> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sreagent.app/llms.txt
> Use this file to discover all available pages before exploring further.

# MCP tools

> Connect an MCP client to your organization and see every tool it can call, grouped by the access it needs.

export const Plan = ({tier}) => <Badge color="blue">{tier} plan</Badge>;

Connect an MCP client such as Claude Code or Claude Desktop to SRE Agent and it can read alerts, investigations, runbooks and configuration, and act on them, with the same checks the web app applies.

<Plan tier="Business" />

## Connect a client

<Steps>
  <Step title="Create a credential">
    In **Settings**, open **API Keys** and select **Generate API Key**. Tick the scopes the client needs: `mcp:read` to look, `mcp:write` to act, `mcp:admin` to configure. The key is shown once, so copy it. As a member you can instead create a personal access token on your **Account** page, which follows your own role.
  </Step>

  <Step title="Add the server to your client">
    The endpoint is `https://sreagent.app/api/mcp` and the credential goes in the `Authorization` header as a Bearer token. For Claude Code:

    ```bash theme={null}
    claude mcp add --transport http sre-agent https://sreagent.app/api/mcp \
      --header "Authorization: Bearer sre_ak_xxxxxxxxxxxx"
    ```
  </Step>

  <Step title="Ask a question">
    Ask the client for something your key can do, such as "list the active alerts". It calls `get_active_alerts` and shows the answer.
  </Step>
</Steps>

<Note>
  A personal token can belong to more than one organization. Call `list_organizations` first, then
  pass the `organization` argument that the other tools offer. An API key belongs to one
  organization, so its tools take no `organization` argument.
</Note>

## How access is decided

Every tool needs one scope, and each scope maps to a role. A scope includes the ones below it, so `mcp:admin` can also call write and read tools.

| Scope | Role a personal token needs | Tools |
| - | - | - |
| `mcp:read` | viewer | Read tools |
| `mcp:write` | member | Write tools |
| `mcp:admin` | org\_admin | Admin tools |

A tool that is outside the key's scope answers "Insufficient scope". A personal token below the role a tool needs answers "Insufficient role". Tools that delete something ask for `confirm: true`.

Tools that take a secret, such as a provider key, a webhook signing secret or connector credentials, are write-only. You can send the value, and the answer only says whether one is stored. They are marked in the tables.

## Read tools

A key with `mcp:read`, or a personal token whose role is at least viewer, can call these. They read data and change no configuration.

| Tool | What it does |
| - | - |
| `list_organizations` | List the organizations this account belongs to, with the role held in each. |
| `get_active_alerts` | List active alerts, optionally filtered by severity or service. |
| `get_alert_details` | Get full details for a specific alert by ID. |
| `get_investigation` | Get investigation results including findings and root cause. |
| `get_slo_status` | List SLO health status for all active SLOs. |
| `list_runbooks` | List available runbooks. |
| `query_prometheus` | Run a PromQL query against the configured Prometheus instance. |
| `query_cloudtrail` | Query AWS CloudTrail for API activity in this organization's AWS account: who called what, when, from where, and whether it was refused. |
| `summarize_cloudtrail_denials` | Count the AWS API calls this organization's account refused in a window, grouped by who was refused, what they called and the error code, most frequent first. |
| `resolve_service_bindings` | How the Observability Explorer resolves one service's logs, metrics and traces. |
| `query_logs` | Run the Explorer's Logs tab query. |
| `query_metrics` | Run the Explorer's Metrics tab. |
| `search_traces` | Run the Explorer's Traces tab: search X-Ray for the service's bound trace service names over the window, or your own X-Ray `filter` expression. |
| `get_trace` | Read one X-Ray trace's segment tree by id: each segment's name, duration, status and its subsegments, as `search_traces` links to. |
| `list_data_sources` | List this organization's data sources: name, type, url, enabled and regions. |
| `get_data_source` | One data source by id, the same fields list\_data\_sources answers for it. |
| `list_slis` | List this organization's SLIs. |
| `get_sli` | One SLI by id, the same fields list\_slis answers for it. |
| `list_slos` | List this organization's SLOs with their targets and status. |
| `get_slo` | One SLO by id, the same fields list\_slos answers for it. |
| `validate_runbook` | Ask the Validate button's questions without running anything. |
| `list_runbook_steps` | List the steps of a runbook, in order. |
| `list_recipes` | List the recipes this organization can install. |
| `list_connectors` | List this organization's infrastructure connectors (credentials are never returned). |
| `get_connector` | One connector by id, the same fields list\_connectors answers for it. |
| `list_synthetic_checks` | List this organization's synthetic checks with their current state (last status, last run, consecutive failures). |
| `get_synthetic_check` | One synthetic check by id, the same fields list\_synthetic\_checks answers for it. |
| `list_oncall_schedules` | This organization's on-call schedules. |
| `who_is_on_call` | Who is on call right now, computed from the schedule's roster and any override in force at this instant, never a stored answer, so it is always current. |
| `list_oncall_overrides` | List one schedule's overrides, earliest first. |
| `get_oncall_notification_preferences` | Read your own on-call notification preferences. |
| `update_oncall_notification_preferences` | Change your own on-call notification preferences. |
| `get_oncall_notification_policy` | Read this organization's on-call notification policy. |
| `list_oncall_notifications` | The most recent on-call notification deliveries for this organization, newest first. |
| `list_alert_mutes` | Every alert mute this organization has, in force or expired. |
| `get_alert_mute` | One alert mute by id, the same fields list\_alert\_mutes answers for it. |
| `list_repo_settings` | List the per-repository fix settings: branch, service alias, environment and the folders a fix may change. |
| `get_repo_settings` | One repository's fix settings by the row id list\_repo\_settings or create\_repo\_settings answered. |
| `list_tickets` | List this organization's board cards, oldest first. |
| `get_ticket` | Read one card in full: its fields, what it was raised for, its comments, its activity feed, its approval requests. |
| `decide_ticket_approval` | Answer an approval request on a board card, as the person it names. |
| `list_ticket_reminders` | Pending reminders on a card, soonest first. get\_ticket also names them; this is the same list on its own. |
| `get_fix_brief` | Fetch the fix brief for a handoff by id. |
| `list_pending_handoffs` | List this organization's fix handoffs still waiting on somebody. |

## Write tools

These change operational data such as alerts, cards, runbooks and on-call. They need `mcp:write`, or a personal token whose role is at least member. A key with `mcp:admin` also passes.

| Tool | What it does |
| - | - |
| `investigate_alert` | Trigger an AI investigation for an alert. |
| `run_runbook` | Execute a runbook by ID. |
| `approve_sli` | Approve a suggested SLI and record who approved it. |
| `activate_sli` | Move an approved SLI to active so it is measured for real. |
| `archive_sli` | Archive an SLI so it stops being offered as something to build on. |
| `preview_sli_query` | Run an SLI's query against its data source and show the result without saving anything. |
| `reprobe_sli` | Re-run the SLI's query validation and write the verdict onto the row. |
| `pause_runbook` | Pause a runbook: scheduled and auto-triggered executions stop until it is resumed. |
| `resume_runbook` | Lift a pause: scheduled and auto-triggered executions run again, and the pause's author and reason are cleared. |
| `install_recipe` | Install a recipe from the library as a runbook. |
| `run_synthetic_check` | Run a synthetic check now instead of waiting for its interval. |
| `create_slo_from_synthetic_check` | Create an availability or latency SLO from a synthetic check. |
| `list_certificate_monitors` | List the TLS certificates this organization watches, with the newest check beside each one: last\_status, days\_until\_expiry and expires\_at. |
| `get_certificate_monitor` | One certificate monitor by id, the same fields list\_certificate\_monitors answers for it. |
| `create_certificate_monitor` | Watch a hostname's TLS certificate. |
| `check_certificate_now` | Check a watched certificate now instead of waiting for the next scheduled check. |
| `list_image_targets` | List the container images this organization scans for known vulnerabilities, with the newest scan beside each one. |
| `get_image_target` | One image scan target by id, the same fields list\_image\_targets answers for it. |
| `create_image_target` | Add a container image to scan for known vulnerabilities. |
| `scan_image_now` | Scan a watched image now instead of waiting for the next scheduled scan. |
| `list_drift_configs` | List the workloads this organization watches for configuration drift, with the cluster each one is read from. |
| `capture_drift_baseline` | Store a workload's current state as its desired baseline. |
| `check_drift_now` | Compare a workload against its baseline now. |
| `list_drift_events` | List detected configuration drift: what changed, on which resource, how bad it is and whether anybody has answered it, newest first. |
| `acknowledge_drift_event` | Record that somebody has seen a drift event. |
| `resolve_drift_event` | Close a drift event. |
| `run_kubernetes_scan` | Assess every connected Kubernetes cluster for security misconfigurations now. |
| `run_iam_scan` | Inventory this organization's AWS IAM estate now and file what is wrong with it. |
| `list_iam_findings` | List what the IAM scan established about this organization's AWS principals. |
| `acknowledge_iam_finding` | Record that somebody has seen an IAM finding. |
| `resolve_iam_finding` | Close an IAM finding once the principal is fixed or the risk is accepted. |
| `list_secret_findings` | List credentials found in alert payloads, investigation findings and Kubernetes objects. |
| `acknowledge_secret_finding` | Record that somebody has seen an exposed credential. |
| `mark_secret_false_positive` | Say this match is not a credential. |
| `list_kubernetes_findings` | List what the latest Kubernetes security scan of each cluster found, worst first. |
| `acknowledge_kubernetes_finding` | Record that somebody has seen this Kubernetes finding. |
| `list_api_anomalies` | List API usage anomalies, newest first. |
| `acknowledge_api_anomaly` | Record that somebody has seen this API anomaly. |
| `reopen_api_anomaly` | Withdraw an acknowledgement and put the finding back on the open list. |
| `list_suppression_rules` | Standing rules that stop a known, expected pattern from filing a fresh API anomaly finding. |
| `create_oncall_override` | Create a temporary on-call override that wins over a schedule's rotation. |
| `update_oncall_override` | Change an override, named by the id list\_oncall\_overrides answers: who covers, when it begins or ends, or the reason. |
| `delete_oncall_override` | Remove an on-call override. |
| `acknowledge_alert` | Acknowledge an alert. |
| `resolve_alert` | Resolve an alert. |
| `create_alert_mute` | Stop alerts matching a pattern from paging. |
| `delete_alert_mute` | Remove a mute, so alerts matching its pattern page again. |
| `create_ticket` | Open a card on this organization's ops board. |
| `update_ticket` | Move a card to another column, assign it, change its priority or add a comment. |
| `update_ticket_comment` | Rewrite a line on a card. |
| `delete_ticket_comment` | Remove a line from a card's conversation. |
| `request_ticket_approval` | Ask a named member to sign off on a board card. |
| `set_ticket_reminder` | Set a reminder on a card for yourself or for everyone on it. |
| `cancel_ticket_reminder` | Cancel one pending reminder. |
| `list_labels` | List the labels on live cards with how many cards carry each, most used first. |
| `rename_label` | Rename a label across every live card that carries it. |
| `delete_label` | Take a label off every live card that carries it. |
| `list_overseer_runs` | List Control Tower runs, newest first. |
| `list_overseer_findings` | List what the Control Tower found, most recently seen first. |
| `dismiss_overseer_finding` | Dismiss a Control Tower finding. |
| `apply_overseer_finding` | Apply the action a Control Tower finding recommends. |
| `submit_feedback` | Send a bug report, suggestion or question to the SRE Agent team. |

## Admin tools

These configure the organization: data sources, integrations, policies, teams and settings. They need `mcp:admin`, or a personal token whose role is org\_admin.

| Tool | What it does |
| - | - |
| `create_data_source` | Create a data source such as Prometheus, Loki, Grafana, CloudWatch or Datadog. |
| `get_aws_external_id` | Read the external ID and the principal that your IAM role must trust. The answer holds a secret, so keep it private. |
| `update_data_source` | Update a data source by id (name, url, enabled, regions, auth\_type, auth\_credentials). auth\_credentials replaces the stored credentials. |
| `delete_data_source` | Delete a data source by id. |
| `create_sli` | Create an SLI. sli\_type is one of latency, error\_rate, availability, throughput, saturation. |
| `update_sli` | Update an SLI by id (name, service, query, data\_source\_id, status). |
| `delete_sli` | Delete an SLI by id. |
| `create_slo` | Create an SLO against an existing SLI. target is a percentage (e.g. 99.9), window\_days defaults to 30. |
| `update_slo` | Update an SLO by id (name, target, window\_days, status). |
| `delete_slo` | Delete an SLO by id, along with its measurement history. |
| `create_runbook` | Create a runbook for this organization. |
| `update_runbook` | Update a runbook by id (name, description, tags, risk\_level, approval\_mode, notification\_level, connector\_scope). |
| `delete_runbook` | Delete a runbook by id, along with its steps. |
| `approve_runbook` | Approve a draft or pending runbook, which is what makes it eligible to run unattended on a matching alert or on its schedule. |
| `archive_runbook` | Archive a runbook: it stops matching alerts, stops running on its schedule and drops off the runbook list. |
| `add_runbook_step` | Add a step to a runbook. |
| `update_runbook_step` | Update a runbook step by id. |
| `delete_runbook_step` | Delete a runbook step by id. |
| `create_connector` | Create an infrastructure connector that runbook steps act through. Write-only: the credential you send is never returned. |
| `update_connector` | Update a connector by id (name, config, metadata, enabled). |
| `delete_connector` | Delete a connector by id. |
| `test_connector` | Run the connector's health check (reaches the real target: K8s API, SSH, or AWS STS GetCallerIdentity) and record the result. |
| `create_synthetic_check` | Create a synthetic check that probes a target on an interval and alerts on failure. |
| `update_synthetic_check` | Update a synthetic check by id. |
| `delete_synthetic_check` | Delete a synthetic check and its probe-result history. |
| `delete_certificate_monitor` | Stop watching a host and delete its check history. |
| `delete_image_target` | Stop scanning an image and delete its scan history. |
| `create_suppression_rule` | Suppress a known, expected pattern of API anomaly findings. |
| `delete_suppression_rule` | Delete a suppression rule by id. |
| `get_organization_settings` | The organization's preferences as the Settings page shows them. |
| `update_organization_settings` | Change one or more preferences; omitted ones keep their value. |
| `set_service_binding` | Correct which log groups, traces and metrics belong to a service. |
| `delete_service_binding` | Remove the override binding for `service`. |
| `get_service_binding` | Read the stored telemetry binding override for a service. |
| `get_notification_settings` | Who this organization emails about what. |
| `update_notification_settings` | Change one or more email notification settings. |
| `get_change_notifications` | The Slack routing for infrastructure changes. |
| `update_change_notifications` | Change where infrastructure changes are announced in Slack. |
| `list_alert_routes` | Where this organization routes one service's alerts. |
| `get_alert_route` | One alert route by id, the same fields list\_alert\_routes answers for it. |
| `upsert_alert_route` | Save where one service's alerts open in Slack, and which on-call schedule (if any) is mentioned in the thread when one opens. |
| `delete_alert_route` | Remove a route, named by the id list\_alert\_routes reports. |
| `update_oncall_notification_policy` | Change this organization's on-call notification policy; only what you name changes. |
| `list_deploy_policies` | The deploy gate's policies, one per service. |
| `get_deploy_policy` | One deploy policy by id, the same fields list\_deploy\_policies answers for it. |
| `create_deploy_policy` | Create the deploy gate's policy for one service. |
| `update_deploy_policy` | Change one deploy policy, named by the id list\_deploy\_policies reports. |
| `delete_deploy_policy` | Delete a deploy policy by id. |
| `set_deploy_freeze` | Hold every deploy of this policy's service until a time you choose. |
| `clear_deploy_freeze` | Lift the freeze on this policy's service, so the gate stops holding its deploys. |
| `list_audit_logs` | This organization's audit trail, newest first. |
| `list_ai_providers` | The AI providers this organization pays for with its own keys. |
| `get_ai_provider` | One AI provider by id, the same fields list\_ai\_providers answers for it. |
| `create_ai_provider` | Add an AI provider that your own key pays for. Write-only: the credential you send is never returned. |
| `update_ai_provider` | Change one provider, named by the id list\_ai\_providers reports; omitted fields keep their value. |
| `delete_ai_provider` | Remove a provider and the key stored on it. |
| `test_ai_provider` | Send one small prompt through a provider with its stored key and report the result. |
| `get_ai_settings` | How this organization's AI work is routed and retried. |
| `update_ai_settings` | Change one or more of those switches. |
| `get_ai_usage` | What this organization spent on AI over a window. |
| `list_prompt_templates` | The prompts this organization's AI work runs on. |
| `get_prompt_template` | One prompt template by id, the same fields list\_prompt\_templates answers for it. |
| `create_prompt_template` | Write a new prompt template for this organization. |
| `update_prompt_template` | Change a template's name, description, content or switches. |
| `set_default_prompt_template` | Make a template the default for its prompt type. |
| `delete_prompt_template` | Delete a prompt template. |
| `list_outbound_configs` | Where this organization escalates its alerts. |
| `get_outbound_config` | One outbound target by id, the same fields list\_outbound\_configs answers for it. |
| `create_outbound_config` | Add a target this organization escalates alerts to. |
| `update_outbound_config` | Change one target, named by the id list\_outbound\_configs reports; omitted fields keep their value. |
| `delete_outbound_config` | Remove a target, the tokens stored on it and every escalation rule that routes through it. |
| `test_outbound_config` | Ask the target whether it can be reached. |
| `list_outbound_rules` | Which alerts escalate to which target. |
| `get_outbound_rule` | One escalation rule by id, the same fields list\_outbound\_rules answers for it. |
| `create_outbound_rule` | Escalate the alerts a rule matches to one target, once per firing per alert. |
| `update_outbound_rule` | Change one rule, named by the id list\_outbound\_rules reports; omitted fields keep their value. |
| `delete_outbound_rule` | Remove one escalation rule. |
| `list_outbound_deliveries` | What this organization actually sent to its escalation targets, newest first. |
| `get_github_integration` | How this organization's GitHub App connection stands. |
| `list_github_installations` | The installations of the SRE Agent GitHub App you could connect here. |
| `adopt_github_installation` | Connect one of the App's installations to this organization, by the id list\_github\_installations answers. |
| `disconnect_github_installation` | Disconnect this organization's GitHub App installation. |
| `update_github_settings` | Change what the connected installation does. |
| `set_github_webhook_secret` | Set the signing secret for GitHub webhooks. Write-only: the credential you send is never returned. |
| `set_pagerduty_signing_secret` | Set the signing secret for PagerDuty webhooks. Write-only: the credential you send is never returned. |
| `register_fix_runner` | Register a runner that executes fix requests for your organization. Write-only: the credential you send is never returned. |
| `update_fix_runner` | Rename this organization's fix runner, or switch it on and off. |
| `remove_fix_runner` | Remove this organization's fix runner registration. |
| `list_ticket_integrations` | The ticket systems this organization writes into. |
| `get_ticket_integration` | One ticket system's connection by provider, the same fields list\_ticket\_integrations answers for it. |
| `configure_ticket_integration` | Save the credentials for a ticket system. Write-only: the credential you send is never returned. |
| `delete_ticket_integration` | Remove this organization's credentials for one ticket system, with the board column mapping and the create destination stored beside them. |
| `set_ticket_status_map` | Map this organization's board columns onto one ticket system's own workflow, so moving a card moves the item. |
| `list_ticket_import_rules` | The standing import rules this organization has, one per tracker. |
| `get_ticket_import_rule` | One tracker's import rule by provider, the same fields list\_ticket\_import\_rules answers for it. |
| `update_ticket_import_rule` | Say which of a tracker's issues become cards on their own, one standing rule per tracker. |
| `delete_ticket_import_rule` | Delete the import rule for one tracker, so nothing more is imported from it. |
| `run_ticket_import` | Fetch everything already open in one tracker that this organization's import rule asks for, and open a card for each. |
| `get_status_page` | This organization's public status page as the admin sees it. |
| `update_status_page` | Change one or more of the page's settings. |
| `get_status_page_component` | One component by id, the same fields get\_status\_page answers for it in its components list. |
| `create_status_page_component` | Add a customer-facing unit to the page ("API", "Dashboard"). |
| `update_status_page_component` | Rename a component, change its description, replace the SLOs it publishes or move it up or down the page. |
| `archive_status_page_component` | Take a component off the public page. |
| `list_status_page_incidents` | What this organization's public status page is telling customers. |
| `get_status_page_incident` | One incident by id, the same fields list\_status\_page\_incidents answers for it. |
| `create_status_page_incident` | Publish an incident on the public status page. |
| `update_status_page_incident` | Add a line to an incident that is already published. message is what customers read. |
| `archive_status_page_incident` | Take a resolved incident off the public page and out of its history. |
| `list_teams` | This organization's teams and who is on each of them, in name order. |
| `get_team` | One team and its members by id, the same shape list\_teams answers for it. |
| `create_team` | Open a new team. |
| `update_team` | Rename a team. |
| `delete_team` | Delete a team. |
| `add_team_member` | Put somebody on a team, named by the email address they sign in with, matched without case. |
| `remove_team_member` | Take somebody off a team. |
| `list_team_members` | Every team membership in this organization, one row per person per team, each with its own id. |
| `get_team_member` | One team membership by its own id, as list\_team\_members answers it. |
| `delete_team_member` | Take somebody off one team, naming the membership by its own id. |
| `get_slack_config` | This organization's Slack integration. |
| `configure_slack` | Connect or update the Slack workspace. Write-only: the credential you send is never returned. |
| `request_fix` | Ask SRE Agent to prepare a remediation pull request, described in plain words. |
| `create_repo_settings` | Create the settings row for one repository the GitHub App can reach. |
| `update_repo_settings` | Change one repository settings row, named by the id list\_repo\_settings reports. |
| `delete_repo_settings` | Remove one repository settings row, named by the id list\_repo\_settings reports. |
| `get_integration_webhooks` | List the webhook URLs to paste into your monitoring and ticket systems. The answer holds a secret, so keep it private. |
| `list_members` | List everyone in this organization with the role they hold. |
| `invite_member` | Add a member to this organization (they claim the account via password reset). |
| `mint_fix_handoff` | Freeze a fix brief and hand it to your local agent session. |
| `report_fix_result` | Report the outcome of a fix handoff back to the platform. |
| `get_overseer_settings` | Read the Control Tower settings. |
| `update_overseer_settings` | Change Control Tower settings; omitted ones keep their value. |
| `run_overseer_now` | Start a Control Tower run now. |
| `run_posture_scans` | Collect compliance posture evidence now. |
| `list_compliance_periods` | The audit windows this organization has opened, latest window first. |
| `get_compliance_period` | One audit window by id, the same fields list\_compliance\_periods answers for it. |
| `create_compliance_period` | Open an audit window for a compliance evidence export. |
| `generate_access_review` | Create an access-review card that lists everyone with access and asks a reviewer to sign off. |
| `list_service_bindings` | List the stored telemetry binding overrides, service by service. |
| `list_status_page_components` | List the status page components. |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.