Connect a client
1
Create a credential
In Settings, open API Keys and select Generate API Key. Tick the scopes the client needs:
mcp:read to look, mcp:write to act, mcp:admin to configure. The key is shown once, so copy it. As a member you can instead create a personal access token on your Account page, which follows your own role.2
Add the server to your client
The endpoint is
https://sreagent.app/api/mcp and the credential goes in the Authorization header as a Bearer token. For Claude Code:claude mcp add --transport http sre-agent https://sreagent.app/api/mcp \
--header "Authorization: Bearer sre_ak_xxxxxxxxxxxx"
3
Ask a question
Ask the client for something your key can do, such as “list the active alerts”. It calls
get_active_alerts and shows the answer.A personal token can belong to more than one organization. Call
list_organizations first, then
pass the organization argument that the other tools offer. An API key belongs to one
organization, so its tools take no organization argument.How access is decided
Every tool needs one scope, and each scope maps to a role. A scope includes the ones below it, somcp:admin can also call write and read tools.
| Scope | Role a personal token needs | Tools |
|---|---|---|
mcp:read | viewer | Read tools |
mcp:write | member | Write tools |
mcp:admin | org_admin | Admin tools |
confirm: true.
Tools that take a secret, such as a provider key, a webhook signing secret or connector credentials, are write-only. You can send the value, and the answer only says whether one is stored. They are marked in the tables.
Read tools
A key withmcp:read, or a personal token whose role is at least viewer, can call these. They read data and change no configuration.
| Tool | What it does |
|---|---|
list_organizations | List the organizations this account belongs to, with the role held in each. |
get_active_alerts | List active alerts, optionally filtered by severity or service. |
get_alert_details | Get full details for a specific alert by ID. |
get_investigation | Get investigation results including findings and root cause. |
get_slo_status | List SLO health status for all active SLOs. |
list_runbooks | List available runbooks. |
query_prometheus | Run a PromQL query against the configured Prometheus instance. |
query_cloudtrail | Query AWS CloudTrail for API activity in this organization’s AWS account: who called what, when, from where, and whether it was refused. |
summarize_cloudtrail_denials | Count the AWS API calls this organization’s account refused in a window, grouped by who was refused, what they called and the error code, most frequent first. |
resolve_service_bindings | How the Observability Explorer resolves one service’s logs, metrics and traces. |
query_logs | Run the Explorer’s Logs tab query. |
query_metrics | Run the Explorer’s Metrics tab. |
search_traces | Run the Explorer’s Traces tab: search X-Ray for the service’s bound trace service names over the window, or your own X-Ray filter expression. |
get_trace | Read one X-Ray trace’s segment tree by id: each segment’s name, duration, status and its subsegments, as search_traces links to. |
list_data_sources | List this organization’s data sources: name, type, url, enabled and regions. |
get_data_source | One data source by id, the same fields list_data_sources answers for it. |
list_slis | List this organization’s SLIs. |
get_sli | One SLI by id, the same fields list_slis answers for it. |
list_slos | List this organization’s SLOs with their targets and status. |
get_slo | One SLO by id, the same fields list_slos answers for it. |
validate_runbook | Ask the Validate button’s questions without running anything. |
list_runbook_steps | List the steps of a runbook, in order. |
list_recipes | List the recipes this organization can install. |
list_connectors | List this organization’s infrastructure connectors (credentials are never returned). |
get_connector | One connector by id, the same fields list_connectors answers for it. |
list_synthetic_checks | List this organization’s synthetic checks with their current state (last status, last run, consecutive failures). |
get_synthetic_check | One synthetic check by id, the same fields list_synthetic_checks answers for it. |
list_oncall_schedules | This organization’s on-call schedules. |
who_is_on_call | Who is on call right now, computed from the schedule’s roster and any override in force at this instant, never a stored answer, so it is always current. |
list_oncall_overrides | List one schedule’s overrides, earliest first. |
get_oncall_notification_preferences | Read your own on-call notification preferences. |
update_oncall_notification_preferences | Change your own on-call notification preferences. |
get_oncall_notification_policy | Read this organization’s on-call notification policy. |
list_oncall_notifications | The most recent on-call notification deliveries for this organization, newest first. |
list_alert_mutes | Every alert mute this organization has, in force or expired. |
get_alert_mute | One alert mute by id, the same fields list_alert_mutes answers for it. |
list_repo_settings | List the per-repository fix settings: branch, service alias, environment and the folders a fix may change. |
get_repo_settings | One repository’s fix settings by the row id list_repo_settings or create_repo_settings answered. |
list_tickets | List this organization’s board cards, oldest first. |
get_ticket | Read one card in full: its fields, what it was raised for, its comments, its activity feed, its approval requests. |
decide_ticket_approval | Answer an approval request on a board card, as the person it names. |
list_ticket_reminders | Pending reminders on a card, soonest first. get_ticket also names them; this is the same list on its own. |
get_fix_brief | Fetch the fix brief for a handoff by id. |
list_pending_handoffs | List this organization’s fix handoffs still waiting on somebody. |
Write tools
These change operational data such as alerts, cards, runbooks and on-call. They needmcp:write, or a personal token whose role is at least member. A key with mcp:admin also passes.
| Tool | What it does |
|---|---|
investigate_alert | Trigger an AI investigation for an alert. |
run_runbook | Execute a runbook by ID. |
approve_sli | Approve a suggested SLI and record who approved it. |
activate_sli | Move an approved SLI to active so it is measured for real. |
archive_sli | Archive an SLI so it stops being offered as something to build on. |
preview_sli_query | Run an SLI’s query against its data source and show the result without saving anything. |
reprobe_sli | Re-run the SLI’s query validation and write the verdict onto the row. |
pause_runbook | Pause a runbook: scheduled and auto-triggered executions stop until it is resumed. |
resume_runbook | Lift a pause: scheduled and auto-triggered executions run again, and the pause’s author and reason are cleared. |
install_recipe | Install a recipe from the library as a runbook. |
run_synthetic_check | Run a synthetic check now instead of waiting for its interval. |
create_slo_from_synthetic_check | Create an availability or latency SLO from a synthetic check. |
list_certificate_monitors | List the TLS certificates this organization watches, with the newest check beside each one: last_status, days_until_expiry and expires_at. |
get_certificate_monitor | One certificate monitor by id, the same fields list_certificate_monitors answers for it. |
create_certificate_monitor | Watch a hostname’s TLS certificate. |
check_certificate_now | Check a watched certificate now instead of waiting for the next scheduled check. |
list_image_targets | List the container images this organization scans for known vulnerabilities, with the newest scan beside each one. |
get_image_target | One image scan target by id, the same fields list_image_targets answers for it. |
create_image_target | Add a container image to scan for known vulnerabilities. |
scan_image_now | Scan a watched image now instead of waiting for the next scheduled scan. |
list_drift_configs | List the workloads this organization watches for configuration drift, with the cluster each one is read from. |
capture_drift_baseline | Store a workload’s current state as its desired baseline. |
check_drift_now | Compare a workload against its baseline now. |
list_drift_events | List detected configuration drift: what changed, on which resource, how bad it is and whether anybody has answered it, newest first. |
acknowledge_drift_event | Record that somebody has seen a drift event. |
resolve_drift_event | Close a drift event. |
run_kubernetes_scan | Assess every connected Kubernetes cluster for security misconfigurations now. |
run_iam_scan | Inventory this organization’s AWS IAM estate now and file what is wrong with it. |
list_iam_findings | List what the IAM scan established about this organization’s AWS principals. |
acknowledge_iam_finding | Record that somebody has seen an IAM finding. |
resolve_iam_finding | Close an IAM finding once the principal is fixed or the risk is accepted. |
list_secret_findings | List credentials found in alert payloads, investigation findings and Kubernetes objects. |
acknowledge_secret_finding | Record that somebody has seen an exposed credential. |
mark_secret_false_positive | Say this match is not a credential. |
list_kubernetes_findings | List what the latest Kubernetes security scan of each cluster found, worst first. |
acknowledge_kubernetes_finding | Record that somebody has seen this Kubernetes finding. |
list_api_anomalies | List API usage anomalies, newest first. |
acknowledge_api_anomaly | Record that somebody has seen this API anomaly. |
reopen_api_anomaly | Withdraw an acknowledgement and put the finding back on the open list. |
list_suppression_rules | Standing rules that stop a known, expected pattern from filing a fresh API anomaly finding. |
create_oncall_override | Create a temporary on-call override that wins over a schedule’s rotation. |
update_oncall_override | Change an override, named by the id list_oncall_overrides answers: who covers, when it begins or ends, or the reason. |
delete_oncall_override | Remove an on-call override. |
acknowledge_alert | Acknowledge an alert. |
resolve_alert | Resolve an alert. |
create_alert_mute | Stop alerts matching a pattern from paging. |
delete_alert_mute | Remove a mute, so alerts matching its pattern page again. |
create_ticket | Open a card on this organization’s ops board. |
update_ticket | Move a card to another column, assign it, change its priority or add a comment. |
update_ticket_comment | Rewrite a line on a card. |
delete_ticket_comment | Remove a line from a card’s conversation. |
request_ticket_approval | Ask a named member to sign off on a board card. |
set_ticket_reminder | Set a reminder on a card for yourself or for everyone on it. |
cancel_ticket_reminder | Cancel one pending reminder. |
list_labels | List the labels on live cards with how many cards carry each, most used first. |
rename_label | Rename a label across every live card that carries it. |
delete_label | Take a label off every live card that carries it. |
list_overseer_runs | List Control Tower runs, newest first. |
list_overseer_findings | List what the Control Tower found, most recently seen first. |
dismiss_overseer_finding | Dismiss a Control Tower finding. |
apply_overseer_finding | Apply the action a Control Tower finding recommends. |
submit_feedback | Send a bug report, suggestion or question to the SRE Agent team. |
Admin tools
These configure the organization: data sources, integrations, policies, teams and settings. They needmcp:admin, or a personal token whose role is org_admin.
| Tool | What it does |
|---|---|
create_data_source | Create a data source such as Prometheus, Loki, Grafana, CloudWatch or Datadog. |
get_aws_external_id | Read the external ID and the principal that your IAM role must trust. The answer holds a secret, so keep it private. |
update_data_source | Update a data source by id (name, url, enabled, regions, auth_type, auth_credentials). auth_credentials replaces the stored credentials. |
delete_data_source | Delete a data source by id. |
create_sli | Create an SLI. sli_type is one of latency, error_rate, availability, throughput, saturation. |
update_sli | Update an SLI by id (name, service, query, data_source_id, status). |
delete_sli | Delete an SLI by id. |
create_slo | Create an SLO against an existing SLI. target is a percentage (e.g. 99.9), window_days defaults to 30. |
update_slo | Update an SLO by id (name, target, window_days, status). |
delete_slo | Delete an SLO by id, along with its measurement history. |
create_runbook | Create a runbook for this organization. |
update_runbook | Update a runbook by id (name, description, tags, risk_level, approval_mode, notification_level, connector_scope). |
delete_runbook | Delete a runbook by id, along with its steps. |
approve_runbook | Approve a draft or pending runbook, which is what makes it eligible to run unattended on a matching alert or on its schedule. |
archive_runbook | Archive a runbook: it stops matching alerts, stops running on its schedule and drops off the runbook list. |
add_runbook_step | Add a step to a runbook. |
update_runbook_step | Update a runbook step by id. |
delete_runbook_step | Delete a runbook step by id. |
create_connector | Create an infrastructure connector that runbook steps act through. Write-only: the credential you send is never returned. |
update_connector | Update a connector by id (name, config, metadata, enabled). |
delete_connector | Delete a connector by id. |
test_connector | Run the connector’s health check (reaches the real target: K8s API, SSH, or AWS STS GetCallerIdentity) and record the result. |
create_synthetic_check | Create a synthetic check that probes a target on an interval and alerts on failure. |
update_synthetic_check | Update a synthetic check by id. |
delete_synthetic_check | Delete a synthetic check and its probe-result history. |
delete_certificate_monitor | Stop watching a host and delete its check history. |
delete_image_target | Stop scanning an image and delete its scan history. |
create_suppression_rule | Suppress a known, expected pattern of API anomaly findings. |
delete_suppression_rule | Delete a suppression rule by id. |
get_organization_settings | The organization’s preferences as the Settings page shows them. |
update_organization_settings | Change one or more preferences; omitted ones keep their value. |
set_service_binding | Correct which log groups, traces and metrics belong to a service. |
delete_service_binding | Remove the override binding for service. |
get_service_binding | Read the stored telemetry binding override for a service. |
get_notification_settings | Who this organization emails about what. |
update_notification_settings | Change one or more email notification settings. |
get_change_notifications | The Slack routing for infrastructure changes. |
update_change_notifications | Change where infrastructure changes are announced in Slack. |
list_alert_routes | Where this organization routes one service’s alerts. |
get_alert_route | One alert route by id, the same fields list_alert_routes answers for it. |
upsert_alert_route | Save where one service’s alerts open in Slack, and which on-call schedule (if any) is mentioned in the thread when one opens. |
delete_alert_route | Remove a route, named by the id list_alert_routes reports. |
update_oncall_notification_policy | Change this organization’s on-call notification policy; only what you name changes. |
list_deploy_policies | The deploy gate’s policies, one per service. |
get_deploy_policy | One deploy policy by id, the same fields list_deploy_policies answers for it. |
create_deploy_policy | Create the deploy gate’s policy for one service. |
update_deploy_policy | Change one deploy policy, named by the id list_deploy_policies reports. |
delete_deploy_policy | Delete a deploy policy by id. |
set_deploy_freeze | Hold every deploy of this policy’s service until a time you choose. |
clear_deploy_freeze | Lift the freeze on this policy’s service, so the gate stops holding its deploys. |
list_audit_logs | This organization’s audit trail, newest first. |
list_ai_providers | The AI providers this organization pays for with its own keys. |
get_ai_provider | One AI provider by id, the same fields list_ai_providers answers for it. |
create_ai_provider | Add an AI provider that your own key pays for. Write-only: the credential you send is never returned. |
update_ai_provider | Change one provider, named by the id list_ai_providers reports; omitted fields keep their value. |
delete_ai_provider | Remove a provider and the key stored on it. |
test_ai_provider | Send one small prompt through a provider with its stored key and report the result. |
get_ai_settings | How this organization’s AI work is routed and retried. |
update_ai_settings | Change one or more of those switches. |
get_ai_usage | What this organization spent on AI over a window. |
list_prompt_templates | The prompts this organization’s AI work runs on. |
get_prompt_template | One prompt template by id, the same fields list_prompt_templates answers for it. |
create_prompt_template | Write a new prompt template for this organization. |
update_prompt_template | Change a template’s name, description, content or switches. |
set_default_prompt_template | Make a template the default for its prompt type. |
delete_prompt_template | Delete a prompt template. |
list_outbound_configs | Where this organization escalates its alerts. |
get_outbound_config | One outbound target by id, the same fields list_outbound_configs answers for it. |
create_outbound_config | Add a target this organization escalates alerts to. |
update_outbound_config | Change one target, named by the id list_outbound_configs reports; omitted fields keep their value. |
delete_outbound_config | Remove a target, the tokens stored on it and every escalation rule that routes through it. |
test_outbound_config | Ask the target whether it can be reached. |
list_outbound_rules | Which alerts escalate to which target. |
get_outbound_rule | One escalation rule by id, the same fields list_outbound_rules answers for it. |
create_outbound_rule | Escalate the alerts a rule matches to one target, once per firing per alert. |
update_outbound_rule | Change one rule, named by the id list_outbound_rules reports; omitted fields keep their value. |
delete_outbound_rule | Remove one escalation rule. |
list_outbound_deliveries | What this organization actually sent to its escalation targets, newest first. |
get_github_integration | How this organization’s GitHub App connection stands. |
list_github_installations | The installations of the SRE Agent GitHub App you could connect here. |
adopt_github_installation | Connect one of the App’s installations to this organization, by the id list_github_installations answers. |
disconnect_github_installation | Disconnect this organization’s GitHub App installation. |
update_github_settings | Change what the connected installation does. |
set_github_webhook_secret | Set the signing secret for GitHub webhooks. Write-only: the credential you send is never returned. |
set_pagerduty_signing_secret | Set the signing secret for PagerDuty webhooks. Write-only: the credential you send is never returned. |
register_fix_runner | Register a runner that executes fix requests for your organization. Write-only: the credential you send is never returned. |
update_fix_runner | Rename this organization’s fix runner, or switch it on and off. |
remove_fix_runner | Remove this organization’s fix runner registration. |
list_ticket_integrations | The ticket systems this organization writes into. |
get_ticket_integration | One ticket system’s connection by provider, the same fields list_ticket_integrations answers for it. |
configure_ticket_integration | Save the credentials for a ticket system. Write-only: the credential you send is never returned. |
delete_ticket_integration | Remove this organization’s credentials for one ticket system, with the board column mapping and the create destination stored beside them. |
set_ticket_status_map | Map this organization’s board columns onto one ticket system’s own workflow, so moving a card moves the item. |
list_ticket_import_rules | The standing import rules this organization has, one per tracker. |
get_ticket_import_rule | One tracker’s import rule by provider, the same fields list_ticket_import_rules answers for it. |
update_ticket_import_rule | Say which of a tracker’s issues become cards on their own, one standing rule per tracker. |
delete_ticket_import_rule | Delete the import rule for one tracker, so nothing more is imported from it. |
run_ticket_import | Fetch everything already open in one tracker that this organization’s import rule asks for, and open a card for each. |
get_status_page | This organization’s public status page as the admin sees it. |
update_status_page | Change one or more of the page’s settings. |
get_status_page_component | One component by id, the same fields get_status_page answers for it in its components list. |
create_status_page_component | Add a customer-facing unit to the page (“API”, “Dashboard”). |
update_status_page_component | Rename a component, change its description, replace the SLOs it publishes or move it up or down the page. |
archive_status_page_component | Take a component off the public page. |
list_status_page_incidents | What this organization’s public status page is telling customers. |
get_status_page_incident | One incident by id, the same fields list_status_page_incidents answers for it. |
create_status_page_incident | Publish an incident on the public status page. |
update_status_page_incident | Add a line to an incident that is already published. message is what customers read. |
archive_status_page_incident | Take a resolved incident off the public page and out of its history. |
list_teams | This organization’s teams and who is on each of them, in name order. |
get_team | One team and its members by id, the same shape list_teams answers for it. |
create_team | Open a new team. |
update_team | Rename a team. |
delete_team | Delete a team. |
add_team_member | Put somebody on a team, named by the email address they sign in with, matched without case. |
remove_team_member | Take somebody off a team. |
list_team_members | Every team membership in this organization, one row per person per team, each with its own id. |
get_team_member | One team membership by its own id, as list_team_members answers it. |
delete_team_member | Take somebody off one team, naming the membership by its own id. |
get_slack_config | This organization’s Slack integration. |
configure_slack | Connect or update the Slack workspace. Write-only: the credential you send is never returned. |
request_fix | Ask SRE Agent to prepare a remediation pull request, described in plain words. |
create_repo_settings | Create the settings row for one repository the GitHub App can reach. |
update_repo_settings | Change one repository settings row, named by the id list_repo_settings reports. |
delete_repo_settings | Remove one repository settings row, named by the id list_repo_settings reports. |
get_integration_webhooks | List the webhook URLs to paste into your monitoring and ticket systems. The answer holds a secret, so keep it private. |
list_members | List everyone in this organization with the role they hold. |
invite_member | Add a member to this organization (they claim the account via password reset). |
mint_fix_handoff | Freeze a fix brief and hand it to your local agent session. |
report_fix_result | Report the outcome of a fix handoff back to the platform. |
get_overseer_settings | Read the Control Tower settings. |
update_overseer_settings | Change Control Tower settings; omitted ones keep their value. |
run_overseer_now | Start a Control Tower run now. |
run_posture_scans | Collect compliance posture evidence now. |
list_compliance_periods | The audit windows this organization has opened, latest window first. |
get_compliance_period | One audit window by id, the same fields list_compliance_periods answers for it. |
create_compliance_period | Open an audit window for a compliance evidence export. |
generate_access_review | Create an access-review card that lists everyone with access and asks a reviewer to sign off. |
list_service_bindings | List the stored telemetry binding overrides, service by service. |
list_status_page_components | List the status page components. |

