# MCP server for cloud cost and operations | ZopNight

> Connect Claude, Cursor or Codex over MCP. 250+ tools, read-only once an admin turns MCP on, write off until you choose a level, every call audited.

Source: https://zop.dev/zopnight/mcp-server

---

_Write is off by default_

## Cloud cost data for your AI agents.

Connect Claude, Cursor or Codex to ZopNight over the Model Context Protocol and ask about costs, schedules and findings in plain language. Once an admin switches MCP on, reading works straight away. Writing stays off until you decide how much to allow.

- 250+ — tools for your AI assistant
- 150+ — of them read-only
- 3 — write levels, off by default
- 0 — tools that touch credentials

Free to start. No card. The playground just needs your work email.

## Useful to the agent. Fenced for you.

The agent is held to the same rules as a person.

- 01. Connect a client — Claude Desktop, Claude Code, Cursor or Codex. Sign in with OAuth, or use a personal access token for CI. An admin switches MCP on for the org first.
- 02. Ask in plain words — Resources, costs, schedules, recommendations, budgets, teams, dashboards and audit logs. 150+ read tools cover the estate.
- 03. Choose what it can do — Write is off by default. Raise it a level at a time: metadata only, then reversible changes, then irreversible ones, which also need an org-bound token.
- 04. Stay in control — The agent only sees the tools it may use, the same permissions apply as for a person, and every call is logged.

## Useful enough to help. Fenced enough to trust.

Some things no level ever unlocks.

- Never exposed: At no level can an agent change roles, manage users, delete the org or a cloud account, read credentials, or run bulk actions. Environment variable values are always redacted.
- Permissions: The agent is held to the role permissions of the person who connected it. The tool list it sees is filtered to exactly what it may call.
- Prompt safety: Access is enforced at the gateway, not by the agent, so a prompt or a document the agent reads cannot talk it into a tool it was not given.
- Audit: Every call is logged, reads as well as writes, and marked as coming from MCP.

## Give your agent the context it is missing.

Switch MCP on, add the ZopNight server URL to your client, sign in, and start asking. Read-only until you say otherwise.

[object Object]
