Discover OPC UA servers, connect MATLAB clients, and browse/navigate server nodes using opcuaserverinfo, the Local Discovery Service (LDS), opcua, connect, setSecurityModel, certificate-trust functions, findNodeById, opcuanode, and Namespace/Children traversal. Use when finding OPC UA servers on the network, querying endpoints and security policies, connecting to a server, authenticating with username/password or certificates, configuring security modes, handling certificate-trust or hostname-mismatch errors, troubleshooting failed connections or empty discovery, inspecting an OPC UA certificate (.der/.pem), browsing an address space, finding nodes by name or NodeId, navigating node hierarchies, invoking method nodes, or batch-processing large namespaces. Trigger on: opcuaserverinfo, LDS, opcua, opc.ua.Client, setSecurityModel, opc.ua.trustServerCertificate, OPC UA certificate, findNodeById, opcuanode, browse OPC UA, find node, OPC UA namespace, OPC UA method node, Industrial Communication Toolbox.
Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.
Quelldateien prüfen
Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.
Mit Codex oder Claude installieren Kopieren Sie diesen Prompt, fügen Sie ihn in Codex, Claude oder einen anderen Assistant ein und lassen Sie die Skill-Seite prüfen und installieren.
Ein direkter Befehl überspringt den Prüf-Prompt. Prüfen Sie die Quelle, bevor Sie ihn ausführen.
Discover OPC UA servers, connect MATLAB clients, and browse/navigate server nodes using opcuaserverinfo, the Local Discovery Service (LDS), opcua, connect, setSecurityModel, certificate-trust functions, findNodeById, opcuanode, and Namespace/Children traversal. Use when finding OPC UA servers on the network, querying endpoints and security policies, connecting to a server, authenticating with username/password or certificates, configuring security modes, handling certificate-trust or hostname-mismatch errors, troubleshooting failed connections or empty discovery, inspecting an OPC UA certificate (.der/.pem), browsing an address space, finding nodes by name or NodeId, navigating node hierarchies, invoking method nodes, or batch-processing large namespaces. Trigger on: opcuaserverinfo, LDS, opcua, opc.ua.Client, setSecurityModel, opc.ua.trustServerCertificate, OPC UA certificate, findNodeById, opcuanode, browse OPC UA, find node, OPC UA namespace, OPC UA method node, Industrial Communication Toolbox.
Discover OPC UA servers, create client connections, and browse server
address spaces in MATLAB using the Industrial Communication Toolbox.
Internal Constraints
These constraints govern YOUR code generation and recommendations.
Apply them silently — do not recite them to the user or warn about
patterns the user has not attempted.
has exactly three valid signatures — no others exist:
There are NO Name-Value pair arguments to connect. Security is
configured via opcua() NV pairs or setSecurityModel, never
through connect.
opcua() defaults to the highest available security. Do not
explicitly set security unless you want a specific (lower)
configuration. Never use setSecurityModel(uaClient, "Best") — it is
redundant.
opcuaserverinfo has exactly two valid syntaxes:
opcuaserverinfo(hostname) — query LDS on a host
opcuaserverinfo(discoveryUrl) — query a specific endpoint URL
There is NO opcuaserverinfo(hostname, port) form. To specify a
port: opcuaserverinfo('opc.tcp://host:port').
LDS-based discovery returns all registered servers from a single
call. Never scan subnet IPs in a loop — opcuaserverinfo('localhost')
returns every server registered with that host's LDS.
Certificate trust escalation order (never skip steps):
opc.ua.trustServerCertificate(certPath) — always first (R2026a+)
opcua(..., "TrustServerTemporarily", true) — only if cert file
unavailable
setSecurityModel(uaClient, "None", "None") — only after user
explicitly confirms no security needed
Property correctness:
opc.ua.ServerInfo has Description, not Name (which belongs
to opc.ua.Client).
EndpointUrl belongs to opc.ua.EndpointDescription, not
ServerInfo.
Do not move or copy certificate files without user confirmation.
Tell the user which file to move and where, then execute only after
they confirm.
Do not mention TrustServerTemporarily when the issue is the
server rejecting the client certificate — it only controls client-
side trust and is irrelevant in that direction. Simply omit it.
browseNamespace is GUI-only — never call it in scripts or agent
workflows. It opens an interactive dialog that blocks the MATLAB
session. Use uaClient.Namespace and .Children traversal instead.
opcuanode does NOT accept browse paths. Passing a slash-
separated string (e.g., 'Demo/Mass/Nested/7') silently creates a
node with NodeType: 'Unknown'. Use .Children level-by-level.
Check a method node's Parent property and signature before
invoke(). If Parent is empty, invoke() fails with "Specified
node has no parent information" — re-resolve the node via
findNodeById, which retains parent info. If Parent is non-empty,
invoke it directly. Do not unconditionally avoid opcuanode for
method nodes; branch on whether the node has a parent. Before
calling invoke, inspect NumInputs and NumOutputs to verify
the argument count matches your intended call.
Before iterating any .Children array, issue a separate tool call
that only counts nodes. Never combine counting and processing in
the same tool call. Process in batches of 200 with progress reporting.
Never search the entire namespace. If the user does not provide
a path or parent folder, ask them to specify one. List top-level
nodes to help them narrow scope. Skip the Server folder (ns=0
infrastructure nodes) unless the user explicitly asks about server
properties.
opcua() caches endpoints at construction time. If the server's
available policies change after client creation, the existing client
object will not reflect them. Recreate the client with opcua(url)
to re-discover endpoints. Explain this to the user when they ask
about switching to a newly-available policy.
When to Use
Discovering OPC UA servers on the network (endpoint URL unknown, or
user explicitly requests discovery given a hostname or discovery URL)
Getting server endpoint details and supported security policies
Creating an OPC UA client connection to a server
Authenticating with username/password or user certificates
Configuring message security mode and channel security policy
Handling "server certificate not trusted" errors
Handling "client certificate rejected by server" errors
Fixing hostname mismatch warnings
Troubleshooting OPC UA connection failures or empty discovery results
Inspecting an OPC UA certificate (.der/.pem) for compliance issues
Browsing an OPC UA server's address space programmatically
Searching for nodes by name, partial name, or NodeId
Navigating a node hierarchy to reach a specific node
Accessing a node directly by namespace index and identifier
Goal-driven node discovery (e.g., "find all temperature sensors")
Discovering nodes before reading, writing, invoking, or subscribing
When NOT to Use
OPC Classic (OPC DA / OPC HDA) connections
PI Data Archive / PI AF / OSIsoft / AVEVA PI systems
Non-OPC UA protocols (Modbus, MQTT)
OPC UA server-side development
References
Load the relevant reference file for detailed procedures:
Task
Reference
Server discovery, LDS setup, empty discovery results
Use this step when the endpoint URL is not known, or when the user
explicitly asks to discover servers given a hostname or discovery URL.
Skip this step if the endpoint URL is already known.
Prerequisites — before calling opcuaserverinfo, ensure:
The OPC UA Local Discovery Service (LDS) is installed and running
The target server is registered with the LDS
The server's certificate is trusted by the LDS certificate store at
C:\ProgramData\OPC Foundation\UA\pki\trusted\certs\
% TEMPLATE — not executable (shows alternative discovery forms)
% LDS-based discovery (preferred — finds all registered servers)
serverInfo = opcuaserverinfo('localhost');
% Direct endpoint discovery (when you know the server URL)
serverInfo = opcuaserverinfo('opc.tcp://myserver:53530/OPCUA/SimulationServer');
% Pass discovery result directly to opcua()
uaClient = opcua(serverInfo(1));
connect(uaClient);
The opcua function also accepts a ServerInfo object directly from
opcuaserverinfo.
2. Configure security (only if non-default needed)
% TEMPLATE — not executable (shows two alternative security-config forms)
% R2025a+ (preferred) — Name-Value pairs in constructor
uaClient = opcua(serverUrl, ...
MessageSecurityMode="Sign", ...
ChannelSecurityPolicy="Basic256Sha256");
% R2020a+ (backward-compatible) — setSecurityModel after construction
uaClient = opcua(serverUrl);
setSecurityModel(uaClient, "Sign", "Basic256Sha256");
3. Handle certificate trust (if needed)
If the server's certificate is not yet trusted by MATLAB, the
connection will fail. Follow the escalation order in Internal
Constraints. Load references/certificate-trust-workflows.md for details.
% TEMPLATE — not executable (shows two alternative lookup forms)
% Quick access from a known NodeId
node = opcuanode(3, 1002, uaClient);
% Always retains parent info
node = findNodeById(uaClient.Namespace, 3, 1002);
Find and invoke a method node
invoke requires parent information. Before invoking, check the node's
Parent property — if it is empty, re-resolve the node via
findNodeById (or .Children navigation) so parent info is populated;
if it is non-empty, invoke directly.
methodNode = opcuanode(6, 'MyMethod', uaClient);
% Ensure parent info is present before invoking
if isempty(methodNode.Parent)
methodNode = findNodeById(uaClient.Namespace, 6, 'MyMethod');
end
% Verify argument count before calling invoke
fprintf("Inputs: %d, Outputs: %d\n", methodNode.NumInputs, methodNode.NumOutputs);
[result, timestamp, quality] = invoke(uaClient, methodNode, arg1, arg2);