Kubeadapt MCP
Permissions and security
What a Kubeadapt MCP connection can read, how sign-in and consent work, how long connections last, the activity log, and the controls admins have.
Kubeadapt MCP gives an AI tool the same view of Kubeadapt you have, narrowed to what you chose when you connected. It never changes anything.
Read-only
Every tool only reads. No tool creates, changes or deletes anything in Kubeadapt, and nothing reaches your clusters. Rightsizing plans include a YAML patch for you to review and apply through your own deployment process.
Your permissions, then your choices
A connection acts as you, with two limits on top of your own access:
- Your permissions in Kubeadapt. The connection sees only the clusters your role and user groups give you. If an admin later changes your role or your groups, the connection follows. If you leave the organization, your connections end.
- What you chose when connecting. On the consent page you pick:
- Kinds of data: Costs and carbon, Savings, Alerts, and Network costs. The AI tool only gets the tools for the kinds you allow.
- Clusters: all the clusters you can see, including ones you get access to later, or specific clusters.
To change your choices, connect again from your AI tool and end the old connection.
Sign-in
Your AI tool signs in through Kubeadapt with OAuth, the standard used across MCP. You sign in on Kubeadapt's own page, including with SSO, and the AI tool never sees your password. There are no API keys to create, paste or rotate.
Connections use short-lived access tokens that the AI tool renews on its own. Several sessions of the same tool, such as two Claude Code windows, can share one connection.
How long a connection lasts
A connection lasts 90 days unless your admin chose a different length, between 7 and 365 days. When it ends, your AI tool asks you to sign in again. You can end a connection sooner at any time.
Connections and activity
Settings → Kubeadapt MCP in the Kubeadapt app has three views:
- Connect: setup for each AI tool, ready to copy.
- Connections: the AI tools connected to your account, with the data and clusters each may read and when each was last used. End any of them with Revoke; it takes effect immediately.
- Activity: every tool call, with the tool, a summary of what was asked, the result and when it happened.
Admins see the connections and activity of everyone in the organization and can revoke any connection, or all of them at once.
Admin controls
Admins set the organization's access policy under Settings → Kubeadapt MCP → Access policy:
| Setting | What it does |
|---|---|
| Allow Kubeadapt MCP | Turns Kubeadapt MCP on or off for the organization. Turning it off stops every connection. |
| Data AI tools can reach | The kinds of data any connection may be given. People can choose less, never more. |
| Which AI tools can connect | Any AI tool, or only the tools Kubeadapt has verified. |
| Connection length | How long a connection lasts before its owner signs in again, from 7 to 365 days. |
Turning Kubeadapt MCP off, narrowing the data AI tools can reach and allowing only verified tools apply to existing connections within a minute. A new connection length applies to connections made after the change.
How answers are protected
- Names are data, not instructions. Workload names, labels and other text from your clusters are cleaned and marked as data before they reach the AI tool, and Kubeadapt tells the tool never to follow instructions found in them.
- No secrets. Tool answers never include tokens, keys, webhook addresses, notification channel settings or Kubernetes annotations.
- Bounded answers. Answers are capped in size, and long lists are cut with a note saying so.
- Rate limits. Each connection can make about 60 requests a minute, and each organization about 600, so one busy tool can't slow down Kubeadapt for anyone else.
What the AI tool keeps
The figures your AI tool receives become part of your conversation with it, and how long they are kept follows that tool's data policy and your settings there. Choose the kinds of data and clusters you connect with that in mind.