AI assistants (MCP)
Cloud Cost Analyzer ships an MCP server, so an AI assistant (Claude Desktop, Cursor, or any MCP client) can read your scans and findings and answer cost questions directly: "what's my biggest AWS waste?", "explain this idle NAT gateway finding", "estimate the savings if I act on the top 10".
The server runs locally over stdio with the cca mcp command and talks to the
same managed backend as the CLI, using your existing API key.
Prerequisites
- The
ccaCLI installed and on yourPATH(see the Quickstart). - A CCA API key (
cca_live_...) from your dashboard. The MCP server uses it the same waycca scandoes.
Claude Desktop
Add the server to your claude_desktop_config.json
(~/Library/Application Support/Claude/ on macOS,
%APPDATA%\Claude\ on Windows):
{
"mcpServers": {
"cloud-cost-analyzer": {
"command": "cca",
"args": ["mcp"],
"env": {
"CCA_API_KEY": "cca_live_your_key_here"
}
}
}
}
Restart Claude Desktop. You should see the Cloud Cost Analyzer tools appear, and you can ask things like "List my recent scans and summarize the biggest findings."
Cursor
Add the same server block to your MCP settings
(~/.cursor/mcp.json, or Settings, then MCP, then Add):
{
"mcpServers": {
"cloud-cost-analyzer": {
"command": "cca",
"args": ["mcp"],
"env": { "CCA_API_KEY": "cca_live_your_key_here" }
}
}
}
Any MCP-compatible client works the same way: the transport is stdio and the
command is always cca mcp.
Tools
| Tool | What it does |
|---|---|
list_scans | List your recent scans (id, totals, timestamp). |
list_findings | List findings for a scan, filterable by provider, category, severity, region. |
explain_finding | Explain one finding: why it fired, the evidence, and the recommended fix. |
estimate_savings | Aggregate estimated monthly/annual savings across findings. |
scan | Kick off a live scan (collect + analyze) and return a scan id. |
scan_status | Poll a running scan until it completes. |
A typical read-only session is list_scans, then list_findings, then explain_finding.
Findings carry the same tier gating as the API: on the free tier the assistant
sees savings totals with resource IDs redacted, exactly like the dashboard.
Read-only mode
To disable the live scan tool (so the assistant can only read existing scans,
never drive cloud API calls), add --no-scan:
{ "command": "cca", "args": ["mcp", "--no-scan"], "env": { "CCA_API_KEY": "cca_live_..." } }
Security
Finding text (descriptions, resource names) is untrusted data: it comes from
your cloud account, not from CCA. The server labels its output accordingly, and a
well-behaved client treats it as data, never as instructions. Keep your
CCA_API_KEY in the client's env block (or a secret manager), never in a
shared/committed file.
Verify it's working
From a shell, you can confirm the server starts and lists its tools without a client:
printf '%s\n%s\n' \
'{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"cli","version":"0"}}}' \
'{"jsonrpc":"2.0","id":2,"method":"tools/list"}' \
| CCA_API_KEY=cca_live_your_key_here cca mcp
You should get an initialize result followed by a tools/list result naming
the six tools above.