Skip to main content
The Kosli MCP server is a Model Context Protocol server that exposes the Kosli API to AI assistants. Once it is connected, you can ask questions like β€œwhich environments are non-compliant, and why?” and the assistant calls the relevant Kosli endpoints to answer. It is published from kosli-dev/mcp-server and distributed as an npm package (@kosli/mcp-server) and as a .mcpb bundle for Claude Desktop.
The Kosli MCP server is in beta. Tool names, parameters, and behavior may change between releases. Pin a version if you need stability: npx -y @kosli/mcp-server@0.5.0.
This server reads the data in your Kosli organization. To let an AI assistant search this documentation instead, see AI access to these docs. The two are complementary, and you can connect both.

How it works

Rather than ship one tool per Kosli endpoint, the server generates a catalog of actions from Kosli’s OpenAPI spec and exposes three generic tools: These are the tool names your client shows as the assistant works, and the name in the prompt when it asks you to approve a write.
execute_write_action creates, modifies, and deletes real resources in your Kosli organization. MCP clients gate these calls behind an approval prompt, and that prompt is the only checkpoint before the call is made. An assistant may choose the wrong action, or the right action with the wrong parameters, so read the action ID and parameters before approving. Treat deletions and anything touching service accounts or API keys with particular care.

Prerequisites

  • Node.js v22 or higher, for the npx-based install methods. You do not need it for the .mcpb bundle, because Claude Desktop ships its own Node runtime.
  • A Kosli API key. Use a personal API key when you run the server on your own machine, or a service account key for automation.
  • An MCP-capable client, such as Claude Code or Claude Desktop.

Install

Run this from your project directory, or add --scope user to install it globally:

Configuration

The server reads its configuration from environment variables.

Example prompts

These prompts only read data, so they run without an approval step. Replace the environment, flow, and trail names with your own.

Environments and compliance

  • β€œWhich of my environments are non-compliant, and why?”
  • β€œWhat is running in prod-aws right now?”
  • β€œHas anything changed in prod-aws since yesterday?”
The assistant answers these from environment snapshots, so it can report both the current state and the reasons an environment is not compliant.

Audit and evidence

  • β€œList every deployment to prod-aws in the last 30 days.”
  • β€œWhat attestations are on trail release-456 in flow my-release?”
  • β€œWhich artifacts running in prod-aws have no security scan attestation?”
The last prompt takes several tool calls, because the assistant has to list what is running and then check the attestations on each artifact. Expect it to be slower than a single lookup, and check the artifact list it worked from before relying on the answer.

Limitations

  • The action catalog is generated from a snapshot of the OpenAPI spec. New endpoints become available when the catalog is regenerated and a new version of the package is published.
  • Ambiguous questions may take several search_actions calls before the assistant settles on the right action.
  • Responses are whatever the Kosli API returns. Large responses consume a lot of context, so ask for specific fields when you can.

Feedback

The server is in beta and we want to hear how it works for you. Email support@kosli.com or open an issue in kosli-dev/mcp-server.
Last modified on August 13, 2026