Let an agent deploy, then tell you what happened

MCP is how an AI assistant uses a tool instead of guessing at one. Point Claude, Cursor or any MCP client at Eigon and it can read a repository, deploy it to your own AWS, watch the deployment, read the logs when something breaks, and tell you what it costs. You stay in the chat; it does the console work.

One tool needs no account at all. eigon_scan takes a public repository URL and answers whether it would deploy and what it would cost per month, so you can ask before you sign up for anything.

When a deploy fails, an agent does not have to guess at the repair. Eigon reads the container’s own crash output, works out the cause and proposes the exact edit, and eigon_suggested_fixes hands that to your assistant. It can show you the diff before anything is applied, and Eigon records whether the fix worked, so the same fix has to succeed three times before it is reused on anyone automatically.

Read first, write rarely. The tools an agent reaches for most are the ones that change nothing: scan a repo, read a deployment, check drift, preview a teardown. The write tools are deliberately few.

Get a token

24 of the 25 tools act on your account, so they need an API token. Create one in the dashboard:

  1. 1. Sign in, then click your avatar in the top right and choose API tokens.
  2. 2. Give the token a name you will recognise later, like claude-desktop.
  3. 3. Choose its scopes. See below.
  4. 4. Copy it. It is shown once and stored hashed, so if you lose it you create another.

Which scope

Give a token the least it needs. The API enforces this, so a read-only token cannot deploy even if an agent asks it to.

readEverything that only looks: projects, status, logs, overview, drift, compliance, teardown preview, billing.
deployAnything that changes something: deploy, set a secret, add a domain, pause, resume. This is the one an agent needs to be useful.
adminCreating and revoking other tokens. An agent does not need this, and a deploy token deliberately cannot mint one.

Install and connect

Limited release. The server is not on npm yet, so there is no one-line install today. Email info@eigon.io and we will send you the package and a token. Everything below is what you do once you have it.

The server is a small Node process that your MCP client starts for you. Build it once, then point your client at the absolute path to dist/index.js.

npm install && npm run build

Claude Desktop

Edit ~/Library/Application Support/Claude/claude_desktop_config.json on macOS, or %APPDATA%\Claude\claude_desktop_config.json on Windows, then restart Claude.

{
  "mcpServers": {
    "eigon": {
      "command": "node",
      "args": ["/absolute/path/to/eigon-mcp/dist/index.js"],
      "env": { "EIGON_TOKEN": "eigon_ab12cd_xxxxxxxxxxxxxxxxxxxxxx" }
    }
  }
}

Claude Code

claude mcp add eigon \
  --env EIGON_TOKEN=eigon_ab12cd_xxxxxxxxxxxxxxxxxxxxxx \
  -- node /absolute/path/to/eigon-mcp/dist/index.js

Cursor

Settings, then MCP, then add a server with the same command, args and env as the Claude Desktop block above.

Leaving the token out is a real option. Without EIGON_TOKEN the server still starts and eigon_scan still works, so an agent can evaluate a repository before you have an account. Every other tool returns a clear authentication error rather than failing oddly.

Settings

EIGON_TOKENYour API token. Optional; without it only eigon_scan works.
EIGON_API_BASEAPI base URL. Defaults to https://api.eigon.io. Only set this for a self-hosted control plane.

Your first ask

Once it is connected, talk to your assistant normally. Things that work on the first try:

  • No account needed: “Would github.com/gothinkster/realworld deploy on Eigon, and what would it cost a month?”
  • “List my Eigon projects and tell me which environments are running.”
  • “Deploy my staging environment and tell me when it is live.”
  • “My app returns 500s. Read the logs and tell me what broke.”
  • “Pause my dev environment until Monday, keep the database.”

A first deploy into a fresh environment provisions a network, a cluster and a load balancer, which takes minutes rather than seconds. The tool descriptions say so, so a well-behaved agent waits instead of deciding it has hung.

Every tool

You never call these yourself; your assistant picks from them. They are listed so you can see exactly what you are handing it.

ToolTokenWhat it does
eigon_scannot neededWould this public repo deploy, and what would it cost per month
eigon_list_orgsrequiredYour organisations. An organisation owns projects and carries the subscription
eigon_list_projectsrequiredAn organisation's projects and their environments
eigon_create_projectrequiredCreate a project. One project is one application
eigon_connect_githubrequiredPoint a project at a GitHub repository
eigon_create_environmentrequiredCreate dev, staging or prod inside a project
eigon_set_secretrequiredSet an environment variable or secret
eigon_list_secretsrequiredList variable names. Values are never returned
eigon_unset_secretrequiredRemove a variable. Takes effect on the next deploy
eigon_add_domainrequiredAttach a custom domain and get the DNS records to create
eigon_verify_domainrequiredVerify a domain once its DNS records exist
eigon_deployrequiredDeploy an environment. Returns a deployment id to poll
eigon_deployment_statusrequiredState and events for a deployment, including why it failed
eigon_logsrequiredRecent application logs. The first place to look when a deploy succeeds but the app is down
eigon_environment_overviewrequiredStatus, URL, running services and estimated monthly cost
eigon_driftrequiredInfrastructure changed outside Eigon, usually a console edit during an incident
eigon_compliancerequiredSOC 2, GDPR and HIPAA technical controls checked against an environment
eigon_teardown_previewrequiredExactly what deleting an environment would destroy, without deleting anything
eigon_pauserequiredScale to zero to stop AWS spend. Data is kept by default
eigon_resumerequiredBring a paused environment back, restoring databases from snapshot
eigon_suggested_fixesrequiredFixes Eigon already worked out for a failed deploy, as exact edits
eigon_preview_fixrequiredThe diff a fix would apply, without applying it
eigon_apply_fixrequiredApply a fix and redeploy. Eigon records whether it worked
eigon_costrequiredWhat an environment actually costs, broken down per resource
eigon_billingrequiredYour subscription, plan and current invoice

What it will not do

An agent acting on a loosely worded instruction is the case worth designing for, so some things are deliberately absent.

  • There is no delete tool. eigon_teardown_preview tells an agent exactly what deleting an environment would destroy, and a person runs the deletion. An agent that can irreversibly drop your database on a misread sentence is not a feature.
  • Pause keeps your data. eigon_pause snapshots databases and keeps them unless it is explicitly told otherwise. The destructive option has to be asked for by name.
  • Secrets only go in. eigon_list_secrets returns names, never values. Nothing in Eigon can read a secret back out, including this server.
  • A token cannot widen itself. A deploy token cannot create another token, so an agent cannot grant itself more access than you gave it.

Troubleshooting

The tools do not appear in my client
Restart the client after editing its config. An MCP server is started once when the client launches, so a config change does nothing until it restarts. Check the path in args is absolute and that dist/index.js exists, which means npm run build has been run.
Every tool says it is not authenticated
EIGON_TOKEN is missing or expired. Tokens can be given an expiry, and a revoked token stops working immediately. Create a new one from the avatar menu, then restart the client.
Reading works, deploying is refused
The token has read but not deploy. Scopes cannot be changed after a token is created, so make a new one.
It deployed and the app is still down
Ask for eigon_logs. A deploy can succeed while the container crashes on start, and the logs name the reason. Eigon reads the container’s own crash output rather than the build log, so the answer is usually one line.

Prefer a terminal?

The CLI covers the same ground for people rather than agents, and uses the same tokens and the same scopes.