IONOS CLOUD MCP Server
About
Inspect and manage IONOS CLOUD infrastructure via MCP
Details
- Author
- ionos-cloud
- Downloads
- 592
- Categories
- Cloud Service, Infrastructure, API, Other
Jump to
- Read‑only by design – never creates, modifies, or deletes resources
- 112 tools across Compute Engine, Kubernetes, Object Storage, DNS, Billing, Certificate Manager, and Activity Log
- Local binary with direct IONOS API calls – no third‑party AI in the data path
- Offers an EU‑sovereign option when paired with IONOS CLOUD AI Model Hub
- Open source under Apache 2.0 license
- Supports both eager and lazy tool loading modes
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
IONOS CLOUD MCP ServerCommand (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
Install via Homebrew (brew install ionos-cloud/ionos-cloud/ionoscloud-mcp), Docker, pre‑built binary, go install, or from source. Set the IONOS_TOKEN environment variable (and optionally IONOS_S3_ACCESS_KEY and IONOS_S3_SECRET_KEY for Object Storage). Add the server to your MCP client’s config JSON, then ask natural‑language questions about your infrastructure.
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"ionos cloud mcp server": {
"ionoscloud": {
"command": "/path/to/ionoscloud-mcp",
"env": {
"IONOS_TOKEN": "your-api-token",
"IONOS_S3_ACCESS_KEY": "your-s3-access-key",
"IONOS_S3_SECRET_KEY": "your-s3-secret-key"
}
}
}
}
}
McpServers
{
"ionoscloud": {
"command": "/path/to/ionoscloud-mcp",
"env": {
"IONOS_TOKEN": "your-api-token",
"IONOS_S3_ACCESS_KEY": "your-s3-access-key",
"IONOS_S3_SECRET_KEY": "your-s3-secret-key"
}
}
}
Aread-only-by-defaultModel Context Protocol(MCP) server that connects your IONOS CLOUD account to any MCP-compatible AI assistant or autonomous AI agent: Claude Desktop, Cursor, VS Code (GitHub Copilot), Windsurf, Cline, Continue, OpenCode, and 5+ others.118 read-only tools across 7 IONOS CLOUD products— list, inspect, and audit your infrastructure through natural-language prompts or programmatic agentic loops. Write operations across Compute (servers, volumes, networking, load balancing) and Managed Kubernetes (clusters, node pools, nodes) are strictly opt-in and create real, billable resources — seeWrite operations.
Built and maintained by the IONOS Cloud team. The server runs as a local binary on your workstation, a CI runner, or inside a container. IONOS CLOUD API calls go directly to IONOS over HTTPS; no third-party AI provider sits in the data path.
Compatibility:MCP spec 2024-11-05 · Go 1.25+ for builds · OCI images for linux/amd64 and linux/arm64.
📚Full product documentation, per-client setup guides, FAQ, and tutorials:docs.ionos.com/cloud/ai/mcp-server
Get started in 60 seconds(macOS or Linux, via Homebrew):
brew install ionos-cloud/ionos-cloud/ionoscloud-mcp
For other install paths (Docker, pre-built binary,go install, source), seeInstallation.
Why•Registries•Products•Install•Config•Tool loading•Transport•Write ops•Demo•Dev•Related•Changelog
- Read-only by default, writes strictly opt-in— out of the box every tool is an inspection operation (list_,get_,head_), so it's safe to connect to production accounts and to deploy inside unattended agent loops on CI runners. Write tools (create_,update_,delete_) register only when you setIONOS_MCP_TOOL_SCOPE, and even then every create and delete requires a two-phase confirmation (preview → one-time token → execute). SeeWrite operations.
- Local binary, no proxy— IONOS CLOUD API calls go directly from your machine to IONOS Cloud. No third-party AI vendor in the data path.
- EU-sovereign option— pair the server with theIONOS CLOUD AI Model Huband both the API callsandthe LLM inference terminate inside IONOS's German data centres. See theFully Sovereign AI Workflowguide.
- Open source— Apache 2.0. Read the source, audit the behaviour, contribute, or fork.
This server is published across multiple MCP registries and IDE marketplaces:
Read tools are namedlist_,get_andhead_; the opt-in write tools arecreate_,update_,delete_plus domain verbs such asstart_andattach_. In the defaulteagermode all tools register at startup;lazymode defers Compute and Object Storage behind loader tools;dynamicmode exposes only three search/describe/call meta-tools for clients with hard tool caps. SeeTool loading mode.
120 read-only tools(118 product + 2 loader), plus77 opt-in write toolson Compute Engine and Kubernetes — seeWrite operations. For per-tool input/output schemas, see theper-product docsor the fullTool Referenceat docs.ionos.com.
brew install ionos-cloud/ionos-cloud/ionoscloud-mcp
docker pull ghcr.io/ionos-cloud/ionoscloud-mcp:latest
Run with the MCP stdio transport (default):
docker run -i --rm \ -e IONOS_TOKEN="$IONOS_TOKEN" \ ghcr.io/ionos-cloud/ionoscloud-mcp
docker run --rm -p 8080:8080 \ -e IONOS_TOKEN="$IONOS_TOKEN" \ ghcr.io/ionos-cloud/ionoscloud-mcp --transport http --http-addr :8080
npx -y @smithery/cli install @ionos-cloud/ionoscloud-mcp --client claude-desktop
Supported--clientvalues:claude-desktop,claude-code,cursor,vscode,windsurf,cline,continue,gemini-cli,kiro, and others. See theSmithery listingfor the current list.
Download the archive for your OS/arch from thelatest release. Available for Linux, macOS, and Windows on both amd64 and arm64.
go install github.com/ionos-cloud/ionoscloud-mcp@latest
git clone https://github.com/ionos-cloud/ionoscloud-mcp.git cd ionoscloud-mcp make build
You need an IONOS CLOUD account with API credentials.
# Required: API token for control-plane APIs (Compute, DNS, Billing, Certificate Manager, Object Storage management) export IONOS_TOKEN="your-api-token" # Optional: only required if you use Object Storage data-plane tools # (listing objects, reading bucket configuration, checking access keys). export IONOS_S3_ACCESS_KEY="your-s3-access-key" export IONOS_S3_SECRET_KEY="your-s3-secret-key" # Optional: opt in to write operations (default: read-only). Values are hierarchical, # so a single level suffices: "write" allows create/update; "destructive" also allows # delete (it implies "write"). See "Write operations". # export IONOS_MCP_TOOL_SCOPE="write"
Generate a token in theIONOS CLOUD DCDunderManagement → Token Management. Object Storage credentials are created underStorage & Backup → IONOS CLOUD Object Storage → Key management.
For least-privilege token scoping, seeAuthenticationat docs.ionos.com.
Add the server to your AI client's MCP config:
{ "mcpServers": { "ionoscloud": { "command": "/path/to/ionoscloud-mcp", "env": { "IONOS_TOKEN": "your-api-token", "IONOS_S3_ACCESS_KEY": "your-s3-access-key", "IONOS_S3_SECRET_KEY": "your-s3-secret-key" } } } }
The Object Storage credentials are only needed if you plan to use Object Storage tools.
Per-client setup guides for the 12 supported AI clients:Connect to an AI Clientat docs.ionos.com.
The load mode selects how tools are exposed. Set it with either the--load-modeflag or theIONOS_MCP_LOAD_MODEenvironment variable;the flag wins if both are set, and otherwise the default iseager. Parsing is case-insensitive.
-
eager(default): all tools register at startup. Recommended for Claude Code (which defers full schemas client-side via ToolSearch, paying ~1–3k tokens for names only) and the only working mode for clients that ignorenotifications/tools/list_changed(Claude Desktop, claude.ai connectors, Claude in Chrome, Smithery scanner).
lazy: Compute and Object Storage register only on demand. Two sentinel tools (ionos_load_compute_tools,ionos_load_objectstorage_tools) appear at startup; calling either registers the full product set and emitsnotifications/tools/list_changed. Use only if your MCP client honours that notification AND lacks client-side schema deferral — otherwise eager mode is cheaper.
dynamic(alias:search): the server exposes onlythreemeta-tools —ionos_search_tools,ionos_describe_toolsandionos_call_tool— and the model discovers and invokes the full catalogue through them at runtime. The real tool list never changes, so unlikelazythis needs nonotifications/tools/list_changedsupport. Intended for clients withhard tool caps and no tool search of their own(e.g. Cursor's ~40-tool cap, Windsurf's 100). Trade-off: the model mustsearch→describe→callrather than seeing tools directly, costing extra round-trips, so prefereageron Claude Code.
The server logs the effective mode and its source (flag / env / default) to stderr at startup, e.g.load mode: dynamic (source: --load-mode flag).
{ "mcpServers": { "ionoscloud": { "command": "/path/to/ionoscloud-mcp", "args": ["--load-mode", "dynamic"], "env": { "IONOS_TOKEN": "your-api-token" } } } }
Tool-count limits:Windsurf caps connected MCP servers at 100 tools combined; Cursor caps at ~40 across all servers. With the default eager mode the server exceeds both. On Windsurf,lazykeeps the startup surface small enough; on Cursor (or any cap-limited client without its own tool search), usedynamicto present just three tools. For more information, seeSelective Tool Loading.
The server speaks stdio by default — the mode every subprocess-spawning MCP client expects (Claude Desktop, Claude Code, Cursor, Windsurf, etc.). For remote or networked deployments (e.g. running the server centrally and pointing multiple clients at it), switch to theStreamable HTTP transportwith--transport httporIONOS_MCP_TRANSPORT=http;the flag wins if both are set.
./ionoscloud-mcp --transport http --http-addr :8080
- --transport <stdio|http>(orIONOS_MCP_TRANSPORT) — selects the transport. Unrecognised values fall back tostdiowith a warning.
- --http-addr <addr>(orIONOS_MCP_HTTP_ADDR) — listen address for the HTTP transport. Default:8080(all interfaces); use127.0.0.1:8080for local-only. Ignored for stdio.
The server logs the effective transport and its source to stderr at startup, e.g.transport: http (source: --transport flag).
In HTTP mode, point your MCP client athttp://<host>:<port>/as a Streamable HTTP server. There is no built-in TLS or authentication for the HTTP endpoint itself — put it behind a reverse proxy (e.g. nginx, Caddy) if it needs to be reachable outside a trusted network.IONOS_TOKENand the other IONOS CLOUD credentials still authenticate the server's own calls to the IONOS API regardless of transport.
The server is read-only until you opt in.Write tools are never registered and never appear intools/listunless you set theIONOS_MCP_TOOL_SCOPEenvironment variable. The gate applies in every load mode, including thedynamicdispatcher — there is no bypass.
Scope is a comma-separated, hierarchical set of capabilities (readis always on):
Unrecognised values fall back to read-only, and the effective scope is logged to stderr at startup. Because the levels are hierarchical, a single value is enough —destructivealone already grantswriteandread; you don't need to list them all (though a comma-separated list likeread,writeis also accepted).
Not available, because the Go SDK cannot build the request the API accepts: renaming an IP block, attaching a CD-ROM to a server, attaching a NIC to a classic load balancer, and detaching a LAN from a cross connect. Useionosctl, the Terraform provider or theDCDfor those.
77 tools in total. The server exposes 118 at the default read-only scope, 165 withwrite, and 195 withdestructive. Reads are unaffected and always available.
Two-phase confirmation.Everycreate_anddelete_, plus the disruptive actions (stop_,reboot_,suspend_,upgrade_,restore_,detach_,recreate_), is confirmation-gated. The first call performs no mutation: it returns a preview — for a delete, a blast-radius summary of what will be destroyed — plus a single-useconfirmation_token(5-minute TTL, bound to that exact target and operation). Only a second call carrying that token executes. This keeps a human in the loop and limits the agent to one resource per call. Reversible single-field changes (update_,start_,attach_,assign_) are a single call.
Annotations.Write tools carry MCP annotations (readOnlyHint,destructiveHint,idempotentHint) so clients can build their own approval UX — but enforcement is always server-side. Note that the class comes from the operation, not the HTTP verb:stop_serveris aPOSTthat is destructive.
⚠️ Write operations create real resources and real charges
EnablingIONOS_MCP_TOOL_SCOPElets an AI model provision billable infrastructure in your live IONOS CLOUD account.Every create is a real resource on a real invoice, effective immediately.
Some resources cost money even when nothing is using them — a reserved IP block, a snapshot, or a volume left behind after its server was deleted. Deletions are equally real: destroyed data is not recoverable without a snapshot, and a released IP address cannot be asked for again.
An AI model decides when and how often to call these tools.It can misread your intent, retry more than you expected, or pick a larger resource than you had in mind. The two-phase confirmation exists to put a human in that loop, but it cannot stop a client configured to approve tool calls automatically — in that setup the model can complete both phases on its own.
You are responsible for everything created, modified or deleted in your account through these tools, and for the resulting charges.IONOS does not control and is not responsible for how a model chooses to call them, or for any cost, data loss or outage arising from those calls.
Reduce the risk: leave the server read-only unless you need writes; grantwriterather thandestructivewhen deletion isn't required; require manual approval of tool calls in your client; read the preview before returning a confirmation token; and prefer a non-production account when experimenting.
Enable writes in your MCP client config, for example:
{ "mcpServers": { "ionoscloud": { "command": "/path/to/ionoscloud-mcp", "env": { "IONOS_TOKEN": "your-api-token", "IONOS_MCP_TOOL_SCOPE": "destructive" } } } }
In Claude Desktop or any other supported client, after configuring the server, try one of these prompts. They cover the kinds of multi-step inspection workflows that are tedious to write as scripts but easy in natural language:
- Cost audit:"Audit my IONOS CLOUD account, find the top 5 cost-inducing resources this month, and suggest cost-efficiency tips."
- Security sweep:"List every bucket whose public access block is off or whose policy is public — flag anything that looks unintentional."
- Audit trail:"Show me every failed API request on my contract in the last 30 days, grouped by user."
- Forgotten resources:"Find unattached volumes, unused IP blocks, and stopped servers across all my data centers."
- DNS sanity check:"List all zones on my account and flag any without DNSSEC enabled or with records pointing to IPs I no longer own."
- Certificate expiry:"Which certificates on my account expire in the next 60 days?"
- Traffic spike investigation:"My last invoice was higher than usual — show me daily traffic and utilization for the previous billing period and tell me what changed."
- Onboarding tour:"Walk me through what I have running on IONOS CLOUD — datacenters, servers, storage, DNS — like you're explaining it to a new teammate."
Each prompt chains multiplelist_andget_*calls and produces a summary you can paste into a ticket, dashboard, or doc. For end-to-end walkthroughs:
- Run a security posture audit on your IONOS CLOUD Object Storage buckets
- Generate a FOCUS-compliant cost report
You can test the server's MCP protocol implementation using stdin/stdout:
# Initialize and list tools { echo '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"test","version":"0.1.0"}}}' echo '{"jsonrpc":"2.0","method":"notifications/initialized"}' echo '{"jsonrpc":"2.0","id":2,"method":"tools/list","params":{}}' sleep 1 } | ./ionoscloud-mcp # Call a tool (requires a valid IONOS_TOKEN) { echo '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"test","version":"0.1.0"}}}' echo '{"jsonrpc":"2.0","method":"notifications/initialized"}' echo '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"list_datacenters","arguments":{}}}' sleep 1 } | ./ionoscloud-mcp
make build # or go build -o ionoscloud-mcp .
Runmakewith no arguments to see the available targets.
- IONOS CLOUD MCP Server product docs— full product documentation
- IONOS CLOUD AI Model Hub— open-weight LLMs hosted in Germany; pair with this server for a fully EU-sovereign AI loop
- IONOS CLOUD Documentation MCP— a free public MCP server exposing the IONOS docs site for AI assistants
Issues and pull requests are welcome. For development setup, code style, and testing instructions, seeCONTRIBUTING.md. For questions and discussion, useGitHub Discussions.
If you believe you have found a security vulnerability,please do not open a public issue. Report it privately via GitHub'sprivate vulnerability reportingor by email tosdk-tooling@ionos.com. Full policy:SECURITY.md.
Notable changes per release are tracked inCHANGELOG.md. For the artefacts published with each tag (Linux/macOS/Windows binaries, multi-arch OCI images), see theGitHub Releasespage.
For more information about the IONOS CLOUD API:
- IONOS CLOUD API Documentation
- API specifications
- SDK documentation
Automate Akamai resource actions using a conversational AI client. Requires Akamai API credentials.
Query Azure retail pricing information using the Azure Retail Prices API.
Manage Azure Cloud PCs using the Microsoft Graph API.
Integrate with Apache CloudStack to manage cloud resources directly from your desktop.
Integrates with the Cloudways API, allowing AI assistants to access and manage Cloudways infrastructure.
Interact with Confluent Cloud REST APIs to manage Kafka clusters, topics, and data.
An MCP server for interacting with the Exoscale cloud platform.
Access and manage Google Cloud Platform (GCP) services and resources.
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.

