631,757 tools. Updated 2026-10-03 02:29
"Managing an AWS Environment" matching MCP tools:
- Who am I? Returns the signed-in account: email, @handle, plan + limits, counts of sites/domains/drives, and connected DNS providers. Call this first to orient before managing sites or domains.ConnectorNo auth
- List the OAuth 2.0 tokens cached for an environment, with their grant type and expiry. Access and refresh token values are never returned. Use this to see cached tokens; to request, refresh or drop one use manage_oauth2_token. Requires project context.ConnectorAPI key
- List Power Automate flows in an environment. Returns id, displayName, state, triggerType, and lastModifiedTime for each flow. mode=owner (default): flows you own plus flows shared with you (personal + team), with full definitions. mode=admin: all flows in the environment (requires an admin account). mode=admin with includeDeleted=true also returns soft-deleted flows (state=Deleted) — the only way to find a deleted flow. If search is provided, results are filtered to flows whose displayName contains the search text. For large environments pagination is time-bounded — if nextLink is returned, pass it as continuationUrl to retrieve the next batch.ConnectorNo auth
- Scan text or code for leaked secrets: API keys (AWS, GCP, Azure, OpenAI, Anthropic, Stripe, GitHub, GitLab, Slack, Twilio, SendGrid, HuggingFace), private keys (RSA/EC/PGP), JWTs, database connection strings, Bearer tokens, and Basic auth headers. Returns a list of findings with type, severity, line number, and a redacted preview. Use before committing code, sharing logs, or sending text to an LLM. 100% regex-based, zero network calls.ConnectorNo auth
- Find every company a person runs or represents - across BOTH registers in one call (cross-border person search). Read-only. Parameters: - name (required): person name substring, case-insensitive, e.g. "Mustermann". - country (optional, default "all"): "AT" | "DE" | "all". - page_size (optional, default 25): results per country. - status (optional, default "all"): "active" | "inactive" | "all". Returns the merged search_companies envelope ({countries, results, per_country, notices}) plus ``person_query``; every result card carries ``country``, ``company_id`` and the matched manager. AT matches the primary managing director, DE matches all managing directors AND registered signatories. IMPORTANT: matching is by name and the registers publish birth YEAR only - a shared name across companies or countries does not prove the same person (the notice says so; use birth years and context to corroborate). For general company search use search_companies with other filters; manager_name can be combined there too.ConnectorNo auth
- Get a Stripe billing portal URL for managing payment methods and invoices. Returns a URL (not a redirect) that the human can open in a browser. Requires: API key with read scope. Args: flow: Optional. Set to "payment_method_update" to go directly to the payment method update page. Returns: {"url": "https://billing.stripe.com/p/session/..."}ConnectorNo auth
Matching MCP Servers
- MIT
- AlicenseAqualityAmaintenanceEnables searching and reading AWS knowledge from sources the official AWS Knowledge MCP Server does not index, including re:Post community Q&A, kiro.dev documentation, and AWS Builder Center posts.3Apache 2.0
Matching MCP Connectors
The AWS Knowledge MCP server is a fully managed remote Model Context Protocol server that provides real-time access to official AWS content in an LLM-compatible format. It offers structured access to AWS documentation, code samples, blog posts, What's New announcements, Well-Architected best practices, and regional availability information for AWS APIs and CloudFormation resources. Key capabilities include searching and reading documentation in markdown format, getting content recommendations, listing AWS regions, and checking regional availability for services and features.
MCP server for Environment & Nature
- Add a new operation to the LIVE catalog so it's reusable via connections_execute - the self-improvement path when an op is missing. TWO lanes, both SSRF-guarded (rows stamped source='agent-added'): (1) AWS - server_url host must be *.amazonaws.com; the SigV4 signing sub-service is auto-derived from the host (lambda.us-east-1.amazonaws.com → 'lambda'), pass `aws_service` to override; set protocol (query|json|rest-json) + action+version OR target+jsonVersion. (2) NON-AWS connected service (cloudflare/github/stripe/…) - pass `service` (the connected-service slug) and the server_url host must match that service's code-level host allowlist; an unnamed auth `scheme` is INHERITED from that service's own existing catalog rows (`bearer` only when the service has no rows yet), an explicit `scheme` still wins (basic|apikey|header|oauth2|query also supported; apikey/header take `header`+`headerPrefix`, query REQUIRES `param`) - the response names which via `auth_scheme_source` and carries a `warning` if the resolved scheme disagrees with what the rest of the service uses. For a one-off AWS call prefer `aws_call`; to remove/repair a row, connections_catalog_remove (or re-add to upsert). Common params: tool_name ([a-z0-9_]), method, path, server_url, summary, description, parameters ({params:[{name,in,required}]}), tags, destructive, safety_score.ConnectorDestructiveOAuth
- Creates (or updates) a persistent per-org rule mapping a counterparty to an account, then BACK-APPLIES it to every pending review event from that counterparty — each is properly approved (journal lines written, audit entry, ledger sync queued), not bulk edited. After this, future events from the counterparty auto-classify and never reach review. This is how you act on get_pending_by_counterparty: "categorise all my AWS as infrastructure" becomes one call. This WRITES financial data — only call it with an account you are confident in. The counterparty is matched on a normalised key, so "AWS, Inc." and "AWS EMEA" resolve to the same rule. Idempotent: re-running updates the single rule and re-approves nothing already approved. actor_id is optional — it defaults to the organisation entity, and if provided must belong to this org. GUARDRAIL (OOB approval): if the rule would back-apply to an unusually large set (many events, a large aggregate, or a large rolling-hour total across recent applies), it returns status "approval_required" and writes ONLY an approval request — YOU CANNOT BOOK IT YOURSELF; confirm:true does not bypass it. Your human gets an email and approves on the dashboard, at which point the action books automatically — do NOT retry the call; verify later by re-reading the books (e.g. get_pending_by_counterparty). If the response says the request was denied recently, do not re-ask for 24h. Small approvals apply immediately (status "applied").ConnectorOAuth
- Set a single environment variable on an app and roll it out. Call this when an app needs plain configuration such as LOG_LEVEL or a feature flag. For secrets (API keys, passwords, tokens) call set_app_secret instead: this tool rejects secret-looking keys.ConnectorNo auth
- Check the current health status for one or more vendors. Accepts registered vendor slugs (e.g., "github", "aws", "gcp", "gitlab") or raw Atlassian Statuspage base URLs. Registry entries are served by each vendor's native status API (Statuspage, Status.io, Slack, AWS Health, Google Cloud Service Health, Azure status, Firehydrant) and normalized to one shape. Returns per-vendor operational indicator (none = all clear, minor, major, critical, maintenance = scheduled window), degraded components, and active incidents. Use mode: "detailed" for component lists and maintenance windows, narrowed with component_filter and bounded by component_limit. Batch-friendly — pass a list to check your full stack in one call; a vendor that cannot be resolved or reached is reported in its own result row, so one bad entry never discards the rest. Every vendor with an active problem gets a pre-filled devops_suggest_action call in nextToolSuggestions.ConnectorNo auth
- List the environments belonging to one shared GROUP — a group holds a separate value set per slug, so its `production` differs from its `staging`. Use this when you already have a group and want its own environments; use list_envs for an application's, and list_env_groups to see which groups an application environment pulls from. Returns Environment rows with `groupId` set: [{ id, name, slug, groupId, createdAt }].ConnectorNo auth
- Compose a shared group into an application environment, so that environment resolves the group's secrets as well as its own. Safe to repeat — composing an already-composed group just updates its position. Use uncompose_group to undo, and list_env_groups to see the current order. No key material involved, so it runs here. Returns the composed { groupId, slug, name, position }.ConnectorNo auth
- Remove a composed group from an application environment. The group and its secrets are untouched — only the link is dropped — but the environment stops resolving every name it inherited from that group, which will break a workload still reading one. Check list_env_groups first, and use delete_group to destroy the group itself. Safe to repeat. Returns { ok: true }.ConnectorNo auth
- Delete a secret from an environment, discarding its ciphertext and every version. Irreversible — restore_secret CANNOT bring it back (that only rolls back within a surviving secret's history), and re-creating it means setting the value again on the local crypto plane. Prefer restore_secret to undo a bad write. Confirm intent before calling. Returns { ok, name } — or { ok, queued: true, changeRequestId } if the environment requires approval, in which case NOTHING was deleted until a human approves.ConnectorDestructiveNo auth
- Updates an event. `title`, `start` and `end` describe the complete new state — including whether it is all-day: an event created all-day becomes a timed event if this call passes timestamps, and vice versa. Two kinds of event are addressable: 1. Events THIS access created (via `event_id` from create_event) — always. 2. Any other event in a calendar the user allowed managing, visible in `list_calendars` as `manageable: true`. Their ids come from `get_availability`. Four things are refused, and each says what to do instead — pass that on rather than retrying: • the calendar is not released for managing (the user can allow it per calendar) • it is shared at less than full detail (a setting, not a temporary error) • the event is a synchronised COPY — change the original in the named source calendar, the change reaches this one by itself • someone else organises it — call `respond_to_event` with `response: "declined"` and the same `event_id` insteadConnectorDestructiveAPI key
- List available browser environments (persistent profiles) for this account. Returns environment IDs needed for persistent sessions in browser_task or create_session. Read-only. NOTE: workflows and agents use the connection's environment automatically — you rarely need this tool for those, and should not ask the user to choose an environment.ConnectorNo auth
- Promotes a tested deployment into the next environment (development -> uat, uat -> production). Reuses the already-built artifact rather than rebuilding, so the bytes that were tested are the bytes that ship. Promotion into an environment that requires approval will be refused until the approval exists. For production, submit the request first.ConnectorNo auth
- List the cost-source providers (AWS, GCP, Anthropic, etc.) enabled for this account. Each row's cost_basis says where that provider's money figures come from: "invoiced" = amounts the provider actually charged; "estimated_from_provider_rates" = an estimate built from the provider's own published rates, because it exposes no historical billing API; "estimated_from_static_rates" = an estimate built from a list-rate card Plutus maintains, which will not reflect rates the customer negotiated. Qualify any total that includes an estimated source rather than reporting it as billed spend.ConnectorNo auth
- Create a NEW architecture diagram from a graph that YOU author, and get back a shareable, editable canvas URL plus a rendered SVG and Mermaid. You produce only the SEMANTICS — nodes, the groups (VPC/cluster/...) they live in, and the directed edges between them. You do NOT lay anything out: never send x/y/position/pinned. A deterministic layout engine computes all geometry and an icon layer picks the pictures from each node's kind. kind.catalog is one of aws | gcp | azure | k8s | saas | generic, each with rich per-catalog kind.types (e.g. aws:lambda, gcp:bigquery, azure:cosmos_db, k8s:deployment, saas:kafka): - "aws" (api_gateway, lambda, s3, rds, dynamodb, sqs, bedrock, kinesis, fargate, eventbridge, aurora, ...). - "gcp" (compute_engine, gke, cloud_run, cloud_sql, spanner, firestore, bigquery, pubsub, dataflow, vertex_ai, ...). - "azure" (virtual_machine, aks, app_service, functions, blob_storage, sql_database, cosmos_db, service_bus, event_hubs, key_vault, ...). - "k8s" (pod, deployment, statefulset, daemonset, job, cronjob, service, ingress, configmap, secret, hpa, ...). - "saas" for hosted third-parties (redis, postgresql, mysql, mongodb, kafka, stripe, twilio, auth0, github, cloudflare, ...). - "generic" primitive when nothing branded fits: service, database, cache, queue, user, external_system, storage, gateway, function, note. - "generic" FLOWCHART kinds for processes/flowcharts: process, decision, terminator, data, document, subprocess. edge.kind is one of: request, response, async_event, data_flow, dependency, network, generic. WORKED EXAMPLE — a user hitting an API in a VPC that talks to Postgres: { "title": "Web API", "domain": "cloud_architecture", "graph": { "groups": [{ "id": "g_vpc", "label": "VPC", "type": "vpc" }], "nodes": [ { "id": "n_user", "label": "User", "kind": { "catalog": "generic", "type": "user" } }, { "id": "n_api", "label": "API", "kind": { "catalog": "aws", "type": "api_gateway" }, "parentId": "g_vpc" }, { "id": "n_db", "label": "Postgres", "kind": { "catalog": "aws", "type": "rds" }, "parentId": "g_vpc" } ], "edges": [ { "id": "e1", "source": "n_user", "target": "n_api", "kind": "request" }, { "id": "e2", "source": "n_api", "target": "n_db", "kind": "data_flow" } ] } } Returns { diagramId, url, svg, mermaid, version }. Give the user the url — opening it shows the same diagram on an editable canvas (anonymous; it's theirs to claim by signing in). To change the diagram afterwards, use get_diagram then edit_diagram.ConnectorNo auth
- List which version each environment currently pins for this spec, whether the pin is frozen, and where it came from. Use this to see what each environment resolves to; to change a pin use promote_version. Requires project context.ConnectorAPI key
- List your personal variables for one environment. They override both organization and environment variables and are visible only to you. Secret values are always masked. Use this for your own layer; for the merged result of all three use resolve_variables. Requires organization context.ConnectorAPI key