Bring your own agent

Ask Claude about your cloud costs, then request the fix

Connect Claude, Cursor or any MCP client to your workspace. 15 tools read cost, findings and savings, and 3 request a fix, decide an approval or start a scan.

It does not make changes in GCP.

The problem

An AI assistant can’t answer questions about your cloud spend without your data. Letting it change anything is only safe if it goes through the same approvals your team uses.

How it works

  1. Get a token

    In Setup → MCP, an owner creates a token with the read scope. For the write scope or an expiry date, create one in Settings → API Tokens.

  2. Add the server

    Copy the ready-made config for Claude Code, Claude Desktop or Cursor, then run Test connection to check that the tools load.

  3. Ask or act

    Ask about spend, findings or savings. With a write-scoped token, the assistant can request a fix, which waits in your approval queue.

  • 18 tools

    15 need only the read scope, and 3 need a write-scoped token

  • Hash only

    is what GetFinOps stores for each token; the secret is shown once

  • Admin role

    token with the write scope and a paid plan or trial, to approve a change

  • Same rules

    as the dashboard: scoping, role and plan checks, guardrails and audit entries

Capabilities

Connect Claude, Cursor or any MCP client to your cost data, with approval-gated write tools.

  1. Read tools for cost, findings and savings

    Fifteen read tools cover the cost trend and cost by account, findings, the remediation plan, scan status, approvals, executions, verified savings and the LLM usage GetFinOps records for your workspace.

  2. Write tools that go through approval

    Request a remediation, approve or deny one, or start a scan. Approving needs a write-scoped, admin-role token and a paid plan or active trial, and the change passes the same safety checks and guardrails as an approval in the app.

  3. Scoped, revocable tokens

    Owners create gfm_ tokens, shown once and stored only as a hash. A new token gets the read scope and the member role unless chosen otherwise. A token can’t out-rank its creator, can carry an expiry date, and stops working once revoked.

  4. The same rules as the app

    Each tool calls the existing GetFinOps API route with your token, so workspace scoping, role and plan checks, guardrails and audit entries apply exactly as they do in the dashboard.

In depth

The tools

The server exposes 18 tools. The cost trend, findings and plan tools can be limited to one connected cloud account.

  • Cost: get_cost_trend (date range, unblended or amortized, daily or monthly, with tax and credits excluded by default) and get_cost_by_account.
  • Findings and scans: list_findings, which says when the scan ran; get_run_status, which reports for each account whether collection completed, was partial or failed, and how many records it returned; and list_cloud_accounts.
  • Plan and remediation: get_plan, which sorts actions into safe to run automatically, needs approval and disallowed; list_approvals; list_executions and get_execution_status, with before and after resource state and any rollback; and get_savings_summary, for savings re-checked after a change rather than estimates.
  • LLM usage: get_llm_usage_summary, get_llm_usage_by_model, get_llm_usage_by_agent, get_llm_usage_timeseries and list_llm_calls.
  • Write: create_approval, decide_approval and trigger_scan.

How the write tools stay gated

create_approval only raises a request. It takes the action type and target resource, and optionally the originating finding, an estimated monthly saving and a cloud account. The request lands in the same approval queue as one raised in the app and shows in the notification bell, and where Slack is connected it posts an approval card. When a finding is given, the target account is taken from that finding, not from the caller.

decide_approval with “approved” runs the full execution pipeline: guardrails, including the spend ceiling, the change in your AWS account, the post-check and automatic rollback for reversible actions. It needs an admin-role token and a paid plan or active trial. Denying works on any plan.

Before an approved change runs, the plan stage checks it again: an action outside the supported list is refused, and the account’s safety policy, including the production block, and your guardrails apply.

When a route refuses a call, the tool passes on the refusal and its reason, such as a missing role, a plan limit or a blocked execution. A token without the write scope is refused before any route is called. trigger_scan starts a scan and returns at once, and get_run_status reports its progress.

Tokens and access

The server accepts a machine token (gfm_…) or a signed-in user’s session. A token belongs to one workspace, and every result is limited to that workspace.

  • Only owners can create, list or revoke tokens, and only from a signed-in session.
  • The secret is shown once. GetFinOps stores only its SHA-256 hash and records when each token was last used.
  • Scopes are read, the default, and write. A read-scoped token can use only the read tools, and outside MCP it can only make read (GET) requests to the API. A token also carries a role, member by default.
  • Tokens can have an expiry date. Expired or revoked tokens are refused, and repeated failed attempts are rate-limited.
  • Actions taken through MCP are recorded in the audit trail as “mcp:” followed by the token creator’s email or the token’s name.

Connecting a client

The endpoint is POST /api/mcp on your workspace’s address, using the MCP streamable HTTP transport. It keeps no session: each request carries its own token.

Setup → MCP walks you through it. An owner creates a token with the read scope, and the page fills it into a config for Claude Code, Claude Desktop or Cursor. Test connection runs the MCP initialize and tools/list calls and shows how many tools loaded. The token is held only in the page’s memory, never in browser storage.

What it does not do

  • It does not skip approvals or guardrails, and it has no tools for changing autonomy or safety settings.
  • It does not make changes in GCP. Remediation runs in AWS only.
  • It does not create or revoke tokens.
  • It does not provide MCP resources or prompts, only tools.
  • It does not include a local server to install. It is a remote HTTP endpoint.

FAQ

Questions

Can an agent change my cloud on its own?

Only with a token that can approve. Through MCP, requesting a change needs a write-scoped token, and approving needs a write-scoped, admin-role token and a paid plan or active trial. The token Setup → MCP creates has the member role, so it can’t approve. The change then runs in AWS through the same guardrails, post-check and rollback as any other approval.

Which clients work?

Any MCP client that can reach a remote server over HTTP with a bearer token. Setup → MCP has ready configs for Claude Code, Claude Desktop (through the mcp-remote bridge, which needs Node.js) and Cursor.

Who can create tokens?

Only workspace owners, from a signed-in session. A token can’t create, list or revoke tokens, and it can’t carry a higher role than the person who made it.

Why does trigger_scan need a write-scoped token?

Because a scan costs money: Cost Explorer charges per request, and the report stage calls Claude. Through MCP, a token without the write scope can check scan status with get_run_status but can’t start a scan.

Try free — no credit card

Create a workspace and connect an AWS or GCP account, or book a demo first.