Early access — The platform is open but still being completed; features and prices may change before general availability.

AI agents (MCP)

Connect Claude Code, Claude Desktop, Cursor or any MCP client to your platform and let an agent read and act on your projects, as you, within the scopes you grant.

The control plane is an MCP server: any client that speaks the Model Context Protocol can list your projects, read deployment status and metrics, attach components, deploy, and even delete a project — always as you, on the projects you are a member of, and only within the scopes you granted.

Connect a client

The server lives at /mcp on your platform URL, over Streamable HTTP, and authenticates with OAuth 2.1. Clients discover everything from the URL.

Claude Code:

claude mcp add --transport http idp https://app.fmjconsulting.fr/mcp

Claude Desktop, Cursor and similar clients take the same URL in their MCP server settings ("type": "http", "url": "https://app.fmjconsulting.fr/mcp").

The first call opens your browser: sign in as usual (two-factor included), then a consent page names the client and the scopes it asks for. Allow hands the client a one-hour token that renews itself while you keep using it; Deny sends the client away with nothing.

Scopes

ScopeLets the agent
idp:readlist projects, read a project's snapshot, components, deployability, catalog, metrics, your plan; poll a pipeline
idp:writeattach and detach components
idp:deploydeploy or replace a component, start or stop its machine, refresh metrics
idp:admindelete a project (its infrastructure is destroyed first)

A client that was not granted a scope gets a clear refusal from every tool behind it and can ask you to re-authorize.

What the tools do and do not do

  • Every tool calls the platform's own API in your name: the same membership checks, the same validation, the same audit trail apply. An agent can do nothing a signed-in you could not.
  • Every write tool takes confirm: true. Without it the tool answers with what it would do and does nothing; agents describe first, act second. delete_project also asks for the exact project name.
  • Deployments return a pipeline to poll with poll_deployment; polling settles the records exactly as the Deploy page does. The full "Deploy all" chain (network, storage, volumes, then components) stays on the Deploy page in this version; agents deploy and reconfigure components one by one.
  • Secret values (passwords, passcodes, credentials) never cross the MCP boundary — an agent can see that a secret is set, never what it is.

Revoking access

Your account page lists the AI clients you authorized, with their scopes and live tokens. Revoke deletes the client's tokens and consent and ends the sessions it opened; it has to go through the consent page again to act. Access tokens expire after one hour on their own.

Plan

AI tools are part of the Team and Enterprise plans (ai_tools). On the First access and Starter plans the connection succeeds but every tool answers that AI tools are not part of your plan.

© 2026 FMJConsulting. All rights reserved.