In one paragraph: @rarecloudio/mcp-server is the official Model Context Protocol server for RareCloud. It runs on your machine over stdio, talks to the public API at https://api.rarecloud.io/v1 with an API token you create, and gives your agent 173 tools: 86 that read and 87 that act. Tools that spend money, delete something, interrupt something running or touch access do nothing unless the call carries confirm: true. This page covers version 0.3.0. The source is on GitHub under the MIT licence.
Before you start
- Node.js 21 or newer. The package declares
node >= 21and the clients below start it withnpx. - A RareCloud account and an API token (next section).
- An MCP client: Claude Code, Claude Desktop, Cursor, Windsurf or any other client that can launch a stdio server.
Create an API token
In the console open Account, then API tokens, then New token. Give it a name, pick its scopes, and optionally an expiry date and a rate limit (1 to 600 requests a minute). The token starts with rc_pat_ and is shown once, so copy it before you close the dialog.
The MCP server reads the token from the environment variable RARECLOUD_API_TOKEN. (The CLI and the Terraform provider use RARECLOUD_TOKEN instead.)
Scopes
| Scope | Lets the agent |
|---|---|
account:read / account:write | Read the profile, limits, SSH keys, contacts and activity / update profile fields, account SSH keys and contacts |
services:read / services:write | Read services and cloud resources / deploy, resize, power, destroy, and manage VMs, Kubernetes, volumes, networks, reserved IPs, firewalls, load balancers, Object Storage and proxies. check_order also needs services:write, because it answers whether this token can order |
billing:read / billing:write | Read invoices, balance, ledgers and billing state / set or remove the spend alert, redeem a voucher |
domains:read / domains:write | Read domains, DNS and TLD prices / register, transfer, renew and manage domains |
tickets:read / tickets:write | Read tickets / open, reply to and close tickets |
* | Everything above |
Scope matching is exact. services:write does not include services:read, so give an agent that reads and acts both scopes. Patterns like *:read are not supported. The tool list is the same whatever the token holds: an under-scoped call comes back from the API as a permission error.
A sensible start: a read-only token (account:read, services:read, billing:read, domains:read, tickets:read). Add a :write scope when you want the agent to act in that area.
Install
Claude Code
claude mcp add rarecloud -e RARECLOUD_API_TOKEN=rc_pat_... -- npx -y @rarecloudio/mcp-server
Options such as -e go before the server name; the command that starts the server goes after --. Add -s user to make it available in every project instead of only the current one. Check it with claude mcp list.
Claude Desktop
Edit ~/Library/Application Support/Claude/claude_desktop_config.json on macOS or %APPDATA%\Claude\claude_desktop_config.json on Windows, then restart Claude Desktop:
{
"mcpServers": {
"rarecloud": {
"command": "npx",
"args": ["-y", "@rarecloudio/mcp-server"],
"env": { "RARECLOUD_API_TOKEN": "rc_pat_..." }
}
}
}
Cursor
Put the same block in ~/.cursor/mcp.json (all projects) or .cursor/mcp.json in a project:
{
"mcpServers": {
"rarecloud": {
"command": "npx",
"args": ["-y", "@rarecloudio/mcp-server"],
"env": { "RARECLOUD_API_TOKEN": "rc_pat_..." }
}
}
}
Windsurf
Windsurf reads ~/.codeium/windsurf/mcp_config.json. Add the same mcpServers block and refresh the MCP servers in Windsurf's settings.
Any other MCP client
Run npx -y @rarecloudio/mcp-server as a stdio server with RARECLOUD_API_TOKEN in its environment. You can also install it globally with npm install -g @rarecloudio/mcp-server and run the rarecloud-mcp binary.
Optional: another API endpoint
RARECLOUD_API_ENDPOINT changes the API base URL. It defaults to https://api.rarecloud.io and you only need it for a staging instance.
How write gating works
Three layers decide what an agent can do, from the outside in:
-
Token scopes. The API checks them on every request. A token without
services:writecannot deploy anything, whatever the agent tries. -
The confirm gate. Every write tool has one safety kind. 63 of the 87 are gated and refuse to run unless the call passes
confirm: true:- spends: places an order or charges the account (deploy, resize, renew, register, reserve an IP, add a node pool, create a bucket);
- destructive: cannot be undone (destroy, delete, cancel, revoke, release, reinstall);
- disruptive: can be undone but interrupts something running or locks someone out (stop, reboot, detach, move a VM to another network, roll a node pool, replace DNS or credentials);
- sensitive: grants access or speaks for you (install an SSH key, mint a long-lived kubeconfig, change a bucket's settings, create an S3 key, edit domain contacts or the account profile, open or reply to a ticket).
Without
confirm: truea gated tool makes no API call at all and says what it would have done, so the agent has to come back to you first. There is no "confirm once, run many". The other 24 write tools are plain: they cost nothing, tear nothing down and run as soon as the scope allows. -
No tool at all. Some things are left out on purpose: password and 2FA changes, sub-user invites, payment methods, API token management, credit top-ups, invoice payment, affiliate activation or withdrawal, and the per-resource API access switch. A token with
*still cannot reach them through MCP.
Destructive and disruptive tools also carry the MCP destructiveHint annotation, and every read tool carries readOnlyHint, so clients that show their own approval prompts can treat them accordingly. A few tools return a live secret (kubeconfigs, proxy credentials, S3 secret keys, one-time console passwords); their descriptions tell the agent not to repeat the value back unless you ask.
Resources you made read-only
In the console you can switch API access off for any single service or domain: a VM, cluster, volume, load balancer, network, proxy or hosting plan. The agent can still list it and read its details (it shows apiAccess: "read_only", and list_api_access lists every such resource in one call), but every change to it, and every read of its credentials, is refused with RESOURCE_PROTECTED and a link to the console. Only you can turn it back on, signed in to the console: there is no tool for the switch.
Safe retries
The 40 write tools that create or change something through a route the API protects with an Idempotency-Key take an optional idempotency_key (1 to 255 printable characters). Reuse the same value when retrying the same request and the API runs it at most once, returning the first answer again. Without one, the server makes a fresh key per call and, if the connection drops before the answer arrives, retries once with that key. A replayed answer says it is a replay, and a secret from the first answer (a console password, an S3 secret key) is not repeated. The confirm gate still comes first: without confirm: true no key is made and no request is sent.
Every tool, by area
Generated from the 0.3.0 release. "Write" tools without a gate are plain changes that cost nothing and tear nothing down, and they run as soon as the token's scope allows.
Catalog (8 read, 0 write)
| Tool | What it does | Type |
|---|---|---|
list_catalog_products | Orderable products in the catalog (filter by kind / backend) | Read |
get_catalog_plan | Full product detail: plans (sizes), specs, per-cycle pricing, billing tracks | Read |
list_regions | Available datacenter regions | Read |
list_images | OS images (Ubuntu / Debian / Rocky / Windows Server / …) installable on new servers; only deployable images are listed | Read |
get_product_details | Order-ready detail for one SKU: cycles + prices, plans, config options | Read |
list_prepurchase_os_templates | OS templates selectable at purchase time for a VPS / dedicated SKU | Read |
list_catalog_listings | Deploy-wizard product cards for one category (the console "create" tiles) | Read |
list_kubernetes_versions | Managed-Kubernetes (Gardener) versions on offer, newest-supported first | Read |
Services (11 read, 21 write)
| Tool | What it does | Type |
|---|---|---|
list_services | All services in the account: VPS, cloud VMs, proxies, hosting, domains (each with apiAccess); a first "partial results" note when some categories could not be loaded | Read |
get_service | Full detail for one service: status, network, billing state, usage, apiAccess; for a cloud VM also tags and bandwidthUsage | Read |
get_service_metrics | CPU / RAM / disk / bandwidth time series for one service | Read |
list_backups | Backups for one legacy VPS | Read |
get_provisioning_state | Setup state of a pending service (paid? VM exists yet? stuck?) | Read |
list_os_templates | Operating systems a legacy VPS can be reinstalled with | Read |
list_upgrade_options | Plans + cycles a service could upgrade / downgrade to | Read |
get_service_iso | Mounted-ISO status for a legacy VPS (is a rescue/install ISO attached?) | Read |
list_service_ssh_key_library | SSH keys registered in a legacy VPS's key library | Read |
get_service_autorenew | Whether a service auto-renews from account balance | Read |
check_order | Would deploy_service be accepted right now? Same body, creates and reserves nothing; on a refusal returns the message plus the Add funds or Pay invoice link for the human (needs services:write) | Read |
set_service_hostname | Rename a service (legacy VPS hostname, or the cloud VM's server name) | Write |
deploy_service | Deploy (order + provision) a new service: polymorphic across VM / k8s / volume / load-balancer / network / proxy / domain; load balancers, volumes and networks take no SKU (call check_order first; returns a: live secret) | Write. Spends, needs confirm |
destroy_service | Permanently destroy a service and release its resources (also load balancers, volumes and private networks by id) | Write. Destructive, needs confirm |
resize_service | Resize a cloud VM to a new flavor/plan | Write. Spends, needs confirm |
upgrade_service | Create an upgrade order moving a service to a new product/plan | Write. Spends, needs confirm |
renew_service | Ensure a renewal invoice exists for a service | Write. Spends, needs confirm |
cancel_service | File a cancellation request: immediate or end-of-term | Write. Destructive, needs confirm |
set_service_autorenew | Toggle auto-renew for a service | Write |
create_service_backup | Create an on-demand backup of a legacy VPS | Write |
mount_service_iso | Mount a rescue/install ISO on a VPS | Write |
unmount_service_iso | Unmount the currently mounted ISO from a VPS | Write |
set_service_password | Set the root/administrator password of a legacy VPS | Write. Disruptive, needs confirm |
start_service | Power on a service | Write |
stop_service | Power off a service | Write. Disruptive, needs confirm |
reboot_service | Reboot a service | Write. Disruptive, needs confirm |
reinstall_service | Reinstall (rebuild from scratch) a service, wiping the disk (returns a: live secret) | Write. Destructive, needs confirm |
reset_service_password | Reset the root password live via qemu-guest-agent, on a running cloud VM | Write. Disruptive, needs confirm |
add_service_ssh_key | Install an SSH public key directly onto a running service | Write. Sensitive, needs confirm |
add_service_ssh_key_to_library | Register an SSH key in a legacy VPS's reinstall-time key library | Write |
apply_service_ssh_key_library | Apply a set of library SSH keys to a legacy VPS, replacing the current set | Write. Disruptive, needs confirm |
set_service_tags | Replace a cloud VM's tags (the whole set; [] clears them) | Write |
Orders (2 read, 0 write)
| Tool | What it does | Type |
|---|---|---|
list_orders | The account's orders: the purchase records behind its services | Read |
get_order | One order: line items, status, payment status, and its invoice | Read |
Billing (11 read, 3 write)
| Tool | What it does | Type |
|---|---|---|
list_invoices | Invoice history: number, status, issued date, total | Read |
get_invoice | Full invoice detail: line items, taxes, payment method + timestamp | Read |
get_credit_balance | Current prepaid credit balance | Read |
get_credit_ledger | Credit movements (top-ups, vouchers, metering debits, refunds) | Read |
get_invoice_pay_preview | Preview what paying an invoice from balance would consume (bonus → credit → shortfall) | Read |
list_payment_methods | Available payment options | Read |
get_billing_campaign | The active credit (deposit-match) promo, or none | Read |
get_bonus_balance | Promo (bonus) balance, in cents (EUR) | Read |
get_bonus_ledger | Bonus-credit ledger: campaign grants and promo consumption | Read |
get_billing_alert | Spending-alert state: threshold, month-to-date spend, triggered? | Read |
get_billing_state | Cloud auto-suspend state (normal / grace-period / suspended) | Read |
set_billing_alert | Set (or update) the month-to-date spend alert | Write |
delete_billing_alert | Remove the month-to-date spend alert | Write. Destructive, needs confirm |
redeem_voucher | Redeem a credit voucher / promo code (adds credit: never spends) | Write |
Account (11 read, 6 write)
| Tool | What it does | Type |
|---|---|---|
get_account | Profile: email, name, country, billing currency, creation date | Read |
list_ssh_keys | SSH keys on a specific server (legacy VPS) | Read |
get_account_limits | Resource limits and current usage (servers / vCPUs / IPs / volumes / …) | Read |
list_account_clients | Users linked to this client account (accepted members + pending invites) | Read |
get_affiliate | Affiliate status + stats: referral link, conversions, commissions, payouts | Read |
get_two_factor_status | Whether 2FA (TOTP) is enabled on the account | Read |
list_account_ssh_keys | Account-wide SSH public keys (offered at deploy time) | Read |
get_account_activity | Account audit trail: sign-ins, 2FA changes, service + billing actions | Read |
list_account_emails | Emails sent to this account, newest first | Read |
list_account_contacts | Billing / technical contacts (email-copy recipients, no login) | Read |
list_api_access | Resources the user made read-only for agents and API tokens (check before planning changes) | Read |
update_account | Update the account's billing / contact profile | Write. Sensitive, needs confirm |
add_account_ssh_key | Add an account-wide SSH public key | Write |
delete_account_ssh_key | Delete an account-wide SSH key | Write. Destructive, needs confirm |
resend_email_verification | Resend the account's email-verification email | Write |
manage_account_contact | Add, update, or delete a billing/technical contact | Write. Sensitive, needs confirm |
create_affiliate_link | Mint a signed affiliate referral link (no money movement) | Write |
Cloud infrastructure (10 read, 21 write)
| Tool | What it does | Type |
|---|---|---|
list_volumes | Block-storage volumes: id, name, size, status, attachment, region | Read |
get_volume | One block-storage volume and which VM it is attached to | Read |
list_networks | Private networks (VPCs): id, name, CIDR, status, attached VM count | Read |
get_network | One private network (VPC) and its attached VMs | Read |
list_load_balancers | L4 load balancers: id, name, status, public IP, port, member count | Read |
get_load_balancer | One load balancer with its members (backend VMs + ports) | Read |
list_load_balancer_members | Backend members of a load balancer (private fixed IP + port) | Read |
list_reserved_ips | Reserved (static) public IPs and their attachments | Read |
list_firewalls | Cloud firewalls (security groups): status, attached VMs, rule count | Read |
get_firewall | One firewall with its full rule set and attached VMs | Read |
create_volume | Create a new block-storage volume | Write. Spends, needs confirm |
delete_volume | Delete a block-storage volume permanently | Write. Destructive, needs confirm |
attach_volume | Attach a volume to a cloud VM | Write |
detach_volume | Detach a volume from a cloud VM | Write. Disruptive, needs confirm |
create_network | Create a new private network (VPC) | Write |
delete_network | Delete a private network (VPC) | Write. Destructive, needs confirm |
attach_network_vm | Move a cloud VM into a private network | Write. Disruptive, needs confirm |
reserve_ip | Reserve a new static public IP | Write. Spends, needs confirm |
release_reserved_ip | Release (permanently delete) a reserved public IP | Write. Destructive, needs confirm |
attach_reserved_ip | Attach a reserved public IP to a cloud VM | Write |
detach_reserved_ip | Detach a reserved public IP from its VM | Write. Disruptive, needs confirm |
create_firewall | Create a new cloud firewall (security group) | Write |
delete_firewall | Delete a cloud firewall | Write. Destructive, needs confirm |
add_firewall_rule | Add an inbound/outbound rule to a firewall | Write |
delete_firewall_rule | Remove a rule from a firewall | Write. Destructive, needs confirm |
attach_firewall | Attach a firewall to a cloud VM | Write |
detach_firewall | Detach a firewall from a cloud VM | Write. Disruptive, needs confirm |
create_load_balancer | Create a new L4 load balancer (VIP + listener + pool + floating IP); returns at once with status pending, poll get_load_balancer until active | Write. Spends, needs confirm |
delete_load_balancer | Delete a load balancer; deleted at once, or deleting when it was still being set up | Write. Destructive, needs confirm |
add_load_balancer_member | Add a VM as a member of a load-balancer pool | Write |
remove_load_balancer_member | Remove a member from a load-balancer pool | Write. Destructive, needs confirm |
Object Storage (7 read, 7 write)
| Tool | What it does | Type |
|---|---|---|
get_object_storage | The S3-compatible storage service: status, namespace handle, price card, month-to-date charge, limits (null if not enabled) | Read |
list_object_storage_regions | Regions a bucket can be created in, with their S3 endpoints | Read |
get_object_storage_usage | Daily usage series for the account: stored bytes, egress, CDN traffic (1-90 days) | Read |
list_buckets | Buckets: id, full name, region, status, versioning, size | Read |
get_bucket | One bucket: endpoint and URLs, versioning, size and object count | Read |
get_bucket_usage | Daily usage series for one bucket (1-90 days) | Read |
list_object_storage_keys | S3 access keys: id, name, access key id, scope, status (never the secret) | Read |
enable_object_storage | Enable Object Storage (starts the monthly base fee); optional, the first bucket does it too | Write. Spends, needs confirm |
disable_object_storage | Delete the storage account for good (only once every bucket is deleted and every key revoked) | Write. Destructive, needs confirm |
create_bucket | Create a bucket (the first one enables or wakes the service and its base fee) | Write. Spends, needs confirm |
update_bucket | Toggle a bucket's versioning. Public delivery is not available yet and is refused | Write. Sensitive, needs confirm |
delete_bucket | Delete a bucket; purge:true deletes every object in it first | Write. Destructive, needs confirm |
create_object_storage_key | Create an S3 access key scoped to buckets + read/readwrite (returns a: live secret, shown once) | Write. Sensitive, needs confirm |
delete_object_storage_key | Revoke an S3 access key | Write. Destructive, needs confirm |
Managed Kubernetes (5 read, 8 write)
| Tool | What it does | Type |
|---|---|---|
get_cluster_scale | Current scale of a managed K8s cluster: node pools + add-ons | Read |
list_cluster_pools | Worker node pools: name, machine type, count, autoscale min/max | Read |
get_cluster_kubeconfig | Short-lived admin kubeconfig (expires in hours): live secret | Read |
list_cluster_kubeconfigs | Long-lived kubeconfig credentials, metadata only (token never returned) | Read |
download_cluster_kubeconfig | Re-download a long-lived credential's kubeconfig (active-only): live secret | Read |
set_cluster_scale | Set the autoscaling bounds of a cluster's first node pool | Write. Disruptive, needs confirm |
add_cluster_pool | Add a named worker node pool | Write. Spends, needs confirm |
update_cluster_pool | Edit an existing node pool's bounds / machineType / volume size | Write. Disruptive, needs confirm |
delete_cluster_pool | Remove a worker node pool | Write. Destructive, needs confirm |
rename_cluster_pool | Rename a worker node pool (rolls its nodes) | Write. Disruptive, needs confirm |
enable_cluster_ha | Enable the HA control plane: add-only, irreversible | Write. Spends, needs confirm |
create_cluster_kubeconfig | Mint a long-lived, revocable kubeconfig credential (returns a: live secret) | Write. Sensitive, needs confirm |
revoke_cluster_kubeconfig | Revoke a long-lived kubeconfig credential | Write. Destructive, needs confirm |
Domains (8 read, 7 write)
| Tool | What it does | Type |
|---|---|---|
list_domains | Registered domains: id, name, status, expiry, auto-renew, apiAccess | Read |
get_domain | One domain: nameservers, transfer lock, WHOIS privacy, auto-renew, expiry, apiAccess | Read |
check_domain_availability | Whether a domain name is available to register | Read |
get_tld_pricing | Register / transfer / renew prices per TLD, in the account currency | Read |
get_domain_nameservers | Nameservers currently set on an owned domain | Read |
get_domain_contacts | Registrant WHOIS contact on an owned domain | Read |
get_domain_dns | DNS host records on an owned domain (A / CNAME / MX / TXT / …) | Read |
get_domain_management | Combined management snapshot for an owned domain in one call | Read |
register_domain | Register a new domain name | Write. Spends, needs confirm |
transfer_domain | Transfer a domain in from another registrar | Write. Spends, needs confirm |
renew_domain | Renew an owned domain | Write. Spends, needs confirm |
set_domain_nameservers | Replace an owned domain's nameservers (2-5) | Write. Disruptive, needs confirm |
set_domain_contacts | Update an owned domain's registrant WHOIS contact | Write. Sensitive, needs confirm |
set_domain_dns | Replace an owned domain's DNS host records | Write. Disruptive, needs confirm |
manage_domain | Dispatch a single domain management action (nameservers / lock / autorenew / idprotect / epp) | Write. Sensitive, needs confirm |
Proxies (10 read, 11 write)
| Tool | What it does | Type |
|---|---|---|
list_proxies | Residential proxy services: id, name, flavor, status, plan, expiry | Read |
get_proxy_catalog | Proxy order-wizard catalog: ISP IP-count tiers + GB Residential buckets, pricing | Read |
get_proxy | One proxy service: flavor, status, plan, location, expiry / renewal | Read |
get_proxy_list | Live proxy endpoints + credentials for an ISP fixed-IP plan: live secret | Read |
get_proxy_auth | Auth settings for a proxy service: method, credentials, IP whitelist: live secret | Read |
list_gb_residential_countries | Countries selectable when creating a GB Residential proxy-request | Read |
list_gb_rotation_intervals | Rotation intervals selectable for a GB Residential proxy-request | Read |
list_proxy_requests | Proxy-requests on a GB Residential bucket (country + rotation + count groups) | Read |
get_proxy_request_list | Live endpoints + credentials for one GB Residential proxy-request: live secret | Read |
get_proxy_replacements | IP-replacement allowance + history for a proxy service | Read |
order_proxy | Order a new residential proxy plan: ISP or GB Residential (returns a: live secret) | Write. Spends, needs confirm |
renew_proxy | Renew a proxy service for another billing term | Write. Spends, needs confirm |
set_proxy_auto_renew | Turn a proxy service's auto-renew on/off | Write |
cancel_proxy | Cancel a proxy service | Write. Destructive, needs confirm |
set_proxy_auth_method | Switch a proxy service's authentication method | Write. Disruptive, needs confirm |
set_proxy_credentials | Set a proxy service's username/password | Write. Disruptive, needs confirm |
add_proxy_whitelisted_ip | Add an IP to a proxy service's whitelist | Write |
remove_proxy_whitelisted_ip | Remove an IP from a proxy service's whitelist | Write. Destructive, needs confirm |
request_proxy_replacement | Request an IP replacement, consuming the monthly allowance | Write. Disruptive, needs confirm |
create_proxy_request | Create a proxy-request on a GB Residential bucket | Write |
delete_proxy_request | Delete a proxy-request from a GB Residential bucket | Write. Destructive, needs confirm |
Support (3 read, 3 write)
| Tool | What it does | Type |
|---|---|---|
list_tickets | Support tickets: id, subject, status, department, last-updated | Read |
get_ticket | One support ticket with its full message thread | Read |
list_ticket_departments | Support departments + their ids (for opening a ticket) | Read |
create_ticket | Open a support ticket | Write. Sensitive, needs confirm |
reply_ticket | Post a reply to an existing support ticket | Write. Sensitive, needs confirm |
close_ticket | Close a support ticket | Write |
Recipes
Type these to your agent. Each one names the tools it should use, so you can check what it did in the tool log.
Deploy a VM. "Deploy a Cloud VM named web-01 in Bucharest on plan g-2vcpu-8gb with Ubuntu 24.04 and my SSH key. Show me the price first." The agent reads the plan with get_product_details, list_regions and list_images, checks with check_order that the order would be accepted, shows you the cost, and after your yes calls deploy_service with category: "cloud-vm", productId: "g-2vcpu-8gb", region: "bucharest-ro", imageId: "ubuntu-24.04" and confirm: true. Then get_provisioning_state until it is running.
Add a volume. "Create a 50 GB volume called web-01-data and attach it to web-01." Uses create_volume (spends, needs your confirm), then attach_volume. Format and mount it inside the VM yourself.
Put a load balancer in front. "Create a load balancer on port 443 for web-01 and web-02." Uses create_load_balancer (spends, needs confirm). It answers at once with status pending and finishes building in the background in a few minutes; the agent polls get_load_balancer until it is active instead of creating it again. It costs €9 a month with its public IP included, billed hourly.
Create a bucket and a key. "Create a bucket called backups in Frankfurt and an access key that can only read it." Uses list_object_storage_regions, create_bucket (spends: the first bucket starts the monthly base fee and needs a handle, your permanent namespace) and create_object_storage_key (sensitive, returns the secret once).
Create a cluster and get a kubeconfig. "Which Kubernetes versions can I pick? Create a cluster with 2 to 4 workers on g-2vcpu-8gb, then give me a 90-day view-only kubeconfig for CI." Uses list_kubernetes_versions (the versions on offer, newest first; a cluster created without a version gets the newest), deploy_service with category: "cloud-k8s" (spends, needs confirm), then create_cluster_kubeconfig (sensitive, needs confirm). For a quick admin session, get_cluster_kubeconfig returns a short-lived one.
Check balance and invoices. "What is my balance, is anything unpaid, and what did I spend this month?" Uses get_credit_balance, get_bonus_balance, list_invoices, get_billing_state and get_billing_alert. Add "alert me if the month passes 50 euro" and it calls set_billing_alert, which flags the alert in the console when spend crosses that figure.
Destroy what you no longer need. "Delete the volume web-01-data, then destroy web-01." Uses detach_volume, delete_volume and destroy_service. The detach is disruptive and both deletions are destructive, so the agent has to ask you, and only a call with confirm: true goes through.
Troubleshooting
| What you see | What it means |
|---|---|
Set RARECLOUD_API_TOKEN to your personal access token | The variable is missing from the server's environment. In Claude Code check claude mcp get rarecloud; in a JSON config check the env block. |
A permission error (FORBIDDEN / PERMISSION_DENIED) | The token lacks the scope the tool needs. Remember :write does not include :read. |
| "... was NOT executed ..." | The tool is gated and the call had no confirm: true. Approve the action and let the agent retry. |
RESOURCE_PROTECTED | You switched API access off for that resource in the console. The agent should not retry; turn API access back on in the console if you want the change. |
IDEMPOTENCY_KEY_REUSED | The agent sent an idempotency_key it had already used for a different request. Use a new key for a new operation. |
| The server does not start | Check node --version (21 or newer) and that npx can reach the npm registry. |
429 errors | The token hit its requests-per-minute limit. Raise it on a new token or slow the agent down. |
| You want to cut the agent off | Revoke the token in Account, API tokens. It stops working immediately. |
Links
- Source and issues: github.com/RareCloudio/rarecloud-mcp-server
- Package: @rarecloudio/mcp-server on npm
- API reference: console.rarecloud.io/docs/api and the OpenAPI spec
- For agents: console.rarecloud.io/llms.txt
- The same API from a terminal or as code: CLI docs and Terraform docs