Each tool maps to one endpoint of the API and needs the scope of that endpoint.
Answers are the API's JSON; errors keep their code, their details and
the request_id, with a hint on what to do next.
Catalogue, no key
| Tool | Arguments | Returns |
|---|---|---|
list_regions | none | Where machines can run. |
list_plans | region | Plans, resources, hourly and monthly prices. |
list_images | region, plan, category | Systems and application images; the slug is what create_vm expects. |
Account
| Tool | Arguments | Scope |
|---|---|---|
get_account | none | billing.read |
Balance, hourly burn rate and runway, quota, monthly budget.
Machines
| Tool | Arguments | Scope |
|---|---|---|
list_vms | status, region, billing, cursor, limit | vms.read |
get_vm | vm | vms.read |
get_vm_metrics | vm, timeframe | vms.read |
estimate_vm | plan, region, image, hostname, billing, ssh_keys, options | vms.create |
create_vm | as estimate_vm, plus payment, password_delivery, idempotency_key | vms.create |
power_vm | vm, type: start, shutdown, reboot, stop | vms.action |
rename_vm | vm, hostname | vms.action |
reinstall_vm | vm, image, confirm_hostname, ssh_keys, password_delivery | vms.action |
destroy_vm | vm, confirm_hostname, when | vms.destroy |
estimate_vm runs every check of an order and prices it without creating
anything. create_vm derives its idempotency key from the order itself:
an agent that retries the same call after a timeout gets the first answer back, not a
second machine. reinstall_vm and destroy_vm erase the disk and
refuse to act unless confirm_hostname is the machine's exact hostname.
Actions
| Tool | Arguments | Scope |
|---|---|---|
get_action | action | vms.read |
list_vm_actions | vm | vms.read |
Creation, reinstall and power changes run in the background and return an action:
poll get_action until its status leaves running. A new
machine is ready in under two minutes.
Network and SSH keys
| Tool | Arguments | Scope |
|---|---|---|
get_vm_network | vm | vms.read |
set_reverse_dns | vm, address, hostname (null clears) | network.write |
list_ssh_keys | none | sshkeys.write or vms.read |
add_ssh_key | name, public_key | sshkeys.write |
delete_ssh_key | key | sshkeys.write |
What the MCP server does not do
Restoring or deleting a backup, opening a console session and adding IPv6 addresses stay in the API and the console: they are rare, and a mistake there is expensive. Invoices, payment methods and tickets are reachable by no key at all.