On this page
01
What you'll set up
Cloptima has a hosted MCP endpoint for the platform itself. Connect an AI assistant to it and you can ask about your AI spend, policies, budgets, and cloud costs in plain language, from the tool you already work in.
- An access token with the scopes you choose
- An MCP client connected to Cloptima
- A first set of questions that return real answers
- A read-only setup for safe access
02
What your assistant can do
The endpoint exposes the same tools as the Cloptima CLI, from AI spend and governance to cloud, Kubernetes, budgets, and billing.
| Area | Example questions |
|---|---|
| AI spend | What is our LLM spend by model this month? |
| AI governance | Which policies blocked requests this week? |
| Budgets and alerts | Which budgets are close to their limit? |
| Cloud and Kubernetes | Break down Kubernetes cost by namespace |
| Anomalies and recommendations | What is our biggest anomaly right now? |
03
Create an access token
The endpoint accepts personal access tokens only. The token's scopes decide what your assistant can see and do.
- 1
Open Personal Access Tokens
Go to Organization settings and find the Personal Access Tokens card.
- 2
Choose New token
Give it a name that says where it is used, such as claude-desktop.
- 3
Set Expires in days
Pick a lifetime that fits your policy. Shorter is safer.
- 4
Choose scopes
Use the scope selector. The read-only preset is the right start.
- 5
Create the token
Copy it now. It is shown once.
| Preset | Gives your assistant |
|---|---|
| Read only | Read access across your organization, AI, cost, Kubernetes, and integrations |
| Operator | Read and write for day-to-day operations |
| Full admin | Everything, including token management |
04
Connect your client
Any MCP client that supports the Streamable HTTP transport can connect.
Endpoint: https://api.cloptima.ai/v1/mcp
Authorization: Bearer <your-personal-access-token>- 1
Add a remote MCP server
In your client, add a server with the endpoint above.
- 2
Add the bearer token
Send the token in the Authorization header.
- 3
Start a conversation
Ask a question. The client discovers the tools on its own.
Requests from a web page are refused, so connect from a desktop client, an editor, or your own agent.
05
Your assistant sees what the token allows
Cloptima lists only the tools the token can use. A read-only token never shows write tools. A token without a scope never shows that area.
- Tools outside the token's scopes are not listed at all
- Tools your plan does not include are not listed
- Every call is checked again at the moment it runs
06
Ask your first questions
Start with questions that have a clear answer, then follow up.
- 1
Start broad
Ask: What is our LLM spend by model this month?
- 2
Narrow it
Ask: Which team drives the most of that spend?
- 3
Check governance
Ask: Show me the policy violations from the last week.
- 4
Look ahead
Ask: Which budgets are likely to run out this month?
07
Preview changes before they happen
Tools that change something ask for confirmation. Your assistant can preview any change first.
| Argument | What it does |
|---|---|
| dry_run: true | Shows the request that would be sent, and runs the same scope checks, without changing anything |
| confirm: true | Runs the change. Without it, a changing tool refuses |
08
Use a read-only token for safe access
The simplest safe setup is a token that cannot change anything.
- Create the token with the read-only preset
- Use one token per client, so you can revoke one without touching the rest
- Set a short expiry and rotate it on a schedule
If you prefer to keep everything on your machine, the Cloptima CLI includes a local MCP server. Run cloptima mcp serve, and add --read-only to refuse every changing tool.
09
Rotate and revoke
Tokens are listed on the same card with their scopes, last use, and expiry.
- 1
Create the new token
Give it the same scopes.
- 2
Update the client
Swap the token and confirm it works.
- 3
Revoke the old token
Choose Revoke on its row.
10
If something goes wrong
Most problems are the token or the client.
| What you see | Likely cause | Fix |
|---|---|---|
| 401 Authentication required | The token is missing, expired, or revoked | Create a new token |
| 403 MCP access is not enabled | Your plan does not include MCP access | Check your plan on the pricing page |
| A tool you expect is missing | The token lacks the scope | Create a token with that scope |
| Browser-origin requests are not allowed | The client runs in a web page | Use a desktop client or your own agent |
| A changing tool refuses | It needs confirm: true | Preview with dry_run, then confirm |