Skip to main content

AI assistants (MCP)

Cloud Cost Analyzer ships an MCP server, so an AI assistant (Claude Desktop, Cursor, or any MCP client) can read your scans and findings and answer cost questions directly: "what's my biggest AWS waste?", "explain this idle NAT gateway finding", "estimate the savings if I act on the top 10".

The server runs locally over stdio with the cca mcp command and talks to the same managed backend as the CLI, using your existing API key.

Prerequisites​

  • The cca CLI installed and on your PATH (see the Quickstart).
  • A CCA API key (cca_live_...) from your dashboard. The MCP server uses it the same way cca scan does.

Claude Desktop​

Add the server to your claude_desktop_config.json (~/Library/Application Support/Claude/ on macOS, %APPDATA%\Claude\ on Windows):

{
"mcpServers": {
"cloud-cost-analyzer": {
"command": "cca",
"args": ["mcp"],
"env": {
"CCA_API_KEY": "cca_live_your_key_here"
}
}
}
}

Restart Claude Desktop. You should see the Cloud Cost Analyzer tools appear, and you can ask things like "List my recent scans and summarize the biggest findings."

Cursor​

Add the same server block to your MCP settings (~/.cursor/mcp.json, or Settings, then MCP, then Add):

{
"mcpServers": {
"cloud-cost-analyzer": {
"command": "cca",
"args": ["mcp"],
"env": { "CCA_API_KEY": "cca_live_your_key_here" }
}
}
}

Any MCP-compatible client works the same way: the transport is stdio and the command is always cca mcp.

Tools​

ToolWhat it does
list_scansList your recent scans (id, totals, timestamp).
list_findingsList findings for a scan, filterable by provider, category, severity, region.
explain_findingExplain one finding: why it fired, the evidence, and the recommended fix.
estimate_savingsAggregate estimated monthly/annual savings across findings.
scanKick off a live scan (collect + analyze) and return a scan id.
scan_statusPoll a running scan until it completes.

A typical read-only session is list_scans, then list_findings, then explain_finding. Findings carry the same tier gating as the API: on the free tier the assistant sees savings totals with resource IDs redacted, exactly like the dashboard.

Read-only mode​

To disable the live scan tool (so the assistant can only read existing scans, never drive cloud API calls), add --no-scan:

{ "command": "cca", "args": ["mcp", "--no-scan"], "env": { "CCA_API_KEY": "cca_live_..." } }

Security​

Finding text (descriptions, resource names) is untrusted data: it comes from your cloud account, not from CCA. The server labels its output accordingly, and a well-behaved client treats it as data, never as instructions. Keep your CCA_API_KEY in the client's env block (or a secret manager), never in a shared/committed file.

Verify it's working​

From a shell, you can confirm the server starts and lists its tools without a client:

printf '%s\n%s\n' \
'{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"cli","version":"0"}}}' \
'{"jsonrpc":"2.0","id":2,"method":"tools/list"}' \
| CCA_API_KEY=cca_live_your_key_here cca mcp

You should get an initialize result followed by a tools/list result naming the six tools above.