Docs · MCP server
Four read-only tools your agent can call today.
The Cloud Horizons MCP server is in private preview. One authenticated JSON-RPC endpoint exposes anomalies.recent, azure.apim.summary, azure.virtual_desktops, and azure.virtual_desktop_sessions, scope-limited per token. Inventory, forecast, policy, and VM lifecycle tools stay out of discovery until a production handler backs them.
Cloud Horizons sits between your agents and the underlying cost data. Your agent never holds cloud credentials, only an MCP token scoped to the tool it needs.
Current preview endpoint
Use the JSON-RPC endpoint at /api/mcp/v1. Tokens are checked against stored API-key hashes and tenant scope before tool discovery or execution.
Quick start
Authenticate with an API key that carries the mcp scope, list the tools the server actually implements, then call one. The transport is JSON-RPC over streamable HTTP at /api/mcp/v1.
1. List implemented tools
$ curl -X POST https://cloud-horizons.com/api/mcp/v1 \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' 2. Call recent anomalies
$ curl -X POST https://cloud-horizons.com/api/mcp/v1 \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"anomalies.recent","arguments":{"days":7,"severity":"critical"}}}' 3. Or wire it as an MCP server
{
"mcpServers": {
"cloud-horizon": {
"url": "https://cloud-horizons.com/api/mcp/v1",
"headers": { "Authorization": "Bearer $TOKEN" }
}
}
} Tool catalog
Four read-only tools in private preview. Nothing in the catalog writes to a cloud account.
anomalies.recent
Recomputes and lists AWS cost anomalies for the authenticated tenant from synced cost data. Takes days, severity, and limit.
anomalies.recent({ days: 7, severity: "critical" })
azure.apim.summary
The MCP tool currently returns sample APIM data; the live ARM-backed APIM view is available at /api/azure/apim with azure:read.
azure.apim.summary({ subscription_id: "<guid>", resource_group: "<rg>", service_name: "<apim>" })
azure.virtual_desktops
Read-only Azure Virtual Desktop host pools and session hosts plus Windows 365 Cloud PCs for the connected subscription. Needs the azure:read scope on top of mcp.
azure.virtual_desktops({ subscription_id: "<guid>" })
azure.virtual_desktop_sessions
Read-only: the user sessions on one Azure Virtual Desktop session host (who is signed in, Active or Disconnected). Same azure:read requirement; disconnect, log off and message stay on the REST API and need azure:write.
azure.virtual_desktop_sessions({ session_host_id: "<session host ARM id>" })
Tools without a production handler stay out of discovery.
Auth model
- API-key auth with the mcp scope. Keys belong to a tenant. Discovery and execution both require the mcp scope.
- Read-only. The preview exposes anomalies.recent, azure.apim.summary, azure.virtual_desktops, and azure.virtual_desktop_sessions. Lifecycle actions stay on the REST API.
- Checked before discovery. The bearer token is matched against stored API-key hashes and tenant scope before tools/list or tools/call runs. azure.virtual_desktops and azure.virtual_desktop_sessions also need the azure:read scope.
Audit and observability
- Last use recorded per key. Every authorized call updates the key’s last-used timestamp.
- No event stream yet. Cloud Horizons does not push call or anomaly events. Agents poll anomalies.recent on their own schedule.
- SOC 2 readiness mapping available. Cloud Horizons does not claim a current SOC 2 report.
Get the MCP token
Request private-preview access for a scoped, read-only MCP token.
Connect AWS cost data or an Azure subscription first, then wire the scoped token into Claude, Cursor, n8n, or your own agent. Inventory, forecast, lifecycle, and policy tools appear only once their handlers are live.