Open navigation

Docs · MCP server

Four read-only tools your agent can call today.

The Cloud Horizons MCP server is in private preview. One authenticated JSON-RPC endpoint exposes anomalies.recent, azure.apim.summary, azure.virtual_desktops, and azure.virtual_desktop_sessions, scope-limited per token. Inventory, forecast, policy, and VM lifecycle tools stay out of discovery until a production handler backs them.

CLIENTS CLOUD HORIZONS MCP BACKEND DATA Claude / GPT agent runs anomaly checks IDE / CLI tools cursor, claude-code Platform scripts curl, n8n, Slack bot Internal portal backstage, retool cloud-horizons.com/api/mcp tools/ tools/list tools/call anomalies.recent hashed API key auth · tenant scoped AWS Cost Data synced Cost Explorer API Key Table hashed tokens Anomaly Store D1 cost tables Future Tools hidden until live

Cloud Horizons sits between your agents and the underlying cost data. Your agent never holds cloud credentials, only an MCP token scoped to the tool it needs.

Current preview endpoint

Use the JSON-RPC endpoint at /api/mcp/v1. Tokens are checked against stored API-key hashes and tenant scope before tool discovery or execution.

Quick start

Authenticate with an API key that carries the mcp scope, list the tools the server actually implements, then call one. The transport is JSON-RPC over streamable HTTP at /api/mcp/v1.

1. List implemented tools

$ curl -X POST https://cloud-horizons.com/api/mcp/v1 \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}'

2. Call recent anomalies

$ curl -X POST https://cloud-horizons.com/api/mcp/v1 \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"anomalies.recent","arguments":{"days":7,"severity":"critical"}}}'

3. Or wire it as an MCP server

{
  "mcpServers": {
    "cloud-horizon": {
      "url": "https://cloud-horizons.com/api/mcp/v1",
      "headers": { "Authorization": "Bearer $TOKEN" }
    }
  }
}

Tool catalog

Four read-only tools in private preview. Nothing in the catalog writes to a cloud account.

anomalies.recent

Recomputes and lists AWS cost anomalies for the authenticated tenant from synced cost data. Takes days, severity, and limit.


              anomalies.recent({ days: 7, severity: "critical" })
            

azure.apim.summary

The MCP tool currently returns sample APIM data; the live ARM-backed APIM view is available at /api/azure/apim with azure:read.


              azure.apim.summary({ subscription_id: "<guid>", resource_group: "<rg>", service_name: "<apim>" })
            

azure.virtual_desktops

Read-only Azure Virtual Desktop host pools and session hosts plus Windows 365 Cloud PCs for the connected subscription. Needs the azure:read scope on top of mcp.


              azure.virtual_desktops({ subscription_id: "<guid>" })
            

azure.virtual_desktop_sessions

Read-only: the user sessions on one Azure Virtual Desktop session host (who is signed in, Active or Disconnected). Same azure:read requirement; disconnect, log off and message stay on the REST API and need azure:write.


              azure.virtual_desktop_sessions({ session_host_id: "<session host ARM id>" })
            

Tools without a production handler stay out of discovery.

Auth model

  • API-key auth with the mcp scope. Keys belong to a tenant. Discovery and execution both require the mcp scope.
  • Read-only. The preview exposes anomalies.recent, azure.apim.summary, azure.virtual_desktops, and azure.virtual_desktop_sessions. Lifecycle actions stay on the REST API.
  • Checked before discovery. The bearer token is matched against stored API-key hashes and tenant scope before tools/list or tools/call runs. azure.virtual_desktops and azure.virtual_desktop_sessions also need the azure:read scope.

Audit and observability

  • Last use recorded per key. Every authorized call updates the key’s last-used timestamp.
  • No event stream yet. Cloud Horizons does not push call or anomaly events. Agents poll anomalies.recent on their own schedule.
  • SOC 2 readiness mapping available. Cloud Horizons does not claim a current SOC 2 report.

Get the MCP token

Request private-preview access for a scoped, read-only MCP token.

Connect AWS cost data or an Azure subscription first, then wire the scoped token into Claude, Cursor, n8n, or your own agent. Inventory, forecast, lifecycle, and policy tools appear only once their handlers are live.