Network scanner for macOS, Windows and Linux

Everything worth knowing
about your network devices.

IP address, hostname, vendor, device type, open ports, availability and risks. Detected automatically and laid out in one place.

No credit card, no account, everything stays on your machine. One payment of €59, no subscription.

  • Click a device and see its IP address, name, services and history so far.
  • Search the whole inventory by IP address, name or vendor.
  • DeviceShelf identifies unknown devices from their network signals.
  • Check open services, risks and what has changed since last time.

macOS · Windows · Linux · iOS · Android · Server 24/7 · MCP for AI agents

DeviceShelf

Included: desktop app, mobile apps and 24/7 server edition · one license covers them all

App and dashboard in English, German, French, Spanish, Italian, Arabic and Chinese — screenshots shown in English.

The information exists. Just not in one place.

What you want to know is spread across four tools.

The router page for the lease, a terminal for arp, a lookup site for the vendor, a scanner for the ports. Four places, one device.

The router gives you an IP and a MAC, and no context at all.

android-8f2c at 192.168.1.31 tells you nothing about whether it is the robot vacuum, the doorbell or something that is not yours.

Services, reachability and history are never visible together.

None of those tools tells you whether a service was already open last week, or when the device was last reachable.

DeviceShelf brings that information together in one view, locally on your machine. Scan once, and it keeps the record from there.

Try free for 7 days No credit card, no account, everything stays on your machine. One payment of €59, no subscription.

Demo

Try it before you download.

A live dashboard you can click through, and a one-minute tour of the whole app.

The DeviceShelf Server dashboard of the demo network: device table, rankings and timeline

Live demo

The server dashboard on a fictional network of 45 devices. Open a device, read the timeline, work through the security findings. It resets every hour and keeps nothing you enter.

Open the live demo

Guided tour

One minute through scan, identification, vulnerabilities, bandwidth, monitoring and the server edition, with captions.

Try free for 7 days One payment of €59. No subscription, no per-device fee.

Watch it work

Your first scan, from the app itself.

Scan

One click, the whole network.

Hit Scan and the list fills in front of you: every device that answers, named, typed and sorted, with its open ports right there in the row.

Identify

Know what that thing is.

An unknown box on .99? The device drawer gathers its signals, and your own AI key turns them into a name, a role and the reasoning behind both.

Secure

See the risk before it bites.

The vulnerability check reads service banners and versions, matches known CVEs and hands you a plain-language fix for each finding.

Watch

Live bandwidth, per device.

Down in green, up in purple: the bars move as your network does, and the streamer, the backup job and the stuck update give themselves away.

History

How stable is that thing, really?

Open a device and its record is right there: availability over 30 days, the latency curve, and every outage with start, end and duration.

Recorded in the app, on a demo network.

Try free for 7 days Then €59 once. No subscription, no per-device fee.

More of the app. Click to enlarge.

Event timeline in DeviceShelf
Event timeline A full timeline of everything that changed (devices on and offline, ports opening and closing), with snapshot comparison.
Device detail in DeviceShelf
Device detail A deep dive on any device: vendor, all hostnames, OS guess, response time, CVE hints and one-click connect (SSH, VNC, SMB…).
Security report in DeviceShelf
Security report A prioritized security report: risk score, exposed risky services, default-credential checks and an AI security advisor with concrete fixes.
Network overview in DeviceShelf
Network overview Your network at a glance: subnets, gateway, DNS and WAN details, with live status for every interface.
Try free for 7 days Then €59 once. No subscription, no per-device fee.

Built for AI agents · MCP

An MCP server for your AI agent.

The 24/7 server edition speaks the Model Context Protocol. Connect Claude, Cursor, VS Code, Windsurf, Cline or Gemini CLI and ask in plain language: what is on the network, what changed overnight, why the NAS does not answer, which disk fills up first. 37 tools answer from your own scan data, on your own machine.

  • Inventory, alarms, uptime, topology, syslog, Docker, Proxmox and NAS health, each one a tool the model can call
  • A risk score with the findings behind it, seven days of CPU, memory and disk history, and an estimate of when a disk runs full
  • Troubleshooting on request: ping, DNS, traceroute, TLS grade, SSH host key and Wake-on-LAN, limited to hosts on your own subnet and only after you switch actions on
  • Strictly local: the endpoint runs inside your server, behind your token, and is reachable on your LAN only

Included in every license and in the 7-day trial. Off by default, read-only unless you allow actions.

AI, optional

Ask AI about
your real scan data.

Stuck on a device that's just a MAC address and an open port? Let AI name it from the network signals. Get a plain-language digest of your whole network, ask what's risky and why, and turn the security findings into step-by-step fixes. Everything is grounded in your real scan data, not in a generic checklist.

  • Identify unknown devices from their network fingerprint
  • Natural-language digest of your whole network
  • Security advice & concrete remediation steps
  • Grounded chat: ask questions about your scan
  • Server edition: plug Claude, Cursor or any AI agent into your live network via the built-in MCP server, 37 tools

You bring your own key, and AI is entirely optional. Your prompts never touch our servers; they go directly from your device to the provider you picked. Prefer fully offline? Run a local model with Ollama.

The instruction text of every AI feature is yours to rewrite, and 25 switches decide what goes out about a device. Turn them all off and nothing about a device leaves the machine.

Supported AI providers

Anthropic Claude · you provide the API key
OpenAI GPT-4 / GPT-5 · you provide the API key
OpenRouter 300+ models · you provide the API key
Mistral EU-hosted · you provide the API key
Groq Fast inference · you provide the API key
Google Gemini Gemini 1.5 / 2 · you provide the API key
Azure OpenAI Microsoft-hosted GPT · you provide the API key
Ollama Fully local · no API key, no network

You are not tied to one AI provider. Switch any time in the settings.

Private by default

What the scan finds stays on your device.

A scan lists every device in your home or office, which is nothing to hand around. DeviceShelf keeps it on your device. Nothing leaves unless you switch on a cloud feature yourself.

Local-first by design

Every scan result is stored locally on your device. There is no DeviceShelf cloud and no central database. Your scan data is not uploaded anywhere.

Install, scan, stay local

You can run DeviceShelf without creating a profile. Purchases are tied to the buyer email for licensing, while scan data stays on the device that collected it.

Zero telemetry

No analytics, no phone-home, no anonymous metrics. The app does not report what you scan, what you find, or that you opened it.

Offline ed25519 license check

Your license is verified locally with an ed25519 signature. There's no license server, no online activation, no check-in. It keeps working even fully offline.

Opt-in outbound only

Data leaves only when you turn a feature on or run an online tool: AI (to your provider), Fingerbank lookup, WAN-IP info, speed test and hop geolocation (Cloudflare & RIPE NCC), or webhooks you configure. Everything is off by default and clearly labeled.

Lightweight, read-only scans

Default scans are non-intrusive TCP-connect probes: they observe, they don't attack. You control depth and timing, from a quick sweep to a full deep scan.

Device recognition

Recognizes the things on your network.

DeviceShelf combines many signals to label each device with a type and a best guess at what it is: MAC vendor (OUI), DNS, mDNS/Bonjour, NetBIOS, SNMP, UPnP, TTL, DHCP fingerprint and open-port profiles.

🌐 Router / Gateway
💻 Computer
📱 Phone / Tablet
🖨 Printer
📷 Camera
💾 NAS
📺 TV / Streaming
🔊 Smart speaker
🎮 Game console
💡 Smart home / IoT
🖥 Server
❓ Unknown → ask AI

Desktop and pocket

The full scanner, on your phone too.

iOS on the App Store · Android direct download

The iOS and Android apps run the same scanning engine as the desktop, not a watered-down companion build. Walk around the house or office and scan from where you stand. One license covers every device you own.

iOS & Android

Scan from the room you're in.

The mobile apps use the same scanning engine as desktop, so you can inspect a friend's Wi-Fi, an office network or a hotel LAN from the device in your hand.

  • Full network scan & device identification on-device
  • Security report and open-port view on the go
  • An alert when an unknown device shows up on your Wi-Fi
  • Export and share a report straight from your phone

A direct download, and that's how we ship it. We're not putting DeviceShelf on Google Play: for a local-first tool, the store's review hurdles and Google's grip on Android aren't a trade worth making. It's the same signed app: a 7-day free trial, then activate your license key.

Direct downloads like this one are under threat: starting in September 2026, Google plans to block Android apps from unverified developers. Learn more at keepandroidopen.org

Auto-updates, no store needed. Want the app to update itself? Add DeviceShelf to Obtainium. It watches the direct download and installs new versions for you, with no store account and no tracking. Add to Obtainium

How to install
  1. Tap Download. Your browser asks once to allow installing apps. Tap Allow.
  2. Open the downloaded DeviceShelf .apk file.
  3. Tap Install. That's it.

Desktop, pocket, server

The full scanner, running 24/7.

A headless server edition runs the same engine continuously in Docker, as a Debian/Ubuntu package, on macOS, or as a Windows service. It keeps watching the networks you care about and alerts you the moment something changes. Covered by your existing license.

Self-hosted monitor Inventory, uptime, alerts and reports from one always-on collector.
Live device inventory Continuous LAN scans with vendors, hostnames, device types, open ports, response times and change history.
Infrastructure health SNMP CPU/RAM/disk, temperature and fan readings, plus Docker containers, Proxmox nodes/guests and NAS RAID health.
Checks and heartbeats Ping, TCP, HTTP, SNMP, database probes and push monitors for cron jobs, backups and small services.
Actionable alerts Email/SMTP, ntfy, Gotify and webhooks with quiet hours, maintenance windows, dependencies and digest batching.
Reports and status Uptime %, daily availability bars, a year-in-review report, CSV export, printable QR labels for every device and an optional public read-only status page.
API, Prometheus and MCP Script it through REST, scrape `/metrics`, or let a local AI agent answer questions from the live inventory.

The desktop and mobile apps pair with the server and show its devices, history and alarms in their own interface. The server collects around the clock, and you read it in the app.

After start, open the dashboard on your LAN, paste the auto-generated token and configure scans, checks and alerts in the browser. New to the server edition? See the server guide.

Server edition included Run DeviceShelf as a self-hosted, always-on monitor with Docker, .deb or Windows service support. Open the server guide for installation, tokens, alerts and MCP setup.

Try free for 7 days Then €59 once. No subscription, no per-device fee.

Features

Scan, identify, monitor.

DeviceShelf starts with a read-only LAN scan, enriches each device with names and signals, then turns the result into monitoring, reports and practical security findings.

🔍

One-click network scan

Point it at your Wi-Fi or LAN and hit scan. A fast, read-only TCP-connect sweep finds every responding device in seconds and keeps the list fresh on every rescan. It needs no setup, no agents, no router login. It also flags what a plain list hides: two devices on one IP address, a DHCP pool running full, and a fixed address sitting inside that pool.

🔀

Scan every interface at once

Multi-homed? Select several adapters (Wi-Fi, Ethernet, VLANs) and DeviceShelf sweeps them all into one merged device list. A “show all adapters” toggle surfaces the interfaces other scanners hide: VPN, VirtualBox, Hyper-V and Docker bridges.

🧬

Deep device identification

DeviceShelf resolves the vendor (MAC OUI), hostname (DNS, mDNS/Bonjour, NetBIOS), OS (TTL, DHCP fingerprint) and device type automatically: router, computer, phone, printer, camera, NAS, IoT.

🛡

Built-in security report

A prioritized risk report for the whole network: exposed dangerous services (Telnet, RDP, ADB, Docker API, Redis…), default-credential checks, weak TLS, known-CVE hints and camera/privacy flags, each with a fix and a 0–100 risk score.

🔌

Open ports & services

Per device, enumerate open TCP/UDP ports with service detection and banner grabbing. Quick, Standard, Deep (1–1024) and Full (1–65535) profiles, plus slow/normal/aggressive timing; you decide between thorough and fast.

📈

Presence monitoring & alerts

Background polling tracks which devices come and go and notifies you when an unknown device shows up on your Wi-Fi. Availability history with uptime and latency per device, perfect for spotting intruders or flaky gear. Alerts reach you by e-mail, push or webhook and respect quiet hours and maintenance windows. The same checks watch your internet uplink, DNS names, TLS certificates and domain registrations, and warn before something runs out.

📊

Per-device bandwidth

See live throughput per device so you can tell what's actually using the line right now. Find the streaming box, the backup that's saturating the uplink, or the chatty IoT gadget at a glance.

How to enable live bandwidth →

🔬

Deep probes

Go further on any device: TLS grading and certificate inspection, SSH key fingerprinting, SMB share enumeration, UPnP model/serial, SNMP system info and nmap-style HTTP enumeration of common admin paths.

🗺️

Physical topology map

See the real layout, not just a list. DeviceShelf reads LLDP/CDP and the switch bridge table over SNMP to map which device hangs off which switch port, and draws the links between your routers and switches.

🪵

Built-in syslog server

Point your routers, switches and access points at DeviceShelf and read their logs in-app: a local syslog receiver (UDP/TCP, RFC 3164/5424). There's no cloud collector; the logs never leave your LAN.

🧰

Diagnostics toolbox

Ping with aggregate stats, streaming traceroute, DNS lookups, a connectivity health check and a built-in speed test (latency, download, upload). Everyday network tools, without opening four other apps.

Wake-on-LAN

Power on compatible machines straight from the device list with a single tap. Great for waking a NAS, a desktop or a media server without getting up.

📤

Export & shareable reports

Export the device list to JSON or CSV, or generate a styled, shareable HTML report. Add custom names, notes and type overrides per device; they persist across scans. An optional local API and webhooks let you wire DeviceShelf into your own tooling.

🏷️

Asset register & QR labels

Every device carries its purchase date, warranty end, serial number and location, synced between the desktop app and the server. DeviceShelf warns a chosen number of days before a warranty runs out. Print a sheet of QR labels, stick one on each box, and a scan with the phone app opens exactly that device. The code holds no MAC address, only an opaque id.

🤖

MCP server for your AI

The 24/7 server edition speaks the Model Context Protocol: connect Claude, Cursor or any MCP client and ask about your network in plain language: “what changed overnight?”, “why can’t I reach the NAS?”, “which disk fills up first?”. 37 tools, strictly local, read-only unless you allow actions.

Connect your AI agent →

✍️

The AI prompts are yours

Every AI feature's instruction text can be rewritten in Settings, in any language, and one click puts our version back. Under it sits every signal that can go out about a device — 25 of them, each with a switch and the value your device would actually send. Switch them all off and nothing about a device leaves the machine. A preview shows the exact request before it goes.

🔒

Local-first & private

Scans, notes and reports stay on your device. The license is verified offline with an ed25519 signature, so normal use does not depend on a DeviceShelf cloud account or activation server.

Pricing

Buy once. Use v1 forever.

One personal license for the buyer email used at checkout: install it on every device that user owns, including desktop, iOS, Android and the server edition. DeviceShelf is a one-time purchase instead of a monthly scanner subscription. Your v1 copy keeps receiving free 1.x updates for as long as the operating systems allow; a future v2 would be an optional paid upgrade. AI runs on your own provider key. The price does not depend on how many devices are on your network. Nine or nine hundred cost the same.

Good to know: DeviceShelf scans the local network the device is connected to. Run it on the Wi-Fi/LAN you want to inspect. Only scan networks you own or are allowed to scan.

Best value

Shelf Bundle

€89 once

DeviceShelf + ServerShelf, once, incl. VAT.

The local infrastructure bundle: map the network, then manage the servers behind it.

For homelabs and small teams that own both the LAN and the machines running on it.

  • ✓ DeviceShelf: LAN devices, ports, topology and security report
  • ✓ ServerShelf: SSH inventory, updates, Docker, TLS/Uptime and AI log triage
  • ✓ Local-first apps: no account, no telemetry, no subscription
  • ✓ 1 registered user, bound to the checkout email, for both apps
  • ✓ 7-day DeviceShelf trial included
Get the bundle for €89

14-day money-back guarantee. No subscription, ever.

See ServerShelf ↗

Company or MSP missing a specific feature? Business & sponsored features

Honest expectations

What DeviceShelf is and isn't.

Please read this before you buy. It saves both of us a refund.

What it is

  • A universal network scanner that discovers every device on the LAN/Wi-Fi you're connected to.
  • A device identifier: vendor, hostname, OS and type from many combined signals.
  • A port scanner with service detection and configurable scan profiles.
  • A security report with risk scoring, exposed-service and default-credential checks and CVE hints.
  • A monitor that watches for new devices and tracks presence and bandwidth.
  • An optional AI assistant that names unknown devices and explains the risks (bring your own key).
  • A 24/7 server edition that runs headless on Linux/Windows/Docker for always-on monitoring, covered by the same license.

What it isn't

  • Not a cloud service: there's no account and nothing is uploaded; it all runs on your device.
  • Not a WAN/internet scanner: it maps the local network you're on, not the public internet.
  • Not a penetration-testing or exploit tool: it observes and reports, it doesn't attack devices.
  • Not a full 24/7 IDS/SIEM like a dedicated security appliance: monitoring is poll-based.
  • Not a router replacement: it doesn't change your network config; it tells you what's on it.
  • Not compliance-certified: we make privacy claims and document them, but hold no SOC2 / ISO 27001 audit.

⚙ Requirements

  • Desktop: macOS 12+, Windows 10 or 11, or a modern Linux. Small download, light on RAM.
  • Mobile: iOS 15+ or Android 7.0+. Connect to the Wi-Fi you want to scan.
  • Network: just be connected to the LAN/Wi-Fi you want to inspect; no router login, no config changes.
  • AI features (optional): an API key from Anthropic, OpenAI, Azure OpenAI, OpenRouter, Mistral, Groq or Gemini, or run Ollama locally. No key means no AI; everything else still works.
  • Bandwidth monitoring: on desktop, live per-device throughput may need elevated privileges.

See full platform support →

Frequently asked

What people ask before buying.

There's an unknown device on my Wi-Fi. What now?

Find out what it is first. For every IP, DeviceShelf shows the vendor behind the MAC address, the hostname, the device type and the open ports. More often than not the intruder turns out to be a printer, a robot vacuum or a TV. If it stays unclear, the AI names it from its network signals. And if it really does not belong: change the Wi-Fi password, rescan, and leave monitoring on so you catch it immediately next time.

Where is my scan data stored?

Locally, on the device that ran the scan. There is no DeviceShelf cloud and no account, so your scan data never gets uploaded anywhere. You can export it yourself to JSON, CSV or an HTML report whenever you like.

Does DeviceShelf send my data anywhere?

No scan data leaves your device by default. DeviceShelf only sends scan traffic on your local network; nothing goes to the internet unless you explicitly use an online feature: AI (to the provider whose key you supplied), Fingerbank device lookups (fingerbank.org), WAN-IP info and the built-in speed test (Cloudflare), IP geolocation for WAN info and traceroute hops (stat.ripe.net, RIPE NCC), or webhooks you configure yourself. No analytics, no phone-home, no telemetry.

Is scanning my network safe and allowed?

Scanning a network you own or administer is completely normal, and DeviceShelf's default scans are lightweight, read-only TCP-connect probes: they observe rather than attack. Only scan networks you have permission to scan.

How does DeviceShelf compare to Fing?

DeviceShelf is built for users who prefer a local-first desktop and mobile scanner without an account, telemetry or subscription. Fing offers its own app ecosystem and subscription plans; DeviceShelf focuses on local network visibility, offline licensing and one-time pricing.

Can I bring my own AI key?

Yes, and AI is entirely optional: the scanner works fully without it. Drop in your Anthropic / OpenAI / Azure OpenAI / OpenRouter / Mistral / Groq / Gemini key, or run Ollama locally for fully offline AI. Your prompts always go directly from your device to your chosen provider.

Can I connect my AI assistant (Claude, Cursor, …)?

Yes: the 24/7 server edition (from 1.5.3) includes a local MCP server. Any MCP-capable client (Claude Desktop & Code, Cursor, VS Code, Windsurf, Cline, Gemini CLI) can query your live inventory, alarms, risk score, uptime and infrastructure history, 37 tools in total. If you allow actions it can also run ping, DNS and traceroute, grade a device’s TLS, read its SSH host key and wake a machine, always limited to your own subnet. Strictly local, off by default, and included in every paid license. See the connection guide.

How many devices can I install on?

One license = one registered user. The license is personal to the buyer and bound to the email address used at checkout; it may not be shared between multiple people. That user can use the same key on every Mac, PC, Linux box, iPhone and Android device they own.

Is there a free trial?

Yes: a 7-day free trial with full features, no credit card required. After that it's a one-time €59 purchase. No subscription, ever.

Will my version keep getting updates?

Yes. Your purchase is yours to keep; there's no subscription and nothing to renew. v1 keeps improving: every 1.x update brings new features and fixes, free of charge, and we'll keep delivering them for as long as the operating systems allow. No software runs on every future OS forever, but we plan to support v1 for a long time. There's no upgrade treadmill: a future v2 would be a major new generation, years away, and an entirely optional paid upgrade — and you can keep using your v1 either way.

Refund policy?

14 days, money-back, no questions asked. Email hello@deviceshelf.app from the address you bought with.

Which platforms are supported?

Desktop: macOS, Windows and Linux are available now. Mobile: iOS is on the App Store, and Android is available as a direct APK download. The same scanning engine runs across platforms, and your single license covers desktop, mobile and server edition.

Can I run DeviceShelf 24/7 on a server?

Yes: the headless server edition is part of DeviceShelf. It runs continuous, always-on monitoring without a GUI in Docker, via .deb, or on Windows Server / Windows 11 for networks you want watched around the clock. It is covered by your existing license: same key, no extra cost.

Can the desktop app show what the server sees?

Yes. The desktop and mobile apps can pair with a server edition and show its data instead of, or next to, their own scan. In the desktop app open Remote servers, press Discover (a server on the same network is found automatically) and paste the server's API token. Then pick the server in the source selector above the device list: Server devices only or Server + local devices. Devices, history, alarms, checks, monitoring, health, Docker and topology come across, and alarms can be acknowledged from there. Devices reported by a server are read-only in the app: wake, port scan and connect stay with the local scan, because they would run from your computer rather than from the server. If the server should be the only scanner, switch off Auto-scan in the desktop settings. Details in the server guide.

Can you build a custom feature for my company?

Yes. For teams, MSPs and privacy-conscious businesses we take on sponsored feature development: custom reports, deployment options, integrations and offline-licensing scenarios. It stays local-first, with no telemetry and no hidden cloud. See the Business & sponsored features page, or email hello@deviceshelf.app.

Weighing your options? Compare DeviceShelf with Fing, LanScan Pro, Advanced IP Scanner & Angry IP Scanner →

Need 24/7 monitoring? Compare DeviceShelf Server with Uptime Kuma, PRTG & Zabbix →

Talk to us

Questions, bugs or business?

We read every message and usually reply within a working day. For technical bugs, Help → Send feedback inside the app attaches useful context automatically. For everything else, use the form below.

Or email hello@deviceshelf.app directly.

Shelf Bundle

One view for the network. One cockpit for the servers.

DeviceShelf finds every device on your LAN. ServerShelf shows what runs on the machines you manage: SSH inventory, updates, Docker, certificates, uptime and AI log triage.