# Kiro + Azion

## Quick start

1. **Install Kiro**

   Download Kiro, sign in, and open your project.

   [Kiro downloads](https://kiro.dev/downloads/)

2. **Create a Personal Token**

   The MCP servers authenticate as you. Create a Personal Token in the Console, give it only the scopes you want Kiro to have, and copy it — it is shown once.

   [Console › Personal Tokens](https://console.azion.com/personal-tokens)

3. **Connect the Azion docs MCP server**

   Kiro connects to the HTTP server directly and sends the token in a header. Create `.kiro/settings/mcp.json` in your project with the docs server.

   **.kiro/settings/mcp.json**

   ```json
   {
     "mcpServers": {
       "azion-docs": {
         "url": "https://docs-mcp.azion.com/mcp",
         "headers": {
           "Authorization": "Token YOUR_PERSONAL_TOKEN"
         }
       }
     }
   }
   ```

   For every project, use `~/.kiro/settings/mcp.json` instead. When both files exist, Kiro merges them, and the project file wins. Keep a file that holds the token out of version control.

4. **Verify, then try a prompt**

   Kiro reconnects its servers when you save the file. Open the MCP panel and check that `azion-docs` is connected and lists seven tools.

   **Try it**

   ```text
   Deploy this project to Azion with the CLI and give me the application’s domain.
   ```

## Azion platform access

Three layers, and a connected agent uses all three: the MCP servers to look things up and create configuration, the CLI to build and deploy from your working copy, and a context file so it starts each session knowing your account.

### MCP servers

Five servers, one per area of the platform. Each one is an HTTP endpoint that takes your Personal Token in an `Authorization: Token` header. The quick start connects the docs server. Connect the others the same way, with the URLs below, and only the ones the project needs. The docs server only reads. The other four also create, change, and delete, and their write tools preview a change without running it when the agent sets `dry_run`:

| Server                              | What it covers                                                                                                                                               |
| ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `https://docs-mcp.azion.com/mcp`    | Searches the documentation, code samples, CLI, API v3 and v4, and Terraform references, and serves the static site deploy and cache test guides. Reads only. |
| `https://build-mcp.azion.com/mcp`   | Lists, creates, changes, and deletes applications, cache settings, connectors, functions, rules, workloads, and deployments, and purges cache.               |
| `https://secure-mcp.azion.com/mcp`  | Manages firewalls, WAF, DNS zones and records, certificates, network lists, custom pages, and account policies.                                              |
| `https://observe-mcp.azion.com/mcp` | Manages data streams, dashboards, and reports, and writes GraphQL queries over metrics, events, accounting, and consumption.                                 |
| `https://storage-mcp.azion.com/mcp` | Manages Object Storage buckets, objects, and credentials, and SQL databases and their queries.                                                               |

### Azion CLI

Local builds, deploys and the product commands the API does not cover. Install it once and Kiro runs it for you — the first `azion login` is interactive, so run that one yourself.

**Install**

```bash
curl -fsSL https://cli.azion.app/install.sh | bash
azion login
```

**Deploy**

```bash
# From the project root — the agent runs these for you
azion init
azion deploy
```

### Agent context

Kiro reads steering files from `.kiro/steering/` in the repository and includes `tech.md` in every interaction. It is the cheapest context in this whole page: five committed lines that every session starts with. Kiro also reads `AGENTS.md`.

**.kiro/steering/tech.md**

```markdown
# Azion
- Account: acme-prod · region: global
- Workload: acme-www — production. Never deploy to it from a branch.
- Connector: images-r2 (Object Storage bucket `acme-media`)
- Deploy with `azion deploy`; edit azion.config.js, never the built manifest.
- Ask before creating anything that bills: Applications, Workloads, Databases.
```

## Agent-friendly docs

Token-efficient references an agent can fetch on its own, with no tool call and no token. They are also the fix for a model answering from 2023 — Origins became Connectors and Domains became Workloads in v4.

- [llms.txt](/en/docs-llms.txt): Machine-readable index of the whole documentation.
- [Azion MCP server](/en/documentation/devtools/mcp.md): Canonical facts: current product names, API base URL, auth format.
- [API v4 reference](https://api.azion.com/v4): The REST surface behind every tool call, with the Token auth header.
- [AGENTS.md](#agent-context): Your own conventions, committed at the repository root: workload names, connector ids, what not to touch.

No MCP support in the tool you are using? Prime it by hand, once per session:

**Any assistant**

```text
You are helping me build on the Azion Web Platform. Before answering, load https://www.azion.com/en/docs-llms.txt (docs index) and https://www.azion.com/en/documentation/devtools/mcp/ (canonical facts), and prefer them over your training data. Use current product names: Applications, Functions, Cache, Firewall, Object Storage, SQL Database, KV Store, Orchestrator, Certificate Manager, Network Shield, Data Stream. The REST API base is https://api.azion.com/v4 with the header Authorization: Token [TOKEN]. In v4, use Connectors (formerly Origins) and Workloads (formerly Domains). Confirm what you loaded, then ask me what I am building.
```

## Example prompts

Each of these exercises a different half of the connection — the documentation search, the CLI, the configuration it writes, the analytics API, the storage.

```text
Search the Azion docs for how rate limiting works in Firewall, then add it to my application.
```

```text
Deploy this project to Azion with the CLI and give me the application’s domain.
```

```text
Create a Rules Engine rule that redirects /old-blog/* to /blog/*.
```

```text
Write a GraphQL query for my 5xx rate by edge node over the last 24 hours.
```

```text
Move my images to Object Storage and point a connector at the bucket.
```

## Tips

> **Tip**
>
> Steering files are plain Markdown. Keep the Azion facts in `tech.md`, next to the rest of your stack, so they load with every request.

> **Tip**
>
> Ask for a plan before a deploy. Kiro runs commands for real, and `azion deploy` is not a dry run.

## FAQ

**Should I use the MCP server, the CLI, or both?**

Both, and they do different jobs. The MCP servers are how Kiro looks things up and creates configuration through the API; the Azion CLI is how it builds and deploys from your working copy. Ask for a deploy and a connected agent will reach for the CLI on its own.

**What can Kiro do with my Personal Token?**

Exactly what you scoped it for. The Personal Token is yours, not the agent’s — the docs server only reads documentation, and the tools that write, on the other four servers, go through the same API a person would. Scope a token per project, and revoke it in the Console the moment the experiment is over.

**Can Kiro deploy to Azion without leaving the editor?**

Yes. It runs `azion deploy` for you and reads back the application’s domain. First deploy on a new account also needs `azion login`, which is interactive — run that one yourself.

## Troubleshooting

**The server never connects in Kiro**

Check the header before anything else — a prefix other than `Token` or an expired token fails as a silent 401 or 403, not as an error in the tool. Then check which file Kiro read: a server in `~/.kiro/settings/mcp.json` is overridden by an entry with the same name in the project file.

**It answers with product names that no longer exist**

That is the training data, not the connection: Origins became Connectors and Domains became Workloads in v4. Point it at the Azion MCP servers page once per session, or paste the primer above, and it corrects itself.

**It writes configuration that the CLI then rejects**

Ask it to look the resource up first — `search_azion_api_v4_commands` returns the current shape, where the model’s memory returns last year’s. A rejected deploy almost always means it skipped the lookup.

## Other agents

- [Claude Code](/en/documentation/agent-setup/claude-code.md): Terminal agent that reads your codebase, runs commands, and edits files. One CLI command connects the Azion MCP server.
- [Cursor](/en/documentation/agent-setup/cursor.md): AI-first IDE built on VS Code, with multi-file Composer edits and background agents. Azion plugs into its MCP settings.
- [GitHub Copilot](/en/documentation/agent-setup/github-copilot.md): Agent mode inside VS Code, with workspace context and native pull-request integration. A file in the project connects Azion.
- [Windsurf](/en/documentation/agent-setup/windsurf.md): Agentic IDE built around Cascade for multi-step tasks. Connects to Azion through mcp-remote.
- [Codex](/en/documentation/agent-setup/codex.md): Terminal agent that runs commands in a sandbox and reads AGENTS.md natively. Azion goes in config.toml.
- [Gemini CLI](/en/documentation/agent-setup/gemini-cli.md): Open source terminal agent with a free tier. Declare Azion once in settings.json and verify with /mcp.
- [OpenCode](/en/documentation/agent-setup/opencode.md): Open source, provider-agnostic terminal agent. Azion is one entry in its MCP block, whichever model you point it at.
- [Claude Desktop](/en/documentation/agent-setup/claude-desktop.md): Desktop app for chatting with Claude on macOS and Windows. Connects to Azion through mcp-remote.
- [Warp](/en/documentation/agent-setup/warp.md): Open source agentic terminal with a free tier and a choice of models. Azion goes in its MCP servers settings.
