Resources·Docs

RareCloud MCP server: install, scopes and every tool

Reference for @rarecloudio/mcp-server 0.3.0: install in Claude Code, Claude Desktop, Cursor and Windsurf, token scopes, the confirm gate, safe retries, all 173 tools by area, and recipes.

By RareCloud Team · 24 min read · 7 Oct 2026 · Updated 9 Oct 2026

In one paragraph: @rarecloudio/mcp-server is the official Model Context Protocol server for RareCloud. It runs on your machine over stdio, talks to the public API at https://api.rarecloud.io/v1 with an API token you create, and gives your agent 173 tools: 86 that read and 87 that act. Tools that spend money, delete something, interrupt something running or touch access do nothing unless the call carries confirm: true. This page covers version 0.3.0. The source is on GitHub under the MIT licence.

Before you start

  • Node.js 21 or newer. The package declares node >= 21 and the clients below start it with npx.
  • A RareCloud account and an API token (next section).
  • An MCP client: Claude Code, Claude Desktop, Cursor, Windsurf or any other client that can launch a stdio server.

Create an API token

In the console open Account, then API tokens, then New token. Give it a name, pick its scopes, and optionally an expiry date and a rate limit (1 to 600 requests a minute). The token starts with rc_pat_ and is shown once, so copy it before you close the dialog.

The MCP server reads the token from the environment variable RARECLOUD_API_TOKEN. (The CLI and the Terraform provider use RARECLOUD_TOKEN instead.)

Scopes

ScopeLets the agent
account:read / account:writeRead the profile, limits, SSH keys, contacts and activity / update profile fields, account SSH keys and contacts
services:read / services:writeRead services and cloud resources / deploy, resize, power, destroy, and manage VMs, Kubernetes, volumes, networks, reserved IPs, firewalls, load balancers, Object Storage and proxies. check_order also needs services:write, because it answers whether this token can order
billing:read / billing:writeRead invoices, balance, ledgers and billing state / set or remove the spend alert, redeem a voucher
domains:read / domains:writeRead domains, DNS and TLD prices / register, transfer, renew and manage domains
tickets:read / tickets:writeRead tickets / open, reply to and close tickets
*Everything above

Scope matching is exact. services:write does not include services:read, so give an agent that reads and acts both scopes. Patterns like *:read are not supported. The tool list is the same whatever the token holds: an under-scoped call comes back from the API as a permission error.

A sensible start: a read-only token (account:read, services:read, billing:read, domains:read, tickets:read). Add a :write scope when you want the agent to act in that area.

Install

Claude Code

claude mcp add rarecloud -e RARECLOUD_API_TOKEN=rc_pat_... -- npx -y @rarecloudio/mcp-server

Options such as -e go before the server name; the command that starts the server goes after --. Add -s user to make it available in every project instead of only the current one. Check it with claude mcp list.

Claude Desktop

Edit ~/Library/Application Support/Claude/claude_desktop_config.json on macOS or %APPDATA%\Claude\claude_desktop_config.json on Windows, then restart Claude Desktop:

{
  "mcpServers": {
    "rarecloud": {
      "command": "npx",
      "args": ["-y", "@rarecloudio/mcp-server"],
      "env": { "RARECLOUD_API_TOKEN": "rc_pat_..." }
    }
  }
}

Cursor

Put the same block in ~/.cursor/mcp.json (all projects) or .cursor/mcp.json in a project:

{
  "mcpServers": {
    "rarecloud": {
      "command": "npx",
      "args": ["-y", "@rarecloudio/mcp-server"],
      "env": { "RARECLOUD_API_TOKEN": "rc_pat_..." }
    }
  }
}

Windsurf

Windsurf reads ~/.codeium/windsurf/mcp_config.json. Add the same mcpServers block and refresh the MCP servers in Windsurf's settings.

Any other MCP client

Run npx -y @rarecloudio/mcp-server as a stdio server with RARECLOUD_API_TOKEN in its environment. You can also install it globally with npm install -g @rarecloudio/mcp-server and run the rarecloud-mcp binary.

Optional: another API endpoint

RARECLOUD_API_ENDPOINT changes the API base URL. It defaults to https://api.rarecloud.io and you only need it for a staging instance.

How write gating works

Three layers decide what an agent can do, from the outside in:

  1. Token scopes. The API checks them on every request. A token without services:write cannot deploy anything, whatever the agent tries.

  2. The confirm gate. Every write tool has one safety kind. 63 of the 87 are gated and refuse to run unless the call passes confirm: true:

    • spends: places an order or charges the account (deploy, resize, renew, register, reserve an IP, add a node pool, create a bucket);
    • destructive: cannot be undone (destroy, delete, cancel, revoke, release, reinstall);
    • disruptive: can be undone but interrupts something running or locks someone out (stop, reboot, detach, move a VM to another network, roll a node pool, replace DNS or credentials);
    • sensitive: grants access or speaks for you (install an SSH key, mint a long-lived kubeconfig, change a bucket's settings, create an S3 key, edit domain contacts or the account profile, open or reply to a ticket).

    Without confirm: true a gated tool makes no API call at all and says what it would have done, so the agent has to come back to you first. There is no "confirm once, run many". The other 24 write tools are plain: they cost nothing, tear nothing down and run as soon as the scope allows.

  3. No tool at all. Some things are left out on purpose: password and 2FA changes, sub-user invites, payment methods, API token management, credit top-ups, invoice payment, affiliate activation or withdrawal, and the per-resource API access switch. A token with * still cannot reach them through MCP.

Destructive and disruptive tools also carry the MCP destructiveHint annotation, and every read tool carries readOnlyHint, so clients that show their own approval prompts can treat them accordingly. A few tools return a live secret (kubeconfigs, proxy credentials, S3 secret keys, one-time console passwords); their descriptions tell the agent not to repeat the value back unless you ask.

Resources you made read-only

In the console you can switch API access off for any single service or domain: a VM, cluster, volume, load balancer, network, proxy or hosting plan. The agent can still list it and read its details (it shows apiAccess: "read_only", and list_api_access lists every such resource in one call), but every change to it, and every read of its credentials, is refused with RESOURCE_PROTECTED and a link to the console. Only you can turn it back on, signed in to the console: there is no tool for the switch.

Safe retries

The 40 write tools that create or change something through a route the API protects with an Idempotency-Key take an optional idempotency_key (1 to 255 printable characters). Reuse the same value when retrying the same request and the API runs it at most once, returning the first answer again. Without one, the server makes a fresh key per call and, if the connection drops before the answer arrives, retries once with that key. A replayed answer says it is a replay, and a secret from the first answer (a console password, an S3 secret key) is not repeated. The confirm gate still comes first: without confirm: true no key is made and no request is sent.

Every tool, by area

Generated from the 0.3.0 release. "Write" tools without a gate are plain changes that cost nothing and tear nothing down, and they run as soon as the token's scope allows.

Catalog (8 read, 0 write)

ToolWhat it doesType
list_catalog_productsOrderable products in the catalog (filter by kind / backend)Read
get_catalog_planFull product detail: plans (sizes), specs, per-cycle pricing, billing tracksRead
list_regionsAvailable datacenter regionsRead
list_imagesOS images (Ubuntu / Debian / Rocky / Windows Server / …) installable on new servers; only deployable images are listedRead
get_product_detailsOrder-ready detail for one SKU: cycles + prices, plans, config optionsRead
list_prepurchase_os_templatesOS templates selectable at purchase time for a VPS / dedicated SKURead
list_catalog_listingsDeploy-wizard product cards for one category (the console "create" tiles)Read
list_kubernetes_versionsManaged-Kubernetes (Gardener) versions on offer, newest-supported firstRead

Services (11 read, 21 write)

ToolWhat it doesType
list_servicesAll services in the account: VPS, cloud VMs, proxies, hosting, domains (each with apiAccess); a first "partial results" note when some categories could not be loadedRead
get_serviceFull detail for one service: status, network, billing state, usage, apiAccess; for a cloud VM also tags and bandwidthUsageRead
get_service_metricsCPU / RAM / disk / bandwidth time series for one serviceRead
list_backupsBackups for one legacy VPSRead
get_provisioning_stateSetup state of a pending service (paid? VM exists yet? stuck?)Read
list_os_templatesOperating systems a legacy VPS can be reinstalled withRead
list_upgrade_optionsPlans + cycles a service could upgrade / downgrade toRead
get_service_isoMounted-ISO status for a legacy VPS (is a rescue/install ISO attached?)Read
list_service_ssh_key_librarySSH keys registered in a legacy VPS's key libraryRead
get_service_autorenewWhether a service auto-renews from account balanceRead
check_orderWould deploy_service be accepted right now? Same body, creates and reserves nothing; on a refusal returns the message plus the Add funds or Pay invoice link for the human (needs services:write)Read
set_service_hostnameRename a service (legacy VPS hostname, or the cloud VM's server name)Write
deploy_serviceDeploy (order + provision) a new service: polymorphic across VM / k8s / volume / load-balancer / network / proxy / domain; load balancers, volumes and networks take no SKU (call check_order first; returns a: live secret)Write. Spends, needs confirm
destroy_servicePermanently destroy a service and release its resources (also load balancers, volumes and private networks by id)Write. Destructive, needs confirm
resize_serviceResize a cloud VM to a new flavor/planWrite. Spends, needs confirm
upgrade_serviceCreate an upgrade order moving a service to a new product/planWrite. Spends, needs confirm
renew_serviceEnsure a renewal invoice exists for a serviceWrite. Spends, needs confirm
cancel_serviceFile a cancellation request: immediate or end-of-termWrite. Destructive, needs confirm
set_service_autorenewToggle auto-renew for a serviceWrite
create_service_backupCreate an on-demand backup of a legacy VPSWrite
mount_service_isoMount a rescue/install ISO on a VPSWrite
unmount_service_isoUnmount the currently mounted ISO from a VPSWrite
set_service_passwordSet the root/administrator password of a legacy VPSWrite. Disruptive, needs confirm
start_servicePower on a serviceWrite
stop_servicePower off a serviceWrite. Disruptive, needs confirm
reboot_serviceReboot a serviceWrite. Disruptive, needs confirm
reinstall_serviceReinstall (rebuild from scratch) a service, wiping the disk (returns a: live secret)Write. Destructive, needs confirm
reset_service_passwordReset the root password live via qemu-guest-agent, on a running cloud VMWrite. Disruptive, needs confirm
add_service_ssh_keyInstall an SSH public key directly onto a running serviceWrite. Sensitive, needs confirm
add_service_ssh_key_to_libraryRegister an SSH key in a legacy VPS's reinstall-time key libraryWrite
apply_service_ssh_key_libraryApply a set of library SSH keys to a legacy VPS, replacing the current setWrite. Disruptive, needs confirm
set_service_tagsReplace a cloud VM's tags (the whole set; [] clears them)Write

Orders (2 read, 0 write)

ToolWhat it doesType
list_ordersThe account's orders: the purchase records behind its servicesRead
get_orderOne order: line items, status, payment status, and its invoiceRead

Billing (11 read, 3 write)

ToolWhat it doesType
list_invoicesInvoice history: number, status, issued date, totalRead
get_invoiceFull invoice detail: line items, taxes, payment method + timestampRead
get_credit_balanceCurrent prepaid credit balanceRead
get_credit_ledgerCredit movements (top-ups, vouchers, metering debits, refunds)Read
get_invoice_pay_previewPreview what paying an invoice from balance would consume (bonus → credit → shortfall)Read
list_payment_methodsAvailable payment optionsRead
get_billing_campaignThe active credit (deposit-match) promo, or noneRead
get_bonus_balancePromo (bonus) balance, in cents (EUR)Read
get_bonus_ledgerBonus-credit ledger: campaign grants and promo consumptionRead
get_billing_alertSpending-alert state: threshold, month-to-date spend, triggered?Read
get_billing_stateCloud auto-suspend state (normal / grace-period / suspended)Read
set_billing_alertSet (or update) the month-to-date spend alertWrite
delete_billing_alertRemove the month-to-date spend alertWrite. Destructive, needs confirm
redeem_voucherRedeem a credit voucher / promo code (adds credit: never spends)Write

Account (11 read, 6 write)

ToolWhat it doesType
get_accountProfile: email, name, country, billing currency, creation dateRead
list_ssh_keysSSH keys on a specific server (legacy VPS)Read
get_account_limitsResource limits and current usage (servers / vCPUs / IPs / volumes / …)Read
list_account_clientsUsers linked to this client account (accepted members + pending invites)Read
get_affiliateAffiliate status + stats: referral link, conversions, commissions, payoutsRead
get_two_factor_statusWhether 2FA (TOTP) is enabled on the accountRead
list_account_ssh_keysAccount-wide SSH public keys (offered at deploy time)Read
get_account_activityAccount audit trail: sign-ins, 2FA changes, service + billing actionsRead
list_account_emailsEmails sent to this account, newest firstRead
list_account_contactsBilling / technical contacts (email-copy recipients, no login)Read
list_api_accessResources the user made read-only for agents and API tokens (check before planning changes)Read
update_accountUpdate the account's billing / contact profileWrite. Sensitive, needs confirm
add_account_ssh_keyAdd an account-wide SSH public keyWrite
delete_account_ssh_keyDelete an account-wide SSH keyWrite. Destructive, needs confirm
resend_email_verificationResend the account's email-verification emailWrite
manage_account_contactAdd, update, or delete a billing/technical contactWrite. Sensitive, needs confirm
create_affiliate_linkMint a signed affiliate referral link (no money movement)Write

Cloud infrastructure (10 read, 21 write)

ToolWhat it doesType
list_volumesBlock-storage volumes: id, name, size, status, attachment, regionRead
get_volumeOne block-storage volume and which VM it is attached toRead
list_networksPrivate networks (VPCs): id, name, CIDR, status, attached VM countRead
get_networkOne private network (VPC) and its attached VMsRead
list_load_balancersL4 load balancers: id, name, status, public IP, port, member countRead
get_load_balancerOne load balancer with its members (backend VMs + ports)Read
list_load_balancer_membersBackend members of a load balancer (private fixed IP + port)Read
list_reserved_ipsReserved (static) public IPs and their attachmentsRead
list_firewallsCloud firewalls (security groups): status, attached VMs, rule countRead
get_firewallOne firewall with its full rule set and attached VMsRead
create_volumeCreate a new block-storage volumeWrite. Spends, needs confirm
delete_volumeDelete a block-storage volume permanentlyWrite. Destructive, needs confirm
attach_volumeAttach a volume to a cloud VMWrite
detach_volumeDetach a volume from a cloud VMWrite. Disruptive, needs confirm
create_networkCreate a new private network (VPC)Write
delete_networkDelete a private network (VPC)Write. Destructive, needs confirm
attach_network_vmMove a cloud VM into a private networkWrite. Disruptive, needs confirm
reserve_ipReserve a new static public IPWrite. Spends, needs confirm
release_reserved_ipRelease (permanently delete) a reserved public IPWrite. Destructive, needs confirm
attach_reserved_ipAttach a reserved public IP to a cloud VMWrite
detach_reserved_ipDetach a reserved public IP from its VMWrite. Disruptive, needs confirm
create_firewallCreate a new cloud firewall (security group)Write
delete_firewallDelete a cloud firewallWrite. Destructive, needs confirm
add_firewall_ruleAdd an inbound/outbound rule to a firewallWrite
delete_firewall_ruleRemove a rule from a firewallWrite. Destructive, needs confirm
attach_firewallAttach a firewall to a cloud VMWrite
detach_firewallDetach a firewall from a cloud VMWrite. Disruptive, needs confirm
create_load_balancerCreate a new L4 load balancer (VIP + listener + pool + floating IP); returns at once with status pending, poll get_load_balancer until activeWrite. Spends, needs confirm
delete_load_balancerDelete a load balancer; deleted at once, or deleting when it was still being set upWrite. Destructive, needs confirm
add_load_balancer_memberAdd a VM as a member of a load-balancer poolWrite
remove_load_balancer_memberRemove a member from a load-balancer poolWrite. Destructive, needs confirm

Object Storage (7 read, 7 write)

ToolWhat it doesType
get_object_storageThe S3-compatible storage service: status, namespace handle, price card, month-to-date charge, limits (null if not enabled)Read
list_object_storage_regionsRegions a bucket can be created in, with their S3 endpointsRead
get_object_storage_usageDaily usage series for the account: stored bytes, egress, CDN traffic (1-90 days)Read
list_bucketsBuckets: id, full name, region, status, versioning, sizeRead
get_bucketOne bucket: endpoint and URLs, versioning, size and object countRead
get_bucket_usageDaily usage series for one bucket (1-90 days)Read
list_object_storage_keysS3 access keys: id, name, access key id, scope, status (never the secret)Read
enable_object_storageEnable Object Storage (starts the monthly base fee); optional, the first bucket does it tooWrite. Spends, needs confirm
disable_object_storageDelete the storage account for good (only once every bucket is deleted and every key revoked)Write. Destructive, needs confirm
create_bucketCreate a bucket (the first one enables or wakes the service and its base fee)Write. Spends, needs confirm
update_bucketToggle a bucket's versioning. Public delivery is not available yet and is refusedWrite. Sensitive, needs confirm
delete_bucketDelete a bucket; purge:true deletes every object in it firstWrite. Destructive, needs confirm
create_object_storage_keyCreate an S3 access key scoped to buckets + read/readwrite (returns a: live secret, shown once)Write. Sensitive, needs confirm
delete_object_storage_keyRevoke an S3 access keyWrite. Destructive, needs confirm

Managed Kubernetes (5 read, 8 write)

ToolWhat it doesType
get_cluster_scaleCurrent scale of a managed K8s cluster: node pools + add-onsRead
list_cluster_poolsWorker node pools: name, machine type, count, autoscale min/maxRead
get_cluster_kubeconfigShort-lived admin kubeconfig (expires in hours): live secretRead
list_cluster_kubeconfigsLong-lived kubeconfig credentials, metadata only (token never returned)Read
download_cluster_kubeconfigRe-download a long-lived credential's kubeconfig (active-only): live secretRead
set_cluster_scaleSet the autoscaling bounds of a cluster's first node poolWrite. Disruptive, needs confirm
add_cluster_poolAdd a named worker node poolWrite. Spends, needs confirm
update_cluster_poolEdit an existing node pool's bounds / machineType / volume sizeWrite. Disruptive, needs confirm
delete_cluster_poolRemove a worker node poolWrite. Destructive, needs confirm
rename_cluster_poolRename a worker node pool (rolls its nodes)Write. Disruptive, needs confirm
enable_cluster_haEnable the HA control plane: add-only, irreversibleWrite. Spends, needs confirm
create_cluster_kubeconfigMint a long-lived, revocable kubeconfig credential (returns a: live secret)Write. Sensitive, needs confirm
revoke_cluster_kubeconfigRevoke a long-lived kubeconfig credentialWrite. Destructive, needs confirm

Domains (8 read, 7 write)

ToolWhat it doesType
list_domainsRegistered domains: id, name, status, expiry, auto-renew, apiAccessRead
get_domainOne domain: nameservers, transfer lock, WHOIS privacy, auto-renew, expiry, apiAccessRead
check_domain_availabilityWhether a domain name is available to registerRead
get_tld_pricingRegister / transfer / renew prices per TLD, in the account currencyRead
get_domain_nameserversNameservers currently set on an owned domainRead
get_domain_contactsRegistrant WHOIS contact on an owned domainRead
get_domain_dnsDNS host records on an owned domain (A / CNAME / MX / TXT / …)Read
get_domain_managementCombined management snapshot for an owned domain in one callRead
register_domainRegister a new domain nameWrite. Spends, needs confirm
transfer_domainTransfer a domain in from another registrarWrite. Spends, needs confirm
renew_domainRenew an owned domainWrite. Spends, needs confirm
set_domain_nameserversReplace an owned domain's nameservers (2-5)Write. Disruptive, needs confirm
set_domain_contactsUpdate an owned domain's registrant WHOIS contactWrite. Sensitive, needs confirm
set_domain_dnsReplace an owned domain's DNS host recordsWrite. Disruptive, needs confirm
manage_domainDispatch a single domain management action (nameservers / lock / autorenew / idprotect / epp)Write. Sensitive, needs confirm

Proxies (10 read, 11 write)

ToolWhat it doesType
list_proxiesResidential proxy services: id, name, flavor, status, plan, expiryRead
get_proxy_catalogProxy order-wizard catalog: ISP IP-count tiers + GB Residential buckets, pricingRead
get_proxyOne proxy service: flavor, status, plan, location, expiry / renewalRead
get_proxy_listLive proxy endpoints + credentials for an ISP fixed-IP plan: live secretRead
get_proxy_authAuth settings for a proxy service: method, credentials, IP whitelist: live secretRead
list_gb_residential_countriesCountries selectable when creating a GB Residential proxy-requestRead
list_gb_rotation_intervalsRotation intervals selectable for a GB Residential proxy-requestRead
list_proxy_requestsProxy-requests on a GB Residential bucket (country + rotation + count groups)Read
get_proxy_request_listLive endpoints + credentials for one GB Residential proxy-request: live secretRead
get_proxy_replacementsIP-replacement allowance + history for a proxy serviceRead
order_proxyOrder a new residential proxy plan: ISP or GB Residential (returns a: live secret)Write. Spends, needs confirm
renew_proxyRenew a proxy service for another billing termWrite. Spends, needs confirm
set_proxy_auto_renewTurn a proxy service's auto-renew on/offWrite
cancel_proxyCancel a proxy serviceWrite. Destructive, needs confirm
set_proxy_auth_methodSwitch a proxy service's authentication methodWrite. Disruptive, needs confirm
set_proxy_credentialsSet a proxy service's username/passwordWrite. Disruptive, needs confirm
add_proxy_whitelisted_ipAdd an IP to a proxy service's whitelistWrite
remove_proxy_whitelisted_ipRemove an IP from a proxy service's whitelistWrite. Destructive, needs confirm
request_proxy_replacementRequest an IP replacement, consuming the monthly allowanceWrite. Disruptive, needs confirm
create_proxy_requestCreate a proxy-request on a GB Residential bucketWrite
delete_proxy_requestDelete a proxy-request from a GB Residential bucketWrite. Destructive, needs confirm

Support (3 read, 3 write)

ToolWhat it doesType
list_ticketsSupport tickets: id, subject, status, department, last-updatedRead
get_ticketOne support ticket with its full message threadRead
list_ticket_departmentsSupport departments + their ids (for opening a ticket)Read
create_ticketOpen a support ticketWrite. Sensitive, needs confirm
reply_ticketPost a reply to an existing support ticketWrite. Sensitive, needs confirm
close_ticketClose a support ticketWrite

Recipes

Type these to your agent. Each one names the tools it should use, so you can check what it did in the tool log.

Deploy a VM. "Deploy a Cloud VM named web-01 in Bucharest on plan g-2vcpu-8gb with Ubuntu 24.04 and my SSH key. Show me the price first." The agent reads the plan with get_product_details, list_regions and list_images, checks with check_order that the order would be accepted, shows you the cost, and after your yes calls deploy_service with category: "cloud-vm", productId: "g-2vcpu-8gb", region: "bucharest-ro", imageId: "ubuntu-24.04" and confirm: true. Then get_provisioning_state until it is running.

Add a volume. "Create a 50 GB volume called web-01-data and attach it to web-01." Uses create_volume (spends, needs your confirm), then attach_volume. Format and mount it inside the VM yourself.

Put a load balancer in front. "Create a load balancer on port 443 for web-01 and web-02." Uses create_load_balancer (spends, needs confirm). It answers at once with status pending and finishes building in the background in a few minutes; the agent polls get_load_balancer until it is active instead of creating it again. It costs €9 a month with its public IP included, billed hourly.

Create a bucket and a key. "Create a bucket called backups in Frankfurt and an access key that can only read it." Uses list_object_storage_regions, create_bucket (spends: the first bucket starts the monthly base fee and needs a handle, your permanent namespace) and create_object_storage_key (sensitive, returns the secret once).

Create a cluster and get a kubeconfig. "Which Kubernetes versions can I pick? Create a cluster with 2 to 4 workers on g-2vcpu-8gb, then give me a 90-day view-only kubeconfig for CI." Uses list_kubernetes_versions (the versions on offer, newest first; a cluster created without a version gets the newest), deploy_service with category: "cloud-k8s" (spends, needs confirm), then create_cluster_kubeconfig (sensitive, needs confirm). For a quick admin session, get_cluster_kubeconfig returns a short-lived one.

Check balance and invoices. "What is my balance, is anything unpaid, and what did I spend this month?" Uses get_credit_balance, get_bonus_balance, list_invoices, get_billing_state and get_billing_alert. Add "alert me if the month passes 50 euro" and it calls set_billing_alert, which flags the alert in the console when spend crosses that figure.

Destroy what you no longer need. "Delete the volume web-01-data, then destroy web-01." Uses detach_volume, delete_volume and destroy_service. The detach is disruptive and both deletions are destructive, so the agent has to ask you, and only a call with confirm: true goes through.

Troubleshooting

What you seeWhat it means
Set RARECLOUD_API_TOKEN to your personal access tokenThe variable is missing from the server's environment. In Claude Code check claude mcp get rarecloud; in a JSON config check the env block.
A permission error (FORBIDDEN / PERMISSION_DENIED)The token lacks the scope the tool needs. Remember :write does not include :read.
"... was NOT executed ..."The tool is gated and the call had no confirm: true. Approve the action and let the agent retry.
RESOURCE_PROTECTEDYou switched API access off for that resource in the console. The agent should not retry; turn API access back on in the console if you want the change.
IDEMPOTENCY_KEY_REUSEDThe agent sent an idempotency_key it had already used for a different request. Use a new key for a new operation.
The server does not startCheck node --version (21 or newer) and that npx can reach the npm registry.
429 errorsThe token hit its requests-per-minute limit. Raise it on a new token or slow the agent down.
You want to cut the agent offRevoke the token in Account, API tokens. It stops working immediately.

Related