<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Prateek Singh</title>
    <description>The latest articles on DEV Community by Prateek Singh (@prateek_kumar_singh).</description>
    <link>https://dev.to/prateek_kumar_singh</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4155828%2F988a065e-d552-460d-a365-6ad232ea71a8.jpeg</url>
      <title>DEV Community: Prateek Singh</title>
      <link>https://dev.to/prateek_kumar_singh</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/prateek_kumar_singh"/>
    <language>en</language>
    <item>
      <title>Give Cursor, Claude Code or Codex your Azure architecture over MCP</title>
      <dc:creator>Prateek Singh</dc:creator>
      <pubDate>Fri, 02 Oct 2026 08:00:33 +0000</pubDate>
      <link>https://dev.to/cloudeval-ai/give-cursor-claude-code-or-codex-your-azure-architecture-over-mcp-1b31</link>
      <guid>https://dev.to/cloudeval-ai/give-cursor-claude-code-or-codex-your-azure-architecture-over-mcp-1b31</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;TL;DR:&lt;/strong&gt; To give Cursor, Claude Code or Codex your Azure architecture, run the Cloudeval CLI's local MCP server (&lt;code&gt;npx -y @ganakailabs/cloudeval-cli mcp serve --toolset readonly&lt;/code&gt;) with a project-scoped, read-only access key. The agent can then read your architecture graph and saved cost and Well-Architected reports. It can't deploy or change Azure resources.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;em&gt;By Prateek Singh, founder of Ganak AI Labs, the team behind Cloudeval AI. Published 2 October 2026; commands checked against @ganakailabs/cloudeval-cli 0.38.5 and each client's MCP docs that day.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Ask a coding agent "is this storage account reachable from the internet?" and it will happily read &lt;code&gt;main.bicep&lt;/code&gt; and give you an answer. What it can't see is everything outside the file: the other resource groups, the subnet the private endpoint lands in, the cost report from last week, the Well-Architected findings nobody has triaged yet. So it guesses, confidently.&lt;/p&gt;

&lt;p&gt;The Model Context Protocol (MCP) fixes the plumbing side of this. Instead of you pasting screenshots and JSON into chat, the agent calls a tool server and gets structured answers back. This post shows how to connect Cursor, Claude Code or Codex to an MCP server that exposes your Azure architecture graph and saved reports, with a read-only toolset and a scoped key. It finishes with prompts that actually produce useful answers.&lt;/p&gt;

&lt;p&gt;This isn't Microsoft's Azure MCP Server, which queries live Azure resources. The two can run side by side.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Key terms used below&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;MCP (Model Context Protocol):&lt;/strong&gt; an open protocol that lets AI clients such as Cursor, Claude Code and Codex call external tool servers and get structured results.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;stdio server:&lt;/strong&gt; an MCP server the client starts as a local process. It has no network endpoint.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;ARM / Bicep:&lt;/strong&gt; Azure Resource Manager JSON templates, and Microsoft's Bicep language that compiles to them.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The server I'm using is the one in the &lt;a href="https://cloudeval.ai/?utm_source=devto&amp;amp;utm_medium=referral&amp;amp;utm_campaign=mcp-azure-review&amp;amp;utm_content=intro" rel="noopener noreferrer"&gt;Cloudeval&lt;/a&gt; CLI, because it's the one I know best.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Disclosure: I'm the founder of Cloudeval (Ganak AI Labs).&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;If you prefer to watch first, here is the 52-second version of the idea: the same review context, reachable from the terminal, the IDE, CI and your own agents.&lt;/p&gt;

&lt;p&gt;  &lt;iframe src="https://www.youtube.com/embed/wA6poXNBlVs" width="710" height="399"&gt;
  &lt;/iframe&gt;
&lt;/p&gt;

&lt;h2&gt;
  
  
  What can a coding agent read over MCP, and what can't it do?
&lt;/h2&gt;

&lt;p&gt;Before wiring anything up, it's worth being precise about the boundary.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;The agent &lt;strong&gt;can&lt;/strong&gt; read (default &lt;code&gt;readonly&lt;/code&gt; toolset)&lt;/th&gt;
&lt;th&gt;The agent &lt;strong&gt;can't&lt;/strong&gt; do&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Projects your key can see, plus details and overview&lt;/td&gt;
&lt;td&gt;Deploy, change or remediate Azure resources&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Architecture graph nodes and relationships&lt;/td&gt;
&lt;td&gt;See anything outside the projects the key is scoped to&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Saved cost and Well-Architected reports and rule results&lt;/td&gt;
&lt;td&gt;Run reports or AI answers (those need an explicit, wider toolset)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;The validation check catalogue&lt;/td&gt;
&lt;td&gt;Reach a hosted endpoint: the server runs locally over &lt;strong&gt;stdio&lt;/strong&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Agent Profile definitions (&lt;code&gt;architecture&lt;/code&gt;, &lt;code&gt;cost&lt;/code&gt;, &lt;code&gt;security-reviewer&lt;/code&gt;, ...)&lt;/td&gt;
&lt;td&gt;Read live AWS or GCP. Inputs are live Azure (Cloud sync), ARM JSON, Bicep compiled to ARM, and AWS CloudFormation as a static beta&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The data comes from Cloudeval projects, so you need at least one: either a live Azure subscription connected through Cloud sync, or an imported template. If you write Bicep, compile it first (&lt;code&gt;az bicep build&lt;/code&gt;) and import the ARM JSON. Cloudeval reviews the compiled output rather than parsing &lt;code&gt;.bicep&lt;/code&gt; directly.&lt;/p&gt;

&lt;h2&gt;
  
  
  How do I connect Cursor, Claude Code or Codex to Azure architecture over MCP?
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Create a scoped, read-only access key.&lt;/li&gt;
&lt;li&gt;Check the server locally with &lt;code&gt;mcp status&lt;/code&gt; and &lt;code&gt;doctor --mcp&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Add the stdio server to your client's MCP config.&lt;/li&gt;
&lt;li&gt;Verify the tool list and the project scope.&lt;/li&gt;
&lt;li&gt;Keep the &lt;code&gt;readonly&lt;/code&gt; toolset and widen access only on purpose.&lt;/li&gt;
&lt;li&gt;Use Agent Profiles as reviewer lenses.&lt;/li&gt;
&lt;li&gt;Use prompts that ask for cited evidence.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Each step is covered below.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 1: Create a scoped, read-only access key
&lt;/h2&gt;

&lt;p&gt;Don't hand an agent your interactive login. Create a dedicated key:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;In the Cloudeval app, open &lt;strong&gt;Developer → API &amp;amp; CLI access keys&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Create a key from the &lt;strong&gt;MCP Read-only&lt;/strong&gt; template.&lt;/li&gt;
&lt;li&gt;Scope it to the one project you want the agent to see.&lt;/li&gt;
&lt;li&gt;Check the expiry and capabilities. The template defaults to 30 days. It includes project, connection, report, download, diagram-export and MCP access, but &lt;strong&gt;not&lt;/strong&gt; billing reads or evaluation runs.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fqmf3ybvy3gbn434n8duj.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fqmf3ybvy3gbn434n8duj.png" alt="Cloudeval create auth key form with the MCP Read-only template selected, a project scope picker and a 30d expiry" width="800" height="377"&gt;&lt;/a&gt;&lt;br&gt;
&lt;em&gt;The create-key form with the MCP Read-only template, a project scope and the 30-day default expiry (the docs example names the key for another client; name yours after the agent that uses it). (Source: Cloudeval docs)&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Store it in your shell profile or secret manager as &lt;code&gt;CLOUDEVAL_ACCESS_KEY&lt;/code&gt;. Each client config below reads it from the environment, so the secret never lands in a file you might commit.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nb"&gt;export &lt;/span&gt;&lt;span class="nv"&gt;CLOUDEVAL_ACCESS_KEY&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;"&amp;lt;your scoped key&amp;gt;"&lt;/span&gt;   &lt;span class="c"&gt;# keep out of dotfiles you commit&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Step 2: Check the server locally
&lt;/h2&gt;

&lt;p&gt;You need Node.js 20+. The no-install form uses &lt;code&gt;npx&lt;/code&gt;. If you'd rather install globally, run &lt;code&gt;npm install -g @ganakailabs/cloudeval-cli&lt;/code&gt; and use &lt;code&gt;cloudeval&lt;/code&gt; directly.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# Inspect the MCP surface and diagnose local setup before touching any client&lt;/span&gt;
npx &lt;span class="nt"&gt;-y&lt;/span&gt; @ganakailabs/cloudeval-cli mcp status &lt;span class="nt"&gt;--format&lt;/span&gt; json
npx &lt;span class="nt"&gt;-y&lt;/span&gt; @ganakailabs/cloudeval-cli doctor &lt;span class="nt"&gt;--mcp&lt;/span&gt; &lt;span class="nt"&gt;--format&lt;/span&gt; json
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F25e9tyqv4nabepqjg9u2.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F25e9tyqv4nabepqjg9u2.png" alt="Terminal output of cloudeval doctor --mcp --format json listing the MCP server info, toolsets, tools, resources and prompts" width="799" height="544"&gt;&lt;/a&gt;&lt;br&gt;
&lt;em&gt;&lt;code&gt;doctor --mcp --format json&lt;/code&gt; shows the server, toolsets, tools, resources and prompts before any client is involved (docs capture from an earlier CLI version, so your lists may be longer). (Source: Cloudeval docs)&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The command every client will launch is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npx &lt;span class="nt"&gt;-y&lt;/span&gt; @ganakailabs/cloudeval-cli mcp serve &lt;span class="nt"&gt;--toolset&lt;/span&gt; &lt;span class="nb"&gt;readonly&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Two things that trip people up:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Don't run &lt;code&gt;login&lt;/code&gt; through the MCP process.&lt;/strong&gt; &lt;code&gt;mcp serve&lt;/code&gt; reserves stdin for protocol messages. Authenticate beforehand (stored &lt;code&gt;cloudeval login&lt;/code&gt;, or &lt;code&gt;cloudeval login --headless&lt;/code&gt; over SSH), or rely on the env var.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Containers don't inherit your host login.&lt;/strong&gt; Pass the scoped key at runtime.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The CLI can also generate the config for you. Always start with &lt;code&gt;--dry-run&lt;/code&gt; so you can read what it would write:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;cloudeval mcp setup cursor &lt;span class="nt"&gt;--dry-run&lt;/span&gt; &lt;span class="nt"&gt;--toolset&lt;/span&gt; &lt;span class="nb"&gt;readonly
&lt;/span&gt;cloudeval mcp setup codex  &lt;span class="nt"&gt;--dry-run&lt;/span&gt; &lt;span class="nt"&gt;--toolset&lt;/span&gt; &lt;span class="nb"&gt;readonly
&lt;/span&gt;cloudeval mcp setup claude &lt;span class="nt"&gt;--dry-run&lt;/span&gt;
cloudeval mcp setup generic &lt;span class="nt"&gt;--dry-run&lt;/span&gt; &lt;span class="nt"&gt;--toolset&lt;/span&gt; &lt;span class="nb"&gt;readonly&lt;/span&gt; &lt;span class="nt"&gt;--format&lt;/span&gt; json
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The supported targets are &lt;code&gt;codex&lt;/code&gt;, &lt;code&gt;claude&lt;/code&gt;, &lt;code&gt;cursor&lt;/code&gt;, &lt;code&gt;vscode&lt;/code&gt; and &lt;code&gt;generic&lt;/code&gt;. &lt;code&gt;--toolset&lt;/code&gt; defaults to &lt;code&gt;readonly&lt;/code&gt;. Without &lt;code&gt;--dry-run&lt;/code&gt;, setup can write to the client's config file. Pass &lt;code&gt;--config-path&lt;/code&gt; if you want to control where it goes.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 3: Wire up your client
&lt;/h2&gt;

&lt;p&gt;Every client below runs the same stdio command. Only the config syntax differs.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F3vmpcuushw0nwf6ffni0.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F3vmpcuushw0nwf6ffni0.png" alt="Cloudeval MCP client configs for Codex, Cursor, Claude Code, VS Code and generic clients" width="800" height="597"&gt;&lt;/a&gt;&lt;br&gt;
&lt;em&gt;Codex uses a registration command; Cursor, Claude Code, VS Code and generic clients share one stdio config shape. (Source: Cloudeval docs)&lt;/em&gt;&lt;/p&gt;
&lt;h3&gt;
  
  
  Cursor
&lt;/h3&gt;

&lt;p&gt;Add this to &lt;code&gt;.cursor/mcp.json&lt;/code&gt; (project) or &lt;code&gt;~/.cursor/mcp.json&lt;/code&gt; (global). Cursor's &lt;code&gt;${env:NAME}&lt;/code&gt; interpolation keeps the key out of the file:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"mcpServers"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"cloudeval"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"stdio"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"command"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"npx"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"args"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;"-y"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"@ganakailabs/cloudeval-cli"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"mcp"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"serve"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"--toolset"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"readonly"&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"env"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"CLOUDEVAL_ACCESS_KEY"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"${env:CLOUDEVAL_ACCESS_KEY}"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If Cursor is launched from the dock and doesn't see your shell variables, Cursor also supports an &lt;code&gt;envFile&lt;/code&gt; for stdio servers. Point it at a git-ignored file.&lt;/p&gt;

&lt;h3&gt;
  
  
  Claude Code
&lt;/h3&gt;

&lt;p&gt;Claude Code wants its own options (like &lt;code&gt;--env&lt;/code&gt;) before &lt;code&gt;--&lt;/code&gt;, and the server command after it:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;claude mcp add cloudeval &lt;span class="nt"&gt;--env&lt;/span&gt; &lt;span class="nv"&gt;CLOUDEVAL_ACCESS_KEY&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="nv"&gt;$CLOUDEVAL_ACCESS_KEY&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;--&lt;/span&gt; npx &lt;span class="nt"&gt;-y&lt;/span&gt; @ganakailabs/cloudeval-cli mcp serve &lt;span class="nt"&gt;--toolset&lt;/span&gt; &lt;span class="nb"&gt;readonly

&lt;/span&gt;claude mcp get cloudeval     &lt;span class="c"&gt;# confirm it registered and connected&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This uses the default local scope, which is stored in &lt;code&gt;~/.claude.json&lt;/code&gt;. Avoid &lt;code&gt;--scope project&lt;/code&gt; here: that writes &lt;code&gt;.mcp.json&lt;/code&gt; into the repo, and you'd be one &lt;code&gt;git add .&lt;/code&gt; away from committing the key.&lt;/p&gt;

&lt;h3&gt;
  
  
  Codex
&lt;/h3&gt;

&lt;p&gt;You can register it with the documented one-liner:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;codex mcp add cloudeval &lt;span class="nt"&gt;--&lt;/span&gt; cloudeval mcp serve &lt;span class="nt"&gt;--toolset&lt;/span&gt; &lt;span class="nb"&gt;readonly&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;To forward the key from your environment instead of storing its value, edit &lt;code&gt;~/.codex/config.toml&lt;/code&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight toml"&gt;&lt;code&gt;&lt;span class="nn"&gt;[mcp_servers.cloudeval]&lt;/span&gt;
&lt;span class="py"&gt;command&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s"&gt;"npx"&lt;/span&gt;
&lt;span class="py"&gt;args&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s"&gt;"-y"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;"@ganakailabs/cloudeval-cli"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;"mcp"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;"serve"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;"--toolset"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;"readonly"&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;span class="py"&gt;env_vars&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s"&gt;"CLOUDEVAL_ACCESS_KEY"&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Anything else that speaks stdio
&lt;/h3&gt;

&lt;p&gt;Use the generic &lt;code&gt;mcpServers&lt;/code&gt; shape, which is the same entry published in the official MCP Registry under &lt;code&gt;io.github.ganakailabs/cloudeval&lt;/code&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nl"&gt;"mcpServers"&lt;/span&gt;&lt;span class="p"&gt;:{&lt;/span&gt;&lt;span class="nl"&gt;"cloudeval"&lt;/span&gt;&lt;span class="p"&gt;:{&lt;/span&gt;&lt;span class="nl"&gt;"command"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;"npx"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nl"&gt;"args"&lt;/span&gt;&lt;span class="p"&gt;:[&lt;/span&gt;&lt;span class="s2"&gt;"-y"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;"@ganakailabs/cloudeval-cli"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;"mcp"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;"serve"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;"--toolset"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s2"&gt;"readonly"&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;&lt;span class="nl"&gt;"env"&lt;/span&gt;&lt;span class="p"&gt;:{&lt;/span&gt;&lt;span class="nl"&gt;"CLOUDEVAL_ACCESS_KEY"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;"&amp;lt;your scoped key&amp;gt;"&lt;/span&gt;&lt;span class="p"&gt;}}}}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Step 4: Verify before you trust it
&lt;/h2&gt;

&lt;p&gt;Restart the client if it needs a restart, then:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Ask it to &lt;strong&gt;list the available Cloudeval tools&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Run something low-risk: &lt;code&gt;capabilities_get&lt;/code&gt; or &lt;code&gt;projects_list&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Check that the result shows the profile, base URL and auth mode you expect, and &lt;strong&gt;only&lt;/strong&gt; the project you scoped the key to.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;If billing tools return permission errors, that's expected. The MCP Read-only key doesn't grant billing read access.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 5: Keep it read-only and widen on purpose
&lt;/h2&gt;

&lt;p&gt;&lt;code&gt;readonly&lt;/code&gt; is the default because review agents rarely need anything else. If a job calls for more, widen deliberately with one of the focused toolsets:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Toolset&lt;/th&gt;
&lt;th&gt;Use it for&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;readonly&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Project, graph, report and capability reads (the default)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;graph&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Graph, timeline, diff, sync-run and insight reads&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;validation&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;template_validate&lt;/code&gt;, &lt;code&gt;template_test&lt;/code&gt;, &lt;code&gt;template_parse&lt;/code&gt; and rule-catalogue reads&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;reports&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Report runs, downloads and deeplinks&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;billing&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Billing inspection, invoices and explicit checkout tools&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;all&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;The full surface&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Note what's &lt;strong&gt;not&lt;/strong&gt; in &lt;code&gt;readonly&lt;/code&gt;: &lt;code&gt;ask&lt;/code&gt;, &lt;code&gt;agent_profiles_run&lt;/code&gt;, &lt;code&gt;reports_run&lt;/code&gt; and the template-validation calls. Those start work on the Cloudeval side and can use credits. Your key also has to allow them.&lt;/p&gt;

&lt;p&gt;After changing toolsets, restart the client so it refreshes its tool list.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 6: Use Agent Profiles as reviewer lenses
&lt;/h2&gt;

&lt;p&gt;Agent Profiles change how an answer is organized, not what evidence is available. The public ids are &lt;code&gt;architecture&lt;/code&gt;, &lt;code&gt;cost&lt;/code&gt;, &lt;code&gt;triage&lt;/code&gt;, &lt;code&gt;remediation&lt;/code&gt;, &lt;code&gt;visual-explainer&lt;/code&gt;, &lt;code&gt;scripter&lt;/code&gt;, &lt;code&gt;change-reviewer&lt;/code&gt;, &lt;code&gt;evidence-auditor&lt;/code&gt; and &lt;code&gt;security-reviewer&lt;/code&gt;. There's no separate Well-Architected profile, because &lt;code&gt;architecture&lt;/code&gt; already includes that lens.&lt;/p&gt;

&lt;p&gt;On &lt;code&gt;readonly&lt;/code&gt;, the agent can discover them with &lt;code&gt;agent_profiles_list&lt;/code&gt; and &lt;code&gt;agent_profiles_get&lt;/code&gt;. Running one is excluded from &lt;code&gt;readonly&lt;/code&gt;, so either use a wider toolset or run it from your terminal:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;cloudeval agents run change-reviewer &lt;span class="s2"&gt;"Review this pull request"&lt;/span&gt; &lt;span class="nt"&gt;--project&lt;/span&gt; &amp;lt;project-id&amp;gt;
cloudeval agents run security-reviewer &lt;span class="s2"&gt;"Review exposure and identity risk"&lt;/span&gt; &lt;span class="nt"&gt;--project&lt;/span&gt; &amp;lt;project-id&amp;gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The &lt;code&gt;change-reviewer&lt;/code&gt; profile is built to return PASS/WARN/BLOCK with current, proposed and live evidence kept separate. If evidence is stale or missing, it should report an evidence gap rather than a pass.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 7: Prompts that work
&lt;/h2&gt;

&lt;p&gt;Vague prompts get vague answers. These work better because each one names the evidence it wants:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Using the cloudeval tools, list my projects, then get the architecture graph for "&amp;lt;project name&amp;gt;".
Which resources have public network access, and which relationships connect them to data stores?
Cite the resource ID for each claim.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Read the latest Well-Architected report for project &amp;lt;id&amp;gt;. Give me the five highest-severity findings
as a table: resource, finding, pillar, and the report reference. If any pillar is "Not assessed",
list it separately. Don't fill gaps with general advice.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;I'm about to change infra/main.json in this repo. Using the project graph, tell me which resources
depend on the App Service plan defined there, so I know what this PR could affect.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Get the agent profile "cost" and summarize what it emphasizes. Then, using only the latest cost
report for project &amp;lt;id&amp;gt;, name the top three cost drivers and what evidence supports each one.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The server also publishes MCP prompts (&lt;code&gt;cloudeval-architecture-review&lt;/code&gt;, &lt;code&gt;cloudeval-template-preflight&lt;/code&gt;, &lt;code&gt;cloudeval-impact-analysis&lt;/code&gt; and others) and resources such as &lt;code&gt;cloudeval://projects&lt;/code&gt; and &lt;code&gt;cloudeval://reports/latest&lt;/code&gt;. Clients that support prompts and resources show them in their prompt or &lt;code&gt;@&lt;/code&gt; menus.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fjntbqhnu2xzx82vroi66.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fjntbqhnu2xzx82vroi66.png" alt="Cloudeval agent answer grounded in selected resources and the diagram" width="800" height="521"&gt;&lt;/a&gt;&lt;br&gt;
&lt;em&gt;A useful agent answer stays tied to the project, the selected resources and the visible diagram. (Source: Cloudeval docs)&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;A habit worth keeping: &lt;strong&gt;ask the agent to name the project, resource or report behind every important claim.&lt;/strong&gt; If it can't, treat the answer as a hypothesis.&lt;/p&gt;

&lt;h2&gt;
  
  
  What are the common MCP setup mistakes?
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Committing the key.&lt;/strong&gt; Use local or user scope and &lt;code&gt;${env:...}&lt;/code&gt; or &lt;code&gt;env_vars&lt;/code&gt;. Don't put it in Dockerfiles or project-scoped config you check in.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Expecting a URL.&lt;/strong&gt; This is a local stdio server. There's no Cloudeval-hosted remote MCP endpoint to paste into a web chat.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Assuming it sees live state.&lt;/strong&gt; A template-backed project describes the template you imported, not what's running. Check the sync time on live projects.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Letting the agent apply changes.&lt;/strong&gt; The agent can prepare a fix. A human reviews it, and the normal deployment pipeline ships it.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Is this the same as Microsoft's Azure MCP Server?
&lt;/h3&gt;

&lt;p&gt;No. Microsoft's Azure MCP Server queries live Azure resources. The Cloudeval MCP server gives the agent review context: project architecture graphs, saved cost and Well-Architected reports and the validation check catalogue. They can run side by side in the same client.&lt;/p&gt;

&lt;h3&gt;
  
  
  How do I add an MCP server to Claude Code?
&lt;/h3&gt;

&lt;p&gt;Run &lt;code&gt;claude mcp add &amp;lt;name&amp;gt;&lt;/code&gt;, put Claude Code's own options such as &lt;code&gt;--env&lt;/code&gt; before &lt;code&gt;--&lt;/code&gt;, and the server command after it. Then run &lt;code&gt;claude mcp get &amp;lt;name&amp;gt;&lt;/code&gt; to confirm it connected. The default local scope keeps the entry out of your repo.&lt;/p&gt;

&lt;h3&gt;
  
  
  Does it work in VS Code?
&lt;/h3&gt;

&lt;p&gt;Yes. &lt;code&gt;cloudeval mcp setup vscode --dry-run&lt;/code&gt; prints the config for VS Code. The server is the same stdio command used by Cursor, Claude Code and Codex.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can the agent change my Azure resources over MCP?
&lt;/h3&gt;

&lt;p&gt;No. The default &lt;code&gt;readonly&lt;/code&gt; toolset reads projects, graphs, reports and the check catalogue. It can't deploy, change or remediate Azure resources. Tools that start work, such as report runs, are only in wider toolsets that you enable on purpose.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is there a hosted MCP URL I can paste into a web chat?
&lt;/h3&gt;

&lt;p&gt;No. It's a local stdio server that your client launches as a process. There's no Cloudeval-hosted remote MCP endpoint.&lt;/p&gt;

&lt;h2&gt;
  
  
  Takeaway
&lt;/h2&gt;

&lt;p&gt;MCP doesn't make an agent smarter about your architecture by itself. What helps is giving it scoped access to real evidence: a graph, saved reports and a check catalogue, with read-only as the default. Start with one project, one key and the &lt;code&gt;readonly&lt;/code&gt; toolset, then make the agent cite its sources. Widen access only when a specific job needs it.&lt;/p&gt;

&lt;p&gt;If you're choosing between MCP servers for Azure work, I wrote up &lt;a href="https://cloudeval.ai/answers/mcp-tools-for-azure-infrastructure-review?utm_source=devto&amp;amp;utm_medium=referral&amp;amp;utm_campaign=mcp-azure-review&amp;amp;utm_content=cta" rel="noopener noreferrer"&gt;which MCP tool fits which Azure review job&lt;/a&gt;. It covers Microsoft's &lt;a href="https://learn.microsoft.com/en-us/azure/developer/azure-mcp-server/overview" rel="noopener noreferrer"&gt;Azure MCP Server&lt;/a&gt; for live resource queries, Bicep tooling while authoring, and project-level review context. The full client reference is in the &lt;a href="https://docs.cloudeval.ai/agents/mcp-client-setup?utm_source=devto&amp;amp;utm_medium=referral&amp;amp;utm_campaign=mcp-azure-review&amp;amp;utm_content=docs" rel="noopener noreferrer"&gt;MCP client setup docs&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Related on cloudeval.ai&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://cloudeval.ai/answers/mcp-tools-for-azure-infrastructure-review?utm_source=devto&amp;amp;utm_medium=referral&amp;amp;utm_campaign=mcp-azure-review&amp;amp;utm_content=related-answer" rel="noopener noreferrer"&gt;Which MCP tools help review Azure infrastructure?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cloudeval.ai/answers/review-bicep-before-deployment?utm_source=devto&amp;amp;utm_medium=referral&amp;amp;utm_campaign=mcp-azure-review&amp;amp;utm_content=related-bicep" rel="noopener noreferrer"&gt;How to review a Bicep or ARM template before deployment&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.cloudeval.ai/agents/profiles?utm_source=devto&amp;amp;utm_medium=referral&amp;amp;utm_campaign=mcp-azure-review&amp;amp;utm_content=related-profiles-docs" rel="noopener noreferrer"&gt;Agent Profiles reference&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cloudeval.ai/compare?utm_source=devto&amp;amp;utm_medium=referral&amp;amp;utm_campaign=mcp-azure-review&amp;amp;utm_content=related-compare" rel="noopener noreferrer"&gt;Compare Cloudeval with other cloud review and diagram tools&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Try it&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Want your own agent to answer from your architecture? Open the &lt;a href="https://cloudeval.ai/app?utm_source=devto&amp;amp;utm_medium=referral&amp;amp;utm_campaign=mcp-azure-review&amp;amp;utm_content=try-app" rel="noopener noreferrer"&gt;Cloudeval app&lt;/a&gt; and follow the &lt;a href="https://docs.cloudeval.ai/agents/mcp-client-setup?utm_source=devto&amp;amp;utm_medium=referral&amp;amp;utm_campaign=mcp-azure-review&amp;amp;utm_content=try-docs" rel="noopener noreferrer"&gt;MCP client setup guide&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;About the author&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Prateek Singh&lt;/strong&gt; is the founder of Ganak AI Labs and builds Cloudeval AI.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://cloudeval.ai/?utm_source=devto&amp;amp;utm_medium=referral&amp;amp;utm_campaign=mcp-azure-review&amp;amp;utm_content=author" rel="noopener noreferrer"&gt;cloudeval.ai&lt;/a&gt; · &lt;a href="https://docs.cloudeval.ai/?utm_source=devto&amp;amp;utm_medium=referral&amp;amp;utm_campaign=mcp-azure-review&amp;amp;utm_content=author" rel="noopener noreferrer"&gt;Docs&lt;/a&gt; · &lt;a href="https://www.youtube.com/@GanakAILabs" rel="noopener noreferrer"&gt;YouTube&lt;/a&gt; · &lt;a href="https://github.com/ganakailabs" rel="noopener noreferrer"&gt;GitHub&lt;/a&gt; · &lt;a href="https://www.linkedin.com/in/prateekkumarsingh/" rel="noopener noreferrer"&gt;LinkedIn&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

</description>
      <category>ai</category>
      <category>mcp</category>
      <category>azure</category>
      <category>devops</category>
    </item>
  </channel>
</rss>
