coderocket-mcp
# @mlgraham/coderocket-mcp
MCP server for [CodeRocket Deploy](https://deploy.coderocket.com) — AI-generated CI/CD workflows
and AI code review, available as tools inside Claude Code.
## Setup
**Claude Code will never prompt you for your API key.** This server reads it from the
environment once at startup. Set it before you start Claude Code, or the tools will report that
they are not configured.
### 1. Create an API key
Go to [deploy.coderocket.com/settings](https://deploy.coderocket.com/settings) → **API Keys** →
**Create Key**. The key is shown **once** — copy it before leaving the page. If you lose it, you
must revoke it and create a new one.
### 2. Export it to your shell profile
```bash
echo 'export CODEROCKET_API_KEY=crk_your_key_here' >> ~/.zshrc # or ~/.bashrc
source ~/.zshrc
```
### 3. Restart Claude Code
Required. A running session will not pick up a newly exported variable.
### 4. Install the plugin
```
claude plugin marketplace add mlgraham/coderocket-plugin
claude plugin install coderocket@coderocket-marketplace
```
Then verify with `/coderocket:status`.
## Tools
| Tool | Purpose |
|------|---------|
| `deploy_repo` | Generate a CI/CD workflow for a repository (polls until complete) |
| `create_pr` | Open a pull request with a generated workflow |
| `list_repos` | List your connected repositories |
| `repo_details` | Details and analysis status for one repository |
| `list_reviews` | List AI code reviews |
| `get_review` | Fetch a single review with its inline comments |
| `account_status` | Account tier, usage, and limits |
| `generation_feedback` | Report whether a generated workflow worked |
| `health_check` | Check API connectivity and that your key is valid |
## Configuration
| Variable | Required | Default | Purpose |
|----------|----------|---------|---------|
| `CODEROCKET_API_KEY` | **yes** | — | Your `crk_` API key |
| `CODEROCKET_API_URL` | no | `https://deploy.coderocket.com/api/v1` | Override the API endpoint |
| `CODEROCKET_ALLOW_CUSTOM_API_URL` | no | — | Set to `1` to permit a non-default host |
`CODEROCKET_API_URL` is validated before use. Because every request carries your API key as a
bearer token, the server accepts only the official host or loopback by default, requires HTTPS
off loopback, and refuses to start on an unsafe value rather than starting up and sending your
credentials somewhere unintended. Pointing at a self-hosted backend requires
`CODEROCKET_ALLOW_CUSTOM_API_URL=1`, which also prints a warning naming the host.
## Troubleshooting
**Every tool says the key is not set.** The variable was not present when Claude Code started.
Confirm with `echo $CODEROCKET_API_KEY` in a new terminal, then fully restart Claude Code — not
just the conversation.
**"API key has been revoked."** The key exists but was revoked. Create a new one in Settings,
update your shell profile, and restart Claude Code.
**"is not an allowed CodeRocket host."** `CODEROCKET_API_URL` points somewhere unexpected. If you
did not set it deliberately, unset it — something in your environment did, and it would have
received your API key. If it is an intentional self-hosted backend, set
`CODEROCKET_ALLOW_CUSTOM_API_URL=1`.
## Links
- [Web app](https://deploy.coderocket.com)
- [Claude Code plugin](https://github.com/mlgraham/coderocket-plugin)
- Changelog: `CHANGELOG.md`, shipped inside this package
## License
MIT
TDQS
Scored across 9 tools
Each tool targets a distinct resource or action: repo listing vs. repo details, deployment generation, PR creation, review listing vs. details, account status, health check, and feedback submission. There is no overlap, and the boundaries between list_repos and repo_details are clear (summary vs. comprehensive).
The tool names mix verb-first patterns (list_repos, create_pr, deploy_repo, list_reviews, get_review) with noun-first patterns (account_status, health_check, generation_feedback, repo_details). This inconsistency, while not causing confusion, prevents a predictable naming convention.
With 9 tools, the server is well-scoped for its purpose—CI/CD workflow generation, PR creation, code reviews, and account management. Each tool serves a clear function, and the count is within the ideal range.
The core lifecycle is covered: analyze repo, generate workflow, create PR, submit feedback, and access reviews. Minor gaps exist, such as no direct listing/updating of individual workflows and no way to comment on or resolve review comments, but these are non-critical and the surface is largely complete.