D
Damira AI

Install the Plugin

Damira is a plugin for Cursor and Claude Code. Two steps, no signup. CCIE-level troubleshooting, upgrade planning, and config audit inside the AI you already use.

Damira is a plugin for Cursor and Claude Code. CCIE-level network ops inside the AI you already use — troubleshooting, upgrade planning, config audit — grounded in live vendor docs, release notes, and CVE data.

Your AI writes the MOP. Damira makes sure it's true.

Advisor mode is the default. Damira never touches your devices. A device gate blocks the agent from SSHing to network gear — even when every safety flag is off. It recommends the exact commands. You run them.

Install in Cursor — 60 seconds, no signup

agent plugin marketplace add https://github.com/ciscoittech/damira-plugins

Then Settings → Plugins (or type /plugins in the agent) and install damira. A shared demo key is built in — 50 queries a day.

Ask it something real:

Is CVE-2023-20198 being exploited, and how bad is it?
What's the IOS-XE configuration for BGP graceful restart?

Install in Claude Code

In Claude Code, add the marketplace and install the plugin:

/plugin marketplace add ciscoittech/damira-plugins
/plugin install damira@damira-plugins

When you enable the plugin, Claude Code asks for three settings:

  • API key — from Dashboard → API Keys. It's stored in your system keychain, not in a settings file. Leave it blank to try Damira on the shared demo key (50 queries a day). To add or change it later, see API key.
  • Execution mode — leave on advisor. Damira recommends the exact commands and you run them. guided and lab let the agent run read-only show commands itself and are meant for lab gear only.
  • Shell device gate — ask (the default) hands you any ssh, telnet, or nc the agent wants to run, since not every host is network gear. strict blocks them outright.

Verify it works: start a new session and ask a network question. The first time each Damira tool runs, Claude Code asks for permission — choose always-allow and it won't ask again.

my OSPF adjacency is stuck in EXSTART between a 4451 and a Nexus 9k

You should get a ranked diagnosis with the exact commands to run, not "check the config."

Set up a project: run /damira:init once in a new project folder. It asks which vendors, platforms, and versions you run and how changes get approved, then creates configs/ (kept out of version control, since configs carry secrets), documents/, and notes/, and records your network in CLAUDE.md so every session starts with that context.

Prerequisites: Python 3 (python3 --version). No pip, no uvx — everything runs on the standard library.

Claude Desktop and other MCP clients

Cursor and Claude Code are above. These are the other install paths.

macOS — one command writes the config for you and keeps any servers you already have:

git clone https://github.com/ciscoittech/damira-plugins ~/.damira/damira-plugins
python3 ~/.damira/damira-plugins/damira-cursor/scripts/damira.py install-mcp --target claude-desktop

Windows / Linux — add this to your Claude Desktop config (%APPDATA%\Claude\claude_desktop_config.json or ~/.config/Claude/claude_desktop_config.json), using the absolute path to where you cloned it:

{
  "mcpServers": {
    "damira": {
      "command": "python3",
      "args": ["/Users/you/.damira/damira-plugins/damira-cursor/mcp/server.py"],
      "env": {
        "DAMIRA_API_KEY": "oncall_sk_your_key_here"
      }
    }
  }
}

Restart Claude Desktop to load the server. Leave DAMIRA_API_KEY out to use the shared demo key (50 queries/day).

Prerequisites: git and Python 3.9+. No pip, no uv — the server is a single standard-library script.

API key

The demo key is for kicking the tires: 50 queries a day, and every answer on it starts with a note saying so. For real use, get your own key:

  1. Sign up at damiraai.com (free, no credit card) and verify your email.
  2. Open Dashboard → API Keys. A Default Key is already there, or choose Create Key.
  3. Copy the key. It starts with oncall_sk_.

Set it

Where you use DamiraHow to set the key
Claude CodeRun /plugin configure damira@damira-plugins, paste the key into API key, and continue through every field until it confirms the save. It's stored in your system keychain.
Claude Code, scriptedclaude plugin install damira@damira-plugins --config api_key=oncall_sk_… stores the key the same way. The key lands in your shell history, so clear it afterwards.
CursorAdd export DAMIRA_API_KEY="oncall_sk_…" to ~/.zshrc or ~/.bashrc, then restart Cursor so it picks up the variable.
Claude Desktop, Windsurf, other MCP clientsPut DAMIRA_API_KEY in the server's env block (see the tabs above) and restart the client.
Any of themWrite the key to ~/.damira/config (one line: api_key = oncall_sk_…). This is the fallback when nothing else sets a key.

If more than one is set, Damira uses the first it finds:

  1. The Claude Code plugin setting
  2. The DAMIRA_API_KEY environment variable
  3. ~/.damira/config
  4. The shared demo key

In Claude Code before plugin version 0.2.6, an exported DAMIRA_API_KEY is ignored whenever the plugin setting is blank. Update the plugin, or set the key with /plugin configure.

Check which key you're on

  • Every answer served on the demo key starts with [Damira is running on the shared demo key (50 queries/day)…]. If you see that after adding your key, the key isn't reaching Damira.
  • Cursor and the terminal: run ~/.damira/bin/damira whoami. It prints the masked key and where it came from. In Claude Code, the plugin setting is only visible to the plugin itself, so use the answer note instead.
  • Dashboard → API Keys shows when each key was last used.

Change or rotate a key

Create a new key in the dashboard, set it the same way you set the first one, then revoke the old key. In Claude Code, running /plugin configure damira@damira-plugins again replaces the stored key.

If your key isn't taking

What you seeWhat to do
Answers still carry the demo-key noteIn Claude Code, run /plugin configure damira@damira-plugins again and continue until it confirms the save. Make sure you're on 0.2.6 or later: /plugin marketplace update damira-plugins, then update damira. In Cursor, restart it from a shell where echo $DAMIRA_API_KEY prints the key.
invalid API keyThe key was revoked or mistyped. Copy it again from the dashboard.
rate limit exceededYou've hit your plan's daily or per-minute limit. The error says which; wait, or upgrade.

Never commit API keys to source control. Use the plugin setting, environment variables, or your client's secret management.

Get your free API key →

What you get

Shipped as skills in the Cursor and Claude Code plugins, and available as MCP tools everywhere else:

SkillWhat it does
TroubleshootStructured diagnosis with ranked root causes and vendor-specific CLI
Upgrade planAssessment from real release notes and CVE data — plus MOP and change control templates
Config auditRuns on your machine. Your configs never leave it
Generate configDevice configuration for Cisco, Juniper, Arista, Palo Alto, and Fortinet
Generate playbookAnsible playbooks for network automation
Generate workbookExcel workbook (.xlsx) with an HTML preview for a migration, audit, or change record
Generate diagramTopology diagram — SVG, HTML preview, Mermaid, D2, optional PowerPoint
Terraform, automation, pipelines, testsInfrastructure as code, Python scripts, CI/CD pipelines, and pyATS/pytest tests, each validated locally — see Automation & Generators
Generate labContainerLab topologies to rehearse a change before the window (Cursor)

Damira supplies the domain data — vendor docs, CVE lookups, version-specific caveats, structured diagnoses. Your AI assembles that into the deliverables your change process actually requires.

Platforms: Cisco (IOS/NX-OS and CUCM), Juniper Junos, Arista EOS, Palo Alto PAN-OS, Fortinet FortiOS.

Full tool reference: MCP Server.

On this page