Give your AI client every cluster, with the access you choose.

Ankra runs a hosted Model Context Protocol server for Kubernetes at platform.ankra.app/api/v1/mcp. Claude connects with OAuth, Cursor and other clients use a Bearer token, and the token's mcp:read or mcp:write scope decides whether the client can only look or can also change things.

A Kubernetes MCP server lets an AI assistant such as Claude or Cursor read and operate clusters through tools instead of pasted kubectl output. Ankra's server covers more than the Kubernetes API. Its 450+ tools reach pods, logs and events, and also Stacks, add-ons, GitOps, applications, pipelines, the Security Center, cost, backups and cluster lifecycle across every cluster in your organisation.

It speaks streamable HTTP and is listed in the official MCP Registry as ai.ankra/platform. There is nothing to install or host. Point the client at the endpoint, sign in or paste a token, and ask it to list your clusters.

What the server can reach

The same tool registry powers the AI assistant in the product and chat over Slack, Microsoft Teams and pull request comments, so what you can ask is the same everywhere.

Clusters and workloads

Pods, deployments, services, ingresses, events, logs, nodes and live CPU and memory, plus restart, scale, apply, patch and cordon with a write token.

Stacks, add-ons and GitOps

Read, validate, create, clone and redeploy Stacks, change Helm values, roll an add-on back, and check GitOps status and conflicts.

Applications and pipelines

Connect a repository, follow its builds and deployments, convert a GitHub Actions or GitLab CI file into an Ankra pipeline, and re-run failed workflows.

Security, cost and backups

Vulnerability findings across the fleet, compliance reports, estimated cost per cluster and stack, and backup vaults and restore points.

Connect in a minute

One endpoint.
Every cluster behind it.

In Claude's web and desktop apps, add Ankra as a custom connector with the endpoint URL and sign in. Ankra's OAuth consent page asks which organisation to use and shows the access requested. In Claude Code, one command registers the server and /mcp runs the sign in.

Cursor and other clients send a token in the Authorization header. Create it in the portal under API Tokens or with the Ankra CLI, and keep it out of shared project files.

terminal
# Claude Code, signs in with OAuth
claude mcp add --transport http ankra \
  https://platform.ankra.app/api/v1/mcp

# A read-only token for Cursor or another client
ankra tokens create cursor --scopes mcp:read
ankra connected, tools filtered by scope

Two scopes, clear lines

mcp:read reaches every read-only tool and changes nothing. mcp:write adds the mutating tools such as apply, scale, delete and pull request creation.

Only the tools you may use

The tool list a client sees is filtered by its token. MCP tokens work only with the MCP endpoint and stay bound to one organisation.

Checked before dispatch

Ankra verifies a cluster belongs to the token's organisation before a cluster tool runs, and refuses mutating calls whose parameters contain literal secrets.

Every call audited

Each resolved tool call, refused calls included, is written to the organisation audit log.

Rate limited per token

Calls are rate limited per token, and write calls also pass a platform write limit that fails closed.

Links back to the portal

Cluster listings carry a portal link, get_portal_url builds one for any other page, and the server asks the model to hand you the link when it reports on a resource.

Step by step

Connect Cursor to the Kubernetes MCP server

Claude users can skip the token and use OAuth. For Cursor and most other clients, these are the steps from the docs.

  1. 1

    Create an MCP token

    Pick mcp:read for a client that should only look. Add mcp:write only when the client needs to change resources. Ankra shows the token once.

    ankra tokens create cursor --scopes mcp:read
  2. 2

    Add the server to Cursor

    Put this in your user level MCP configuration, not in a file you commit.

    {
      "mcpServers": {
        "ankra": {
          "url": "https://platform.ankra.app/api/v1/mcp",
          "headers": {
            "Authorization": "Bearer <ankra-token>"
          }
        }
      }
    }
  3. 3

    Refresh and test it

    Restart or refresh MCP servers in Cursor. Ask it to list your Ankra clusters, and it should call list_clusters and return the clusters in your organisation.

A server you run, or Ankra's hosted one

Open source Kubernetes MCP servers that wrap your kubeconfig are a good fit for many setups. This is where the two approaches differ.

Kubernetes MCP server you run yourselfAnkra MCP server
Where it runsOn your machine or in your clusterHosted by Ankra by default, or in a self-hosted Ankra on Enterprise
CredentialsUsually your kubeconfigOAuth or a token scoped to mcp:read or mcp:write and one organisation
What it reachesThe clusters your kubeconfig reachesEvery cluster connected to your Ankra organisation
ToolsThe Kubernetes API450+ tools across Kubernetes, Stacks, GitOps, pipelines, security, cost and backups
Audit trailWhatever you set upEvery call in the organisation audit log
Air-gapped clustersWorks without internet accessWith a self-hosted Ankra on Enterprise, at custom pricing
Know before you start

How calls behave

The server is stateless, and a few rules follow from that. The server repeats them to the model when it connects.

  • Your MCP client owns the confirmation step. Ankra shows no second prompt before a write tool runs, so only give mcp:write to clients you trust.
  • Every call has a 55 second deadline. A write that timed out may still have started, so read the target before repeating it.
  • Writes that start platform work return an operation id at once. wait_for_execution blocks for up to 50 seconds and returns the settled result.
  • Creating a credential is not available over MCP, because it would mean passing the secret as a tool argument. Create credentials in the portal or the CLI.
  • Claude's OAuth grant lasts seven days, with no refresh token. When it expires, reconnect the connector or run /mcp again.

Questions teams actually ask

What is a Kubernetes MCP server?+

It is a Model Context Protocol server that exposes Kubernetes operations as tools an AI client can call. Instead of pasting kubectl output into a chat, the assistant lists pods, reads logs and events, and with permission applies changes itself.

How do I connect Claude to Kubernetes?+

Add Ankra as a custom connector in Claude's Connectors settings with the URL https://platform.ankra.app/api/v1/mcp, then select Connect and sign in to Ankra. In Claude Code, run claude mcp add --transport http ankra with the same URL, then authenticate from the /mcp command. Custom connectors need a paid Claude plan.

Can the MCP server change my clusters?+

Only with a token or grant that carries mcp:write. With mcp:read the client sees only read-only tools and cannot change anything. Ankra shows no extra confirmation for write tools over MCP, so the client's own approval prompt is the safeguard.

Which AI clients work with it?+

Any client that supports remote MCP servers over HTTP. Claude web, desktop and Claude Code connect with OAuth. Cursor and other clients send a Bearer token created in the Ankra portal or with ankra tokens create.

What does the Ankra MCP server cost?+

The MCP server is part of the Ankra platform and works on the free tier. Ankra bills on worker vCPUs only, every plan includes 30 worker vCPUs free, controller nodes are never billed, and the free tier needs no credit card.

Free tier available

Connect your AI client in a minute

Start on the free tier with 30 worker vCPUs included and no credit card, connect a cluster, then point Claude or Cursor at the endpoint.

Claude and Claude Code are products of Anthropic. Cursor is a product of Anysphere. Ankra is not affiliated with or endorsed by either. Product details on this page were checked against the Ankra documentation in October 2026.