Tools
MCP serverPreview
Connect Claude Code, Claude Desktop or any Model Context Protocol client to Ankra Cloud, with one tool per API operation under your API token's permissions.
The MCP server is in preview and not generally available yet. The endpoint, tool names and behaviour described here may change before release.
Ankra Cloud serves the Model Context Protocol, so an AI assistant such as Claude
Code or Claude Desktop can inspect and manage your account. Every tool is one operation of the
API reference, and every call runs through the same API route as the equivalent curl: the
same permissions, quotas, audit entries and errors.
Connect Claude Code#
Create an API token under Settings → API tokens, then:
claude mcp add --transport http ankra-cloud https://cloud.ankra.app/mcp \
--header "Authorization: Bearer <token>"
A read-only token is the safe way to try it: the assistant can look at everything the token's user can see except secrets (passwords, keys, kubeconfigs, the console), and change nothing.
Connect Claude Desktop#
Claude Desktop, and any client that only speaks stdio, runs the small bridge ankra-cloud-mcp. It reads one JSON-RPC
message per line from stdin, sends it to the MCP endpoint and writes the answer to stdout:
{
"mcpServers": {
"ankra-cloud": {
"command": "ankra-cloud-mcp",
"env": {
"ANKRA_CLOUD_TOKEN": "<token>",
"ANKRA_CLOUD_ENDPOINT": "https://cloud.ankra.app"
}
}
}
}
| Variable | Meaning |
|---|---|
ANKRA_CLOUD_TOKEN |
The API token (required), read only from the environment. |
ANKRA_CLOUD_ENDPOINT |
The API origin or the MCP URL itself; defaults to https://cloud.ankra.app. |
ANKRA_CLOUD_CERTIFICATE_AUTHORITY |
A PEM file to trust instead of the system roots. |
Tools#
- One tool per API operation an API token may call, named after its
operationId:list_servers,create_server,create_edge,get_usage_summaryand so on. Session-only operations (API tokens, members, support consents, sign-in) are never tools. - Each tool's input is one JSON object: the path parameters, the query parameters and the request body's fields.
- Read operations are marked read-only; deletions and actions such as stop, rebuild, restore, key rotation and password reset are marked destructive, so clients can ask before running them.
wait_for_operation(operation_id,timeout_secondsup to 300) polls an operation until it succeeds, fails or is cancelled. Operations that answer202point to it.
tools/list hides what your token's scope or your role would refuse, but the API route always decides: a refused call
comes back as a tool error such as HTTP 403 Forbidden: ….
Resources and prompts#
| Resource | Content |
|---|---|
ankra-cloud://account/overview |
Quotas, the usage summary, the servers and the zones. |
ankra-cloud://catalogue/zones |
The zones. |
ankra-cloud://catalogue/plans |
Server plans, templates, storage tiers and database plans. |
ankra-cloud://openapi.yaml |
The OpenAPI document the tools are generated from. |
Prompts: deploy_ipv6_server_with_bastion (zone, hostname, optional plan and SSH key), investigate_server_metrics
(server id, optional period) and review_account_usage.
Authorization and audit#
- The endpoint authenticates your API token and dispatches every tool call into the API as an ordinary request, so there is no second permission system: token scopes and roles apply exactly as over REST, and another account's resources answer 404.
- Every write is recorded in your audit log by its route, with
(via mcp)next to(via API token <name>)in the entry's detail. - Each token may send 300 MCP requests per minute; beyond that the endpoint answers 429 with
Retry-After.
Protocol#
Streamable HTTP, stateless: each POST /mcp carries one JSON-RPC message and gets one JSON answer; there is no
session id, so any API replica answers any request, and GET answers 405. Protocol revisions 2024-11-05 through
2025-11-25 are negotiated through initialize, and 2026-07-28 per request.