Skip to content

Cloud and Platform MCP Servers: AWS, Azure, Google Cloud, Vercel and Stripe

Cloud and platform MCP servers let Claude Code, Codex and Cursor read live state from AWS, Azure, Google Cloud, Vercel and Stripe instead of guessing it. In September 2026 each vendor ships an official server, usually inside a plugin with skills. They are safe only behind a read-only identity, a pinned version, and a deterministic check of the agent’s answer.

This page is for developers and tech leads whose agent writes the code but cannot see the platform it runs on: it proposes a Lambda upgrade without knowing which functions exist, or “fixes” a failed Vercel preview by guessing at a build log it never read. Each vendor server closes that gap, and each one can also delete, deploy or charge money with your credentials. The setup below gives the agent eyes first and hands only through CI.

  • A read-only identity per platform that every server on this page connects through
  • Verified install lines for the AWS, Azure (pinned stable), gcloud, Vercel and Stripe servers in all three agents
  • A Lambda runtime audit you check with one AWS CLI query, not the agent’s summary
  • A scheduled Terraform drift check that fails CI when Azure has drifted
  • A complete loop for a failed Vercel preview: MCP logs, local reproduction, fix, redeploy, smoke test
  • The traps, including an npm latest tag that is a beta

Which cloud or platform MCP server do you need?

Section titled “Which cloud or platform MCP server do you need?”

Pick by where your code runs. Every server below is the vendor’s own. Popularity: GitHub stars from the GitHub API and installs from the Claude Marketplace directory (claude.com/plugins), both recorded 2026-09-26 in the site’s research dossiers.

PlatformServerTransport and authRead-only controlPopularity (2026-09-26)
AWSAWS MCP Server, through the Agent Toolkit for AWS (aws-core plugin)Local uvx proxy that signs requests with SigV4 to https://aws-mcp.us-east-1.api.aws/mcpThe IAM identity behind --profile; the proxy’s --read-only flagaws/agent-toolkit-for-aws ★2.7k, awslabs/mcp ★9.7k
AWS docsAWS Knowledge MCPRemote https://knowledge-mcp.global.api.aws, no auth, rate-limitedDocumentation onlypart of awslabs/mcp
AzureAzure MCP Server (@azure/mcp)Local stdio, your Azure identity (az login)--read-only on the server, plus RBACmicrosoft/mcp ★3.7k
Google Cloudgcloud MCP (@google-cloud/gcloud-mcp), plus Google-hosted endpointsLocal stdio with your gcloud account; hosted endpoints use Google OAuthImpersonate a service account with a viewer rolegoogleapis/gcloud-mcp ★914
VercelVercel MCPRemote https://mcp.vercel.com, OAuthRead-only in its initial release (per Vercel’s plugin manifest)vercel plugin 227,688 installs
StripeStripe MCPRemote https://mcp.stripe.com (OAuth) or local @stripe/mcpSandbox or test mode, and a restricted API key for the local serverstripe/ai ★1.8k; stripe plugin 61,066 installs

Cloudflare has its own page, Cloudflare MCP servers, and Terraform, Kubernetes and Docker live in infrastructure MCP servers.

Create a read-only identity before you connect anything

Section titled “Create a read-only identity before you connect anything”

Every cloud server acts as whoever it authenticates as; if that is your admin login, the agent is an admin. Set up the narrow identity first: a server flag can be mistyped and a plugin update can change a default, while an IAM role still holds.

PlatformThe identity to createHow the server picks it up
AWSAn IAM role with the AWS managed ReadOnlyAccess policy (or a narrower custom policy), assumed through a profile named agent-readonly--profile agent-readonly on the proxy, or AWS_MCP_PROXY_PROFILES="agent-readonly" in the environment for the plugin
AzureFor your own sessions, the server’s --read-only flag; for automation, a service principal with the Reader role on one resource groupaz login session or the Azure Identity environment variables
Google CloudA service account with roles/viewer on one projectgcloud config set auth/impersonate_service_account agent-viewer@PROJECT_ID.iam.gserviceaccount.com
VercelYour Vercel login, scoped to the team you choose at OAuthBrowser OAuth on first connection
StripeA sandbox (or test mode) account; for the local server, a restricted key (rk_test_…)OAuth to the sandbox, or STRIPE_SECRET_KEY in the environment

The AWS profile looks like this in ~/.aws/config (the role and account ID are yours):

[profile agent-readonly]
role_arn = arn:aws:iam::123456789012:role/AgentReadOnly
source_profile = default
region = eu-west-1

Connect AWS through the Agent Toolkit for AWS

Section titled “Connect AWS through the Agent Toolkit for AWS”

The Agent Toolkit for AWS (aws/agent-toolkit-for-aws, “GA” badge) is what AWS now recommends over the older awslabs servers. Its aws-core plugin configures the managed AWS MCP Server and 25 AWS skills (version 1.1.0). The server has four tools: search_documentation and retrieve_skill (no authentication), call_aws (300+ AWS services) and run_script (sandboxed Python). AWS logs every request to CloudTrail and adds IAM condition keys that tell agent actions from human ones.

Terminal window
# In a Claude Code session: the plugin brings the server and the skills
/plugin install aws-core@claude-plugins-official
/reload-plugins

If the install reports that the marketplace is not found, run claude plugin marketplace add anthropics/claude-plugins-official and retry. The plugin starts the proxy with --skip-auth and no profile, so it uses your default credential chain. Point it at the read-only role before you start claude:

Terminal window
export AWS_MCP_PROXY_PROFILES="agent-readonly"

Or skip the plugin and add the server alone, with the profile on the command line:

Terminal window
claude mcp add aws-mcp -- uvx mcp-proxy-for-aws-cli@latest \
https://aws-mcp.us-east-1.api.aws/mcp --profile agent-readonly --region eu-west-1

mcp-proxy-for-aws-cli (PyPI 1.7.0) is the version-pinned distribution of the proxy: even @latest installs a frozen dependency tree. For documentation questions only, the AWS Knowledge MCP needs no credentials: claude mcp add --transport http aws-knowledge https://knowledge-mcp.global.api.aws (or codex mcp add aws-knowledge --url https://knowledge-mcp.global.api.aws).

Audit Lambda runtimes without touching anything

Section titled “Audit Lambda runtimes without touching anything”

Try this first: it is read-only, and the answer is a list you can check with one command.

You get a table of functions, a plan grouped by risk and a closing CLI query. Run it, or this one, and compare the names:

Terminal window
# Terminal: deterministic cross-check of the agent's list
aws lambda list-functions --region eu-west-1 --profile agent-readonly \
--query "Functions[?Runtime=='nodejs18.x'].FunctionName" --output text

If the lists differ, the agent stopped paginating or filtered on the wrong field. That comparison is the verification. The runtime change ships as an infrastructure-as-code pull request (SAM, CDK or Terraform) that CI deploys, not as a live update-function-configuration call.

The proxy also has a --read-only flag that drops every tool not annotated readOnlyHint. Rely on the IAM role first. If you add --read-only, run /mcp and confirm call_aws is still listed before you rely on it.

The Azure MCP Server queries and manages many Azure services with your local Azure identity. The npm latest tag is a beta: on 2026-09-26 @azure/mcp@latest resolved to 3.0.0-beta.47, while the newest stable release is 2.0.5, and the azure plugin in claude-plugins-official runs @azure/mcp@latest. Pin the stable version and start it read-only.

Terminal window
az login
az account set --subscription "SUBSCRIPTION_NAME_OR_ID"
claude mcp add azure -- npx -y @azure/mcp@2.0.5 server start --read-only

The setup is identical in all three agents: same package, same arguments, same az login. The Azure MCP command reference (microsoft/mcp) adds two switches. The default namespace mode exposes one tool per Azure service, which keeps the tool list short, and --namespace storage --namespace functionapp limits the server to the services you name. When a prompt names no subscription, the server uses your Azure CLI default (az account set) or AZURE_SUBSCRIPTION_ID.

For Azure documentation, the Microsoft Learn MCP server is remote and needs no auth: claude mcp add --transport http microsoft-learn https://learn.microsoft.com/api/mcp.

Check the first answer with az storage account list --query '[?allowBlobPublicAccess].name' -o tsv. The fix is a Bicep or Terraform change that goes through review, not a live toggle.

Detect drift between Terraform and live Azure

Section titled “Detect drift between Terraform and live Azure”

Drift detection suits an agent because the evidence is concrete on both sides: the declared resources in the repo and the deployed ones in Azure.

A CI runner has none of your local MCP configuration, so the job brings the pinned server with it. Authenticate with the Azure Identity environment variables of a Reader service principal, give the runner the agent’s own API key as a CI secret (see headless agents in CI), run from the default branch, and fail the job unless the report is exactly NO_DRIFT, so a run that could not reach Azure fails too.

Check in ci/azure-mcp.json:

{
"mcpServers": {
"azure": {
"command": "npx",
"args": ["-y", "@azure/mcp@2.0.5", "server", "start", "--read-only"]
}
}
}
Terminal window
claude -p "$(cat prompts/azure-drift.md)" \
--mcp-config ci/azure-mcp.json --strict-mcp-config \
--allowedTools "mcp__azure__*" "Read" "Glob" "Grep" > drift.md
[ "$(tr -d '[:space:]' < drift.md)" = 'NO_DRIFT' ] || { cat drift.md; exit 1; }

--strict-mcp-config loads only the servers in that file. claude -p starts in Manual permission mode, so --allowedTools is what lets the Azure tools and file reads run.

Google offers two routes. gcloud MCP (@google-cloud/gcloud-mcp, npm 0.5.3) wraps the gcloud CLI in one tool, run_gcloud_command, and blocks commands that take arbitrary input or open interactive sessions. Its README says it is in preview, “not an officially supported Google product”, and its last npm release was 2026-01-05. It acts with your active gcloud account, so first make every gcloud call, the agent’s included, impersonate the viewer service account:

Terminal window
# Terminal: applies to all three agents
gcloud config set auth/impersonate_service_account agent-viewer@acme-prod.iam.gserviceaccount.com

The three installs differ only in the add line:

Terminal window
claude mcp add gcloud -- npx -y @google-cloud/gcloud-mcp

The second route is Google-hosted MCP endpoints at https://<service>.googleapis.com/mcp, registered in the Official MCP Registry for compute, container (GKE), run, sqladmin, firestore, monitoring and more. They authenticate with Google OAuth against your IAM permissions and may need your own OAuth client (claude mcp add --transport http … --client-id …). Test one in your client before you roll it out; until then, use gcloud MCP.

Google’s google/skills repo (★20.4k) adds skills and a plugin marketplace, google-plugins. Its google-cloud-developer plugin bundles authentication and gcloud safety skills with the Developer Knowledge MCP server, which needs DEVELOPERKNOWLEDGE_API_KEY exported before the agent starts:

Terminal window
claude plugin marketplace add google/skills
claude plugin install google-cloud-developer@google-plugins

Fix a failed Vercel preview deployment end to end

Section titled “Fix a failed Vercel preview deployment end to end”

Vercel’s remote server at https://mcp.vercel.com is read-only in its initial release, per Vercel’s plugin manifest: it searches docs, lists projects and deployments, and reads logs, which is what a failed preview needs. The vercel plugin bundles it with 37 skills and 3 hooks and adds about 4,217 always-on tokens to every session (claude plugin details, Claude Code 2.1.283). Install it per project, or add the server alone.

Terminal window
claude plugin install vercel@claude-plugins-official --scope project
# or the server alone:
claude mcp add --transport http vercel https://mcp.vercel.com

Then run /mcp in a session and log in to Vercel.

The loop keeps the agent’s MCP access read-only; writes go through the Vercel CLI or your Git integration, as a human’s would.

  1. Read the failure through MCP. The agent finds the latest failed preview for your branch and pulls the build log lines that matter.

  2. Reproduce it locally, so you can prove the fix. Pull the preview environment and build with Vercel’s builder:

    Terminal window
    vercel pull --yes --environment=preview
    vercel build

    vercel pull writes project settings and environment values under .vercel/, which must stay out of Git.

  3. Fix it and let the quality gates decide. The agent adds a test that fails on the old behaviour, then changes the code. Type check, lint and tests must pass locally before anything ships.

  4. Redeploy the preview. If the project deploys through Git integration, push the branch and Vercel builds a new preview. Otherwise deploy the build you just verified: vercel deploy --prebuilt (without --prebuilt, a prior vercel build is ignored). In Claude Code, the plugin’s /vercel:deploy command does the same with preflight checks and defaults to preview.

  5. Verify the new preview, not the agent’s claim. vercel inspect <deployment-url> --wait waits for the build to finish, and vercel inspect <deployment-url> --logs shows the build log. Then run a smoke test against the preview URL and attach the result to the pull request. The reviewer signs off on the evidence: the failing test, the green build log and the smoke test.

Production promotion stays in your pipeline. The ordering of preview, canary and production is covered in progressive delivery.

Connect Stripe in a sandbox with a restricted key

Section titled “Connect Stripe in a sandbox with a restricted key”

Stripe’s server can create products, prices, customers and refunds, so it can move money. Keep it on a sandbox or test-mode account. Stripe’s stripe-best-practices skill recommends separate sandboxes for local development and CI, and restricted API keys (rk_…) with only the permissions a job needs.

Terminal window
claude plugin install stripe@claude-plugins-official

The plugin connects to https://mcp.stripe.com over OAuth and adds Stripe’s skills and two commands, /stripe:explain-error and /stripe:test-cards, for about 2,238 always-on tokens. When you authorize, pick the sandbox account.

Every Stripe object carries a livemode field, so the mode check is deterministic. Prove the webhook path with events, not by reading the handler: stripe listen --forward-to localhost:3000/webhook in one terminal, stripe trigger checkout.session.completed in another, and a test that asserts what the handler wrote.

Pair each server with the vendor’s skills, and watch the context cost

Section titled “Pair each server with the vendor’s skills, and watch the context cost”

A server gives the agent live state; a skill gives it the vendor’s rules for acting on that state. Install skills only for the platforms you deploy to: Microsoft’s microsoft/skills README warns that loading all skills “causes context rot”.

VendorInstall the skillsWhat they add
AWSIncluded in aws-core; or npx skills add aws/agent-toolkit-for-aws/skillsCDK, CloudFormation, serverless, containers, IAM, cost management, Well-Architected review
Azurenpx skills add microsoft/azure-skills (or the azure plugin, after replacing its server entry with the pinned one)azure-prepare, azure-deploy, azure-diagnostics, azure-validate
Azure SDKsnpx skills add microsoft/skills --full-depth175 SDK skills; without --full-depth the CLI finds only 13 root-level ones
Google Cloudnpx skills add google/skills --skill gke-basics cloud-run-basics google-cloud-recipe-authGKE, Cloud Run and authentication practice
StripeIncluded in the stripe plugin; or npx skills add https://docs.stripe.comstripe-best-practices, upgrade-stripe, stripe-docs
VercelIncluded in the vercel pluginDeployments, functions, environment variables, the Vercel CLI

Pick one channel per agent; a plugin plus npx skills add for the same vendor gives duplicates. claude plugin details <plugin> prints a plugin’s always-on token cost but not its MCP tool schemas, so run /context before and after adding a server. Azure’s --namespace filter, project-scoped plugins (--scope project) and Codex’s enabled_tools and disabled_tools keys keep the cost down. See the best backend and platform skills and reducing MCP token cost.

How do you prove the agent’s cloud work is right?

Section titled “How do you prove the agent’s cloud work is right?”

You check artifacts the platforms produce, not the agent’s summary:

  • A deterministic query confirms every inventory. The Lambda list, the public storage accounts and the Cloud Run revisions each come with a CLI command you diff against the agent’s table.
  • The audit log shows what the agent called. After a read-only session, CloudTrail or the Azure activity log should contain no write events from the agent’s identity.
  • Changes arrive as reviewed code. A runtime upgrade or drift correction is an infrastructure-as-code pull request; the platform owner signs off on terraform plan or cdk diff, not on the prose.
  • Deploys are verified on the deployed URL. The Vercel loop ends with a green build log and a smoke test, attached to the pull request as part of the evidence bundle.
  • Mode is asserted, not assumed. Stripe work starts with livemode false, and stripe trigger proves the webhook path.
  • Read-only is tested once. Ask the agent to stop a harmless test resource and confirm the server refuses or the identity is denied.

What breaks with cloud MCP servers, and how do you recover?

Section titled “What breaks with cloud MCP servers, and how do you recover?”

Azure tools fail with an authentication error. Run az login, then restart the agent so the server starts with fresh credentials. In CI, set the Azure Identity environment variables for a service principal.

The agent returns Azure resources you do not recognise. It is on the wrong subscription. Run az account show, switch with az account set --subscription "NAME_OR_ID", or pass the subscription in the prompt.

Azure queries time out on a large subscription. Scope the prompt to one resource group and limit the server with --namespace.

The agent cannot change something you expected it to change. That is RBAC or --read-only doing its job. Make the change through a pull request and CI, not by widening the agent’s role.

A …@claude-plugins-official install says the marketplace is not found. Some fresh Claude Code installs have no marketplace configured. Run claude plugin marketplace add anthropics/claude-plugins-official (or /plugin marketplace update claude-plugins-official if it is listed but stale), then retry the install.

call_aws fails while documentation search works. No AWS credentials resolved. The aws-core plugin starts the proxy with --skip-auth, which lets it run unsigned when credentials are missing, so the unauthenticated tools still answer. Export AWS_MCP_PROXY_PROFILES or AWS_PROFILE, refresh the source profile’s credentials if they expired (for IAM Identity Center, aws sso login), and restart the agent.

The AWS server takes a long time to appear. The first uvx run downloads the proxy. Start it once in a terminal to warm the cache, then reconnect with /mcp.

gcloud MCP refuses a command. Its deny list blocks interactive and arbitrary-input commands on purpose. Ask for the equivalent list or describe command, or run the command yourself.

Vercel MCP shows the wrong projects. OAuth granted a different team. Log out of the server and authorize again with the right team selected.

The Stripe server acts on the wrong account. OAuth was granted to a live account, or a sk_live_ key is in the environment. Revoke it, re-authorize against the sandbox, and start every session with the livemode check. Stripe’s skill also notes that an account created with stripe sandbox create must be claimed (stripe sandbox claim) before MCP can use it.

General connection failures (servers that never start, OAuth loops, tool lists that stay empty) are covered in MCP connection issues.