Base44
Build and edit Base44 apps from an AI assistant, and query data your app's users submit.
Deploy, scale and delete cloud workloads on AWS, GCP and Azure.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Control Plane MCP server connects a Control Plane organization — a platform that runs containerized workloads across AWS, GCP, Azure, Oracle Cloud and your own hardware — to Claude, ChatGPT and any MCP-compatible agent. It deploys, scales, inspects and deletes live infrastructure. Sign-in is OAuth with per-org consent.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
scopes_supported of openid and offline_access; the authorization server at https://auth.cpln.io advertises openid, offline and offline_access. Both lists are identity and refresh-token claims. Nothing at the OAuth grant separates reading a workload from deleting one — the per-org consent screen and the toolset profile are the only boundaries.workload_exec runs a command inside a running container and is marked core by Control Plane. Auditing the directory listing alone will miss it.cpln_api_request appears only in the plugin's generated manifest, marked conditional behind a kill switch and documented as bypassing typed-tool validation. We did not authenticate, so we cannot say whether it is advertised to your organization. If it is, the reachable surface is Control Plane's whole REST API rather than 132 tools.list_quotas and get_quota but no billing, spend or cost tool, so an agent can provision without any tool that could price it first. Control Plane publishes no per-call rate, and we found no documentation of idempotency keys on the create tools.destructiveHint is published here. The Read/Write/Destructive markers are Control Plane's documentation.full holds 132 tools; the tables below it enumerate 131. The 132nd is cpln_api_request, which the manifest carries and the reference does not.get_agent_info is about Control Plane's network agents, not AI agents. The naming collides with MCP vocabulary; it reads a private-network connectivity agent's heartbeat.Yes, on the default profile. One tool named delete_resource removes a resource by kind and name, and Control Plane documents it as the single delete tool for every deletable kind. Deleting a GVC cascades to every workload and identity inside it. Control Plane states destructive operations execute on a single call with no server-side preview or confirmation token.
Yes, through a tool Anthropic's directory does not list. Control Plane's tools reference documents workload_exec, marked Destructive and available on the default core profile, which runs a single command in a running container and returns its output. It is the one core tool missing from the directory's 55, so a reader who audits only the directory listing will not see it.
132, and the number depends on a URL parameter. Control Plane's tools reference documents 30 tools on the readonly profile, 56 on core, 78 on mk8s and 132 on full, selected with the toolsets query parameter on the endpoint. Anthropic's directory lists 55, which is the core profile minus workload_exec.
Only identity claims. The server's RFC 9728 descriptor advertised scopes_supported of openid and offline_access on 2026-08-23, and its authorization server advertised openid, offline and offline_access. Neither names a Control Plane resource or verb, so no OAuth scope separates reading a workload from deleting one. The real boundary is the per-org consent screen.
No tool returns a secret value. Control Plane documents secrets as read-only through the MCP server: list_resources and get_resource show a secret exists and its metadata, never its data, and no tool creates, edits, deletes or reveals one. But create_cloud_account and update_cloud_account on the full profile change the bridge between Control Plane and your AWS, GCP or Azure account.
Connect to the readonly profile URL. Control Plane documents https://mcp.cpln.io/mcp?toolsets=readonly as a 30-tool set that advertises no tool which creates, updates, deletes or executes a command. The profile is fixed for the life of a connection and an agent cannot expand it mid-session, so reconnecting is the only way to change it.
The connector is not metered, but the resources it creates are. Creating a GVC, workload, mk8s cluster or IP set provisions real capacity across AWS, GCP, Azure or Hetzner, and Control Plane documents that reserved IP addresses must be explicitly released to prevent ongoing charges. The surface exposes list_quotas and get_quota but no billing or spend tool.
A Control Plane account and a decision about which orgs to authorize. Control Plane documents sign-in through Google, GitHub, Microsoft or SAML, followed by a consent screen where you pick the orgs the AI client may access. Its own guidance is to authorize only the orgs you need, because that consent is the connector's main access boundary.
.md route) · retrieved 2026-08-23docs.controlplane.com/mcp/overview, which serves this same page. · retrieved 2026-08-23llms.txt index and llms-full.txt (543,814 words) — · (retrieved 2026-08-23) · retrieved 2026-08-23scripts/tools-manifest.json, operating guide at plugins/cpln/rules/cpln-guardrails.md, and SECURITY.md (MIT, commit a8873a6, read 2026-08-23) · retrieved 2026-08-23https://mcp.cpln.io/mcp returned HTTP 401 with www-authenticate: Bearer realm="https://mcp.cpln.io/mcp", resource_metadata="https://mcp.cpln.io/.well-known/oauth-protected-resource/mcp", scope="openid offline_access"; RFC 9728 descriptor and authorization server metadata at https://auth.cpln.io/.well-known/oauth-authorization-server (2026-08-23) · retrieved 2026-08-23docs.controlplane.com/robots.txt carries Content-Signal: ai-train=yes, search=yes, ai-input=yes — the publisher expressly permits AI synthesis of this content (retrieved 2026-08-23) · retrieved 2026-08-23Connect Control Plane once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.