All guides

Connect Your AI Assistant to Cloptima with MCP

Create an access token, point Claude, Cursor, or any MCP client at Cloptima, and ask about spend, policies, and anomalies in plain language.

9 min read Updated October 2026LLM FinOps
On this page
  1. 01What you'll set up
  2. 02What your assistant can do
  3. 03Create an access token
  4. 04Connect your client
  5. 05Your assistant sees what the token allows
  6. 06Ask your first questions
  7. 07Preview changes before they happen
  8. 08Use a read-only token for safe access
  9. 09Rotate and revoke
  10. 10If something goes wrong

01

What you'll set up

Cloptima has a hosted MCP endpoint for the platform itself. Connect an AI assistant to it and you can ask about your AI spend, policies, budgets, and cloud costs in plain language, from the tool you already work in.

  • An access token with the scopes you choose
  • An MCP client connected to Cloptima
  • A first set of questions that return real answers
  • A read-only setup for safe access

02

What your assistant can do

The endpoint exposes the same tools as the Cloptima CLI, from AI spend and governance to cloud, Kubernetes, budgets, and billing.

AreaExample questions
AI spendWhat is our LLM spend by model this month?
AI governanceWhich policies blocked requests this week?
Budgets and alertsWhich budgets are close to their limit?
Cloud and KubernetesBreak down Kubernetes cost by namespace
Anomalies and recommendationsWhat is our biggest anomaly right now?

03

Create an access token

The endpoint accepts personal access tokens only. The token's scopes decide what your assistant can see and do.

  1. 1

    Open Personal Access Tokens

    Go to Organization settings and find the Personal Access Tokens card.

  2. 2

    Choose New token

    Give it a name that says where it is used, such as claude-desktop.

  3. 3

    Set Expires in days

    Pick a lifetime that fits your policy. Shorter is safer.

  4. 4

    Choose scopes

    Use the scope selector. The read-only preset is the right start.

  5. 5

    Create the token

    Copy it now. It is shown once.

PresetGives your assistant
Read onlyRead access across your organization, AI, cost, Kubernetes, and integrations
OperatorRead and write for day-to-day operations
Full adminEverything, including token management

04

Connect your client

Any MCP client that supports the Streamable HTTP transport can connect.

connection
Endpoint: https://api.cloptima.ai/v1/mcp
Authorization: Bearer <your-personal-access-token>
  1. 1

    Add a remote MCP server

    In your client, add a server with the endpoint above.

  2. 2

    Add the bearer token

    Send the token in the Authorization header.

  3. 3

    Start a conversation

    Ask a question. The client discovers the tools on its own.

Requests from a web page are refused, so connect from a desktop client, an editor, or your own agent.

05

Your assistant sees what the token allows

Cloptima lists only the tools the token can use. A read-only token never shows write tools. A token without a scope never shows that area.

  • Tools outside the token's scopes are not listed at all
  • Tools your plan does not include are not listed
  • Every call is checked again at the moment it runs

06

Ask your first questions

Start with questions that have a clear answer, then follow up.

  1. 1

    Start broad

    Ask: What is our LLM spend by model this month?

  2. 2

    Narrow it

    Ask: Which team drives the most of that spend?

  3. 3

    Check governance

    Ask: Show me the policy violations from the last week.

  4. 4

    Look ahead

    Ask: Which budgets are likely to run out this month?

07

Preview changes before they happen

Tools that change something ask for confirmation. Your assistant can preview any change first.

ArgumentWhat it does
dry_run: trueShows the request that would be sent, and runs the same scope checks, without changing anything
confirm: trueRuns the change. Without it, a changing tool refuses

08

Use a read-only token for safe access

The simplest safe setup is a token that cannot change anything.

  • Create the token with the read-only preset
  • Use one token per client, so you can revoke one without touching the rest
  • Set a short expiry and rotate it on a schedule

If you prefer to keep everything on your machine, the Cloptima CLI includes a local MCP server. Run cloptima mcp serve, and add --read-only to refuse every changing tool.

09

Rotate and revoke

Tokens are listed on the same card with their scopes, last use, and expiry.

  1. 1

    Create the new token

    Give it the same scopes.

  2. 2

    Update the client

    Swap the token and confirm it works.

  3. 3

    Revoke the old token

    Choose Revoke on its row.

10

If something goes wrong

Most problems are the token or the client.

What you seeLikely causeFix
401 Authentication requiredThe token is missing, expired, or revokedCreate a new token
403 MCP access is not enabledYour plan does not include MCP accessCheck your plan on the pricing page
A tool you expect is missingThe token lacks the scopeCreate a token with that scope
Browser-origin requests are not allowedThe client runs in a web pageUse a desktop client or your own agent
A changing tool refusesIt needs confirm: truePreview with dry_run, then confirm

Put This Guide Into Practice

Cloptima automates the strategies described in this guide.

No credit card required
5-minute setup
Free trial