argocd-mcp
About
An implementation of Model Context Protocol (MCP) server for Argo CD.
Details
- Author
- akuity
- Repository
- argoproj-labs/mcp-for-argocd
- GitHub stars
- 236
- Downloads
- 12
- License
- Apache License 2.0
- Categories
- Developer Tools, Other
Jump to
- Transport Protocols: Supports both stdio and HTTP stream transport modes for flexible integration with different clients
- Complete Argo CD API Integration: Provides comprehensive access to Argo CD resources and operations
- AI Assistant Ready: Pre-configured tools for AI assistants to interact with Argo CD in natural language
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
argocd-mcpCommand (node, npx, python, etc.)npxArguments-
Argument 1
argocd-mcp@latest -
Argument 2
stdio
Environment-
ARGOCD_BASE_URL
<argocd_url> -
ARGOCD_API_TOKEN
<argocd_token>
Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
-
Argument 1
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
1. Follow the Cursor documentation for MCP support, and create a .cursor/mcp.json file in your project:
{
"mcpServers": {
"argocd-mcp": {
"command": "npx",
"args": [
"argocd-mcp@latest",
"stdio"
],
"env": {
"ARGOCD_BASE_URL": "<argocd_url>",
"ARGOCD_API_TOKEN": "<argocd_token>"
}
}
}
}
2. Start a conversation with Agent mode to use the MCP.
1. Follow the Use MCP servers in VS Code documentation, and create a .vscode/mcp.json file in your project:
{
"servers": {
"argocd-mcp-stdio": {
"type": "stdio",
"command": "npx",
"args": [
"argocd-mcp@latest",
"stdio"
],
"env": {
"ARGOCD_BASE_URL": "<argocd_url>",
"ARGOCD_API_TOKEN": "<argocd_token>"
}
}
}
}
2. Start a conversation with an AI assistant in VS Code that supports MCP.
1. Follow the MCP in Claude Desktop documentation, and create a claude_desktop_config.json configuration file:
{
"mcpServers": {
"argocd-mcp": {
"command": "npx",
"args": [
"argocd-mcp@latest",
"stdio"
],
"env": {
"ARGOCD_BASE_URL": "<argocd_url>",
"ARGOCD_API_TOKEN": "<argocd_token>"
}
}
}
}
2. Configure Claude Desktop to use this configuration file in settings.
list_clusters
List all clusters registered with ArgoCD.
get_appproject
Get detailed information about a specific AppProject (project).
list_applications
List and filter all applications.
get_application
Get detailed information about a specific application.
create_application
Create a new application.
update_application
Update an existing application.
delete_application
Delete an application.
sync_application
Trigger a sync operation on an application.
get_application_resource_tree
Get the resource tree for a specific application.
get_application_managed_resources
Get managed resources for a specific application.
get_application_workload_logs
Get logs for application workloads (Pods, Deployments, etc.).
get_resource_events
Get events for resources managed by an application.
get_resource_actions
Get available actions for resources.
run_resource_action
Run an action on a resource.
The server provides the following ArgoCD management tools:
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"argocd-mcp": {
"env": {
"ARGOCD_BASE_URL": "<argocd_url>",
"ARGOCD_API_TOKEN": "<argocd_token>"
},
"args": [
"argocd-mcp@latest",
"stdio"
],
"command": "npx"
}
}
}
Linux
{
"env": {
"ARGOCD_BASE_URL": "<argocd_url>",
"ARGOCD_API_TOKEN": "<argocd_token>"
},
"args": [
"argocd-mcp@latest",
"stdio"
],
"command": "npx"
}
Macos
{
"env": {
"ARGOCD_BASE_URL": "<argocd_url>",
"ARGOCD_API_TOKEN": "<argocd_token>"
},
"args": [
"argocd-mcp@latest",
"stdio"
],
"command": "npx"
}
Windows
{
"env": {
"ARGOCD_BASE_URL": "<argocd_url>",
"ARGOCD_API_TOKEN": "<argocd_token>"
},
"args": [
"/c",
"npx",
"argocd-mcp@latest",
"stdio"
],
"command": "cmd"
}
Argo CD MCP Server
An implementation of Model Context Protocol (MCP) server for Argo CD, enabling AI assistants to interact with your Argo CD applications through natural language. This server allows for seamless integration with Visual Studio Code and other MCP clients through stdio and HTTP stream transport protocols.
<a href="https://glama.ai/mcp/servers/@akuity/argocd-mcp">
</a>
<!--
// Generate using?:
const config = JSON.stringify({
"name": "argocd-mcp",
"command": "npx",
"args": ["argocd-mcp@latest", "stdio"],
"env": {
"ARGOCD_BASE_URL": "<argocd_url>",
"ARGOCD_API_TOKEN": "<argocd_token>"
}
});
const urlForWebsites = vscode:mcp/install?${encodeURIComponent(config)};
// Github markdown does not allow linking to vscode: directly, so you can use our redirect:
const urlForGithub = https://insiders.vscode.dev/redirect?url=${encodeURIComponent(urlForWebsites)};
-->
---
Features
- Transport Protocols: Supports both stdio and HTTP stream transport modes for flexible integration with different clients
- Complete Argo CD API Integration: Provides comprehensive access to Argo CD resources and operations
- AI Assistant Ready: Pre-configured tools for AI assistants to interact with Argo CD in natural language
Available Tools
The server provides the following ArgoCD management tools:
Cluster Management
-list_clusters: List all clusters registered with ArgoCD
Project Management
-get_appproject: Get detailed information about a specific AppProject (project)
Application Management
-list_applications: List and filter all applications
- get_application: Get detailed information about a specific application
- create_application: Create a new application
- update_application: Update an existing application
- delete_application: Delete an application
- sync_application: Trigger a sync operation on an application
Resource Management
-get_application_resource_tree: Get the resource tree for a specific application
- get_application_managed_resources: Get managed resources for a specific application
- get_application_workload_logs: Get logs for application workloads (Pods, Deployments, etc.)
- get_resource_events: Get events for resources managed by an application
- get_resource_actions: Get available actions for resources
- run_resource_action: Run an action on a resource
Installation
Prerequisites
- Node.js (v18 or higher recommended)
- pnpm package manager (for development)
- Argo CD instance with API access
- Argo CD API token (see the docs for instructions)
Usage with Cursor
1. Follow the Cursor documentation for MCP support, and create a.cursor/mcp.json file in your project:
{
"mcpServers": {
"argocd-mcp": {
"command": "npx",
"args": [
"argocd-mcp@latest",
"stdio"
],
"env": {
"ARGOCD_BASE_URL": "<argocd_url>",
"ARGOCD_API_TOKEN": "<argocd_token>"
}
}
}
}
2. Start a conversation with Agent mode to use the MCP.
Usage with VSCode
1. Follow the Use MCP servers in VS Code documentation, and create a .vscode/mcp.json file in your project:
{
"servers": {
"argocd-mcp-stdio": {
"type": "stdio",
"command": "npx",
"args": [
"argocd-mcp@latest",
"stdio"
],
"env": {
"ARGOCD_BASE_URL": "<argocd_url>",
"ARGOCD_API_TOKEN": "<argocd_token>"
}
}
}
}
2. Start a conversation with an AI assistant in VS Code that supports MCP.
Usage with Claude Desktop
1. Follow the MCP in Claude Desktop documentation, and create a claude_desktop_config.json configuration file:
{
"mcpServers": {
"argocd-mcp": {
"command": "npx",
"args": [
"argocd-mcp@latest",
"stdio"
],
"env": {
"ARGOCD_BASE_URL": "<argocd_url>",
"ARGOCD_API_TOKEN": "<argocd_token>"
}
}
}
}
2. Configure Claude Desktop to use this configuration file in settings.
Self-signed Certificates
If your Argo CD instance uses self-signed certificates or certificates from a private Certificate Authority (CA), you may need to add the following environment variable to your configuration:
"NODE_TLS_REJECT_UNAUTHORIZED": "0"
This disables TLS certificate validation for Node.js when connecting to Argo CD instances using self-signed certificates or certificates from private CAs that aren't trusted by your system's certificate store.
> Warning: Disabling SSL verification reduces security. Use this setting only in development environments or when you understand the security implications.
Providing ArgoCD Credentials
The server connects to ArgoCD using a base URL and an API token.
API token — header / env var only (mandatory)
The ArgoCD API token is a secret and is only ever read from the transport layer, never from a tool-call argument:
- HTTP headers (HTTP transport only): x-argocd-api-token.
- Environment variables: ARGOCD_API_TOKEN (all transports).
This token is outbound only: it authenticates this server to ArgoCD and never authorizes an inbound caller. See Network Exposure for who may reach the listener.
This is the default token. It is mandatory unless a token registry is configured: on the HTTP transport, a connection that supplies no token (neither header nor env var) is rejected with 400 Bad Request, but when a registry is configured a tokenless connection is allowed because each call resolves its own registry token. Keeping the token out of tool arguments ensures it never enters prompts, model context, or tool-call logs.
Base URL — header / env var, or per-call argument
The base URL may be supplied at the session level (resolved once when the server starts or when an HTTP client connects):
- HTTP headers (HTTP transport only): x-argocd-base-url.
- Environment variables: ARGOCD_BASE_URL (all transports).
In addition, every tool accepts an optional argocdBaseUrl argument:
- If a session default base URL exists, argocdBaseUrl is optional and overrides the default for that single call.
- If no session default base URL is configured (header and env var both absent), argocdBaseUrl is required; a call without it returns an error.
Token registry — per-base-URL tokens (multi-instance)
To target multiple ArgoCD instances, each with its own token, configure a token registry. Because the tokens are secrets, the registry is read from a JSON file, not an environment variable — point ARGOCD_TOKEN_REGISTRY_PATH at the file (e.g. a mounted Kubernetes secret). This keeps the tokens out of the process environment, crash dumps, and child-process inheritance.
ARGOCD_TOKEN_REGISTRY_PATH=/app/argocd-mcp/token-registry.json
The file contains a JSON array mapping a base URL to the token that should be used for it:
[
{ "baseUrl": "https://argo-a.example.com", "token": "<token-a>" },
{ "baseUrl": "https://argo-b.example.com", "token": "<token-b>" }
]
> Secure the file. Restrict it to the server's user (e.g. chmod 400) and prefer a secret-management mechanism (Kubernetes secret volume, Vault agent, etc.) over a plaintext file on disk.
> Local development. The make run / make dev targets run without a registry by default; pass ARGOCD_TOKEN_REGISTRY_PATH=/path/to/tokens.json to use one. Do not place the file under dist/ — tsup runs with clean: true and wipes that directory on every build. See Running locally.
With a registry configured, a caller targets an instance by passing only the (non-secret) argocdBaseUrl argument; the server pairs it with the registered token. The token never appears in the tool-call payload.
Two kinds of token
The server resolves calls using one of two distinct tokens. Keeping them straight is what makes the security model work:
| | Default token | Registry token |
|---|---|---|
| Source | x-argocd-api-token header / ARGOCD_API_TOKEN env var (the session credential) | A token entry in the ARGOCD_TOKEN_REGISTRY_PATH JSON file, keyed by baseUrl |
| Scope | The default base URL only (x-argocd-base-url / ARGOCD_BASE_URL) | The specific base URL its entry is keyed to |
| Used for | A call that targets the default base URL | A call that targets any base URL present in the registry (including the default, as a fallback) |
| Never used for | Any base URL other than the default — it is never sent to a different host | Any base URL not registered |
The cardinal rule: the default token is bound to the default base URL; every other host's token must come from the registry. A registry token is bound to exactly the host it is registered under.
Resolution order
For a given call, the resolved base URL is the argocdBaseUrl argument if supplied, otherwise the session default. The token is then chosen by:
1. Call targets the default base URL → use the default token. If no default token was supplied (a tokenless session), fall back to the registry token for that base URL, if one exists.
2. Call targets any other base URL → use the registry token for that base URL only. The default token is never used here — it is not sent to a host other than the default one.
3. If neither applies (no token can be resolved for the requested base URL), the call returns a "Missing required ArgoCD API token" error and no request is made to that host.
> Why the default token is bound to the default base URL. The argocdBaseUrl argument comes from the tool call, so a caller (or a prompt-injected model) could point it at an arbitrary host. If the default token were paired with any supplied base URL, that token would be sent — as an Authorization: Bearer header — to the attacker's host. Restricting the default token to the default base URL, and requiring an explicit registry entry for every other host, prevents this token exfiltration. To target additional instances you must register their tokens (and thus their hostnames) up front.
Base URLs are normalized for lookup (lowercased host, trailing slashes ignored), so minor formatting differences still match. When a registry is configured, the HTTP transport no longer requires x-argocd-api-token at connection time — a tokenless connection is allowed because the per-call base URL resolves its own token. If ARGOCD_TOKEN_REGISTRY_PATH is set but the file is missing, unreadable, or malformed, the server fails closed: it throws at startup rather than silently falling back to its default credential, so a misconfigured registry can never cause calls to be routed with the wrong token.
For example, a tools/call request overriding only the base URL:
{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "list_applications",
"arguments": {
"argocdBaseUrl": "https://argocd.other-cluster.example.com"
}
}
}
> Overriding the base URL to a different instance requires a registry token. The default token (x-argocd-api-token / ARGOCD_API_TOKEN) is bound to the default base URL only and is never sent to a different host. Overriding argocdBaseUrl to point at the default instance (same host, formatting aside) reuses the default token; pointing it at any other instance requires a registry token for that instance, otherwise the call fails with "Missing required ArgoCD API token" and no request is sent. This is intentional — see why the default token is bound to the default base URL above.
Network Exposure
The http and sse transports open a network listener that reaches every ArgoCD tool, including create_application, delete_application, sync_application, and run_resource_action. By default it binds loopback only.
ARGOCD_API_TOKEN does not protect it. That token authenticates this server to ArgoCD. It says nothing about who the caller is. Inbound access is controlled by the settings below.
| Setting | Flag | Env var | Default | What it does |
|---|---|---|---|---|
| Bind address | --bind-address | MCP_BIND_ADDRESS | 127.0.0.1 | Which address the listener accepts connections on. |
| Inbound token | — | MCP_AUTH_TOKEN | unset | When set, every request must carry Authorization: Bearer <token>. |
| Allowed Host | --allowed-host-header | — | loopback names | Extra hostname accepted in a request's Host header. Repeat per name. |
| Allowed Origin | --allowed-origin | — | loopback origins | Extra browser origin accepted in a request's Origin header. Repeat per origin. |
| External auth | --allow-unauthenticated | — | false | Allows a non-loopback bind with no token, when something in front already authenticates callers. |
| Port | --port | — | 3000 | Which port to listen on. |
> --bind-address decides who may connect. --allowed-host-header only checks what an already-connected client claims. They are not a pair, and the second is not a firewall.
Flags with no env var are passed as arguments, in a container too: docker run <image> http --allow-unauthenticated.
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.





