KosmoKrator

productivity

Terraform Cloud MCP Gateway for AI Agents

Expose Terraform Cloud tools to Claude Code, Cursor, Codex, and other MCP clients through the local KosmoKrator MCP gateway.

7 functions 7 read 0 write API token auth

Terraform Cloud MCP Gateway

Expose Terraform Cloud to MCP clients with `kosmokrator mcp:serve --integration=terraform`.

If the client has never used KosmoKrator before, install it first, then register this integration as a stdio MCP server. The gateway exposes only the selected integration in the example below.

curl -fsSL https://raw.githubusercontent.com/OpenCompanyApp/kosmokrator/main/install.sh | bash
kosmokrator mcp:gateway:install --integration=terraform --write=deny --json
{
  "mcpServers": {
    "kosmokrator-terraform": {
      "type": "stdio",
      "command": "kosmo",
      "args": [
        "mcp:serve",
        "--integration=terraform",
        "--write=deny"
      ]
    }
  }
}

Serve Manually

kosmokrator mcp:serve --integration=terraform --write=deny

MCP Tool Names

KosmoKrator exposes integration tools through the gateway with stable names:

MCP toolSource functionType
integration__terraform__terraform_list_workspaces terraform.terraform_list_workspaces Read read
integration__terraform__terraform_get_workspace terraform.terraform_get_workspace Read read
integration__terraform__terraform_list_runs terraform.terraform_list_runs Read read
integration__terraform__terraform_get_run terraform.terraform_get_run Read read
integration__terraform__terraform_list_variables terraform.terraform_list_variables Read read
integration__terraform__terraform_list_organizations terraform.terraform_list_organizations Read read
integration__terraform__terraform_get_current_user terraform.terraform_get_current_user Read read

Write Access

Start with --write=deny for read-only MCP clients. Use --write=ask or --write=allow only when the client and workspace are trusted.