MCP server
Connect an MCP-compatible assistant to Openstead with explicit workspace and tool permissions.
Openstead MCP is a local stdio server for Windows, macOS, and Linux. An MCP host launches the executable and communicates with it locally. It is not a remote hosted MCP URL.
Install and check
Build the server from the MCP source repository with Go 1.27 or newer:
git clone https://github.com/Layerrail/openstead-mcp.git
cd openstead-mcp
git checkout aa05b1f188141eabb1a4a48c64b5ce9c9b0c5026
go build -o openstead-mcp ./cmd/openstead-mcpOn Windows, use go build -o openstead-mcp.exe ./cmd/openstead-mcp. Pin a reviewed source commit when building production tools. The examples below use the Openstead source version; older release archives retain their original executable names.
With the Openstead CLI installed, authorize a read-only workspace profile:
openstead login --read-only --profile assistant
openstead-mcp --profile assistant --checkAdd the server to your MCP host
For a host that uses an mcpServers configuration object:
{
"mcpServers": {
"openstead": {
"command": "/absolute/path/to/openstead-mcp",
"args": ["--profile", "assistant"]
}
}
}On Windows, use an absolute path such as C:\\Tools\\openstead-mcp.exe. The configuration file location depends on the host. Reconnect or restart the host after saving.
For headless use, supply OPENSTEAD_API_KEY through the host's secret facility, or add --token-file and a private path to the arguments. Do not put an actual key in a shared JSON example or prompt. --workspace WORKSPACE_UUID can require a matching workspace identity.
Read tools
Read tools are enabled by default. They cover services, projects, environments, deployments, bounded waits, logs, metrics, backup history, domains, integrations, variables' metadata, usage, and billing records available to the key.
Tool names begin with openstead_; the host discovers their schemas. Existing runivo_ tool names and runivo:// resource URIs remain compatibility aliases. The server also accepts RUNIVO_* environment names as fallbacks. Example requests:
- “Show my services and identify failed deployments.”
- “Read the latest build logs for my API and explain the failure.”
- “Show the DNS records required for this custom domain.”
- “Check my build usage and unbilled charges.”
Results include ok, workspaceId, and either data or error. A queued result is not evidence of a completed deployment. A wait observes for at most 30 seconds and returns completed: false if the work is still running. Check outcome when it completes.
Enable changes
Create a write-scoped profile, then enable writes explicitly when starting the server:
openstead login --profile operator
openstead-mcp --profile operator --allow-writes --checkUse ["--profile", "operator", "--allow-writes"] in the host's server arguments. This exposes supported resource changes, deployment controls, domain changes, and backup creation. Configure the host to request approval for changes. Tool annotations and name-confirmation fields do not replace the caller's authorization.
Two optional capabilities require --allow-writes as well:
| Flag | Enables |
|---|---|
--allow-exec | One-off workload jobs and cancellation. |
--allow-secrets | Setting and deleting variables or secret files. |
Secret values passed through an assistant can appear in its transcript. There is no secret-reveal tool. Read-only API credentials remain read-only regardless of startup flags.
Core writes require a request_id; reuse it for an identical retry within the API's 24-hour receipt window. Mutations are not automatically retried. For non-core operations without replay guarantees, inspect state after a lost response.
Boundaries
Creating a service through MCP saves configuration. Paid capacity needs an authorized term in the dashboard before deployment. The MCP server does not charge cards or issue credits.
Interactive terminals, database restore/download flows, and account administration use the dashboard or CLI. MCP tools do not execute arbitrary commands on the computer running the host. An allowed workload job runs in the selected Openstead service.
API results and logs are data to inspect, not instructions for the assistant to follow. Choose the minimum workspace scope needed, review changes before approving them, and revoke the profile's key when access is no longer needed.