deploy the twin, apply the candidate change, and diff pre/post state — before production.
Compare intended state (NetBox/Nautobot records) against live state (show-command output) in one conversation and get the delta.
“Run show ip bgp summary on core-rtr-01” — Nornir executes read-only show commands with credentials brokered from your Nautobot, never stored.
“What changed in NetBox this week?” — the agent reads changelogs and job logs, without the ability to run or modify anything.
The honest comparison: exporter scripts and hand-wired MCP servers work — they just cost engineering time NetPilot spends for you.
Verdict:DIY wins for hands-on control and zero budget; NetPilot wins when the goal is rehearsing real changes from real data — connected, deployed, and validated in one conversation.
How teams connect their source of truth to NetPilot — safely
Rehearse BGP, ACL, and routing changes on a runnable mirror before production.
A twin you can actually run — built from your source of truth, real CLIs via SSH.
Two-way MCP, custom integrations, on-prem options, and founder-led onboarding.
Talk to us about wiring NetPilot into your stack — or add a NetBox, Nautobot, or Nornir connector yourself and ask the agent what's really in your network.
Bigger stack? Talk to us about custom MCP integrations