{
  "name": "io.github.moxforge/ig1",
  "title": "IG1 Edge Cloud",
  "description": "Operate an IG1 Edge Cloud project — compute, block storage, networking, security groups, load balancing, VM autoscaling groups, tenant edge exposures, DNS, Kubernetes clusters (including worker autoscaling), object storage, managed databases, secrets (Barbican), the quota-tier catalogue, observability, billing and scoped IAM — through 148 scoped, tiered, audited tools. The server holds no identity of its own: the caller's Bearer token is forwarded to the backing services on every tool call, and the IG1 API resolves project + permission tier server-side (tiers: 0 read-only, 1 operate, 2 destructive). Guardrails the API does not impose are imposed here: minted credentials are tier <= 1 with expiry <= 7 days, routers cannot carry an external gateway (the parameter does not exist), security groups are default-deny, world-SSH needs an explicit flag, and secret PAYLOAD read is not a tool at all — agents get metadata/create/delete; values are revealed only through the portal/CLI reveal-once flows.",
  "version": "0.9.4",
  "transport": "streamable-http",
  "endpoint": "https://mcp.cloud.ig1.com/mcp",
  "protocol": {
    "mcp_spec": "2026-07-28",
    "stateless": true,
    "sdk": "mcp 2.0.0 (python)"
  },
  "tools": 148,
  "tools_by_domain": {
    "identity": [
      "whoami",
      "list_projects",
      "create_project",
      "get_effective_org_policy",
      "list_org_units",
      "get_project_contents",
      "list_workload_identities",
      "create_workload_identity",
      "delete_workload_identity",
      "exchange_workload_token"
    ],
    "compute": [
      "list_vms",
      "create_vm",
      "vm_action",
      "resize_vm",
      "confirm_resize",
      "revert_resize",
      "get_console_log",
      "snapshot_vm",
      "shelve_vm",
      "unshelve_vm",
      "delete_vm"
    ],
    "keypairs": [
      "list_keypairs",
      "import_keypair",
      "delete_keypair"
    ],
    "volumes": [
      "list_volumes",
      "create_volume",
      "attach_volume",
      "detach_volume",
      "extend_volume",
      "delete_volume",
      "list_volume_snapshots",
      "create_volume_snapshot",
      "delete_volume_snapshot",
      "create_volume_from_snapshot",
      "list_volume_backups",
      "create_volume_backup",
      "delete_volume_backup",
      "restore_volume_backup"
    ],
    "network": [
      "list_networks",
      "create_network",
      "delete_network",
      "create_subnet",
      "delete_subnet",
      "list_routers",
      "create_router",
      "add_router_interface",
      "remove_router_interface",
      "delete_router",
      "list_ports",
      "list_floating_ips",
      "allocate_floating_ip",
      "associate_floating_ip",
      "disassociate_floating_ip",
      "release_floating_ip",
      "list_nat_gateways",
      "create_nat_gateway",
      "delete_nat_gateway"
    ],
    "security_groups": [
      "list_security_groups",
      "create_security_group",
      "list_security_group_rules",
      "add_security_group_rule",
      "remove_security_group_rule",
      "delete_security_group"
    ],
    "images_and_flavors": [
      "list_images",
      "get_image",
      "import_image",
      "delete_image",
      "list_flavors",
      "get_quotas",
      "get_tiers"
    ],
    "kubernetes": [
      "list_clusters",
      "get_kubernetes_cluster",
      "create_cluster",
      "scale_cluster",
      "upgrade_cluster",
      "set_cluster_protection",
      "set_cluster_autoscaling",
      "list_cluster_versions",
      "delete_cluster",
      "get_cluster_kubeconfig"
    ],
    "autoscaling_groups": [
      "list_asgs",
      "create_asg",
      "get_asg",
      "update_asg",
      "delete_asg"
    ],
    "edge_exposures": [
      "list_edge_exposures",
      "create_edge_exposure",
      "delete_edge_exposure",
      "claim_edge_domain",
      "verify_edge_domain",
      "release_edge_domain",
      "get_edge_exposure"
    ],
    "object_storage": [
      "list_buckets",
      "create_bucket",
      "delete_bucket",
      "get_s3_credentials",
      "rotate_s3_credentials",
      "list_bucket_objects",
      "presign_bucket_object",
      "get_bucket_versioning",
      "set_bucket_versioning"
    ],
    "databases": [
      "list_databases",
      "create_database",
      "get_database",
      "resize_database",
      "restore_database",
      "get_database_credentials",
      "delete_database"
    ],
    "secrets": [
      "list_secrets",
      "get_secret_metadata",
      "create_secret",
      "delete_secret"
    ],
    "dns": [
      "list_dns_zones",
      "create_dns_zone",
      "delete_dns_zone",
      "list_dns_records",
      "create_dns_record",
      "update_dns_record",
      "delete_dns_record",
      "get_dns_zone",
      "get_dns_delegation",
      "import_dns_records"
    ],
    "load_balancing": [
      "list_load_balancers",
      "get_load_balancer",
      "create_load_balancer",
      "delete_load_balancer"
    ],
    "observability": [
      "list_events",
      "get_audit_log",
      "get_instance_metrics",
      "get_instance_metrics_history",
      "get_status",
      "list_webhooks",
      "create_webhook",
      "delete_webhook",
      "list_event_topics",
      "list_webhook_deliveries"
    ],
    "billing": [
      "get_usage",
      "get_cost_breakdown",
      "get_cost_forecast",
      "list_invoices",
      "list_budgets",
      "create_budget",
      "delete_budget"
    ],
    "iam": [
      "list_credentials",
      "create_credential",
      "revoke_credential",
      "get_credentials_usage"
    ],
    "sandbox": [
      "run_workflow"
    ]
  },
  "authentication": {
    "type": "oauth2-client-credentials",
    "token_endpoint": "https://zitadel.cloud.ig1.com/oauth/v2/token",
    "scope": "openid urn:zitadel:iam:org:project:roles urn:zitadel:iam:org:project:id:385253743135817916:aud",
    "header": "Authorization: Bearer ${IG1_TOKEN}",
    "credential": "issue with: ig1 credential create --kind mcp --tier 0 --label <agent-name> (portal: Security → Agent / MCP credentials); agent-minted credentials are capped at tier 1 and 7 days",
    "tls": "publicly trusted (Let's Encrypt) since 2026-08-25 — no CA bundle needed"
  },
  "config_snippet": {
    "mcpServers": {
      "ig1": {
        "type": "http",
        "url": "https://mcp.cloud.ig1.com/mcp",
        "headers": {
          "Authorization": "Bearer ${IG1_TOKEN}"
        }
      }
    }
  },
  "audit": "every tool call emits an agent.actions event with real caller attribution (tool + parameter NAMES only, never values); destructive tools are write-ahead audited and refuse to act when the audit cannot be recorded or the actor cannot be resolved",
  "docs": "https://docs.10.57.8.64.nip.io/mcp.html",
  "skill": "docs/agent/ig1-skill/SKILL.md (in-repo; install with: ig1 agent init)"
}
