# Tools and resources

The [Azion MCP servers](/en/documentation/devtools/mcp/) expose tools, and the docs server also exposes resources, to a coding agent that connects with an Azion [personal token](/en/documentation/fundamentals/personal-tokens/). Each server covers one area of the platform. The docs server only reads. The build, secure, observe, and storage servers also create, change, and delete resources in your account.

| Server  | URL                                 | What it covers                                                                                                          |
| ------- | ----------------------------------- | ----------------------------------------------------------------------------------------------------------------------- |
| docs    | `https://docs-mcp.azion.com/mcp`    | Search of the documentation, code samples, CLI, API, and Terraform references; static site deploy and cache test guides |
| build   | `https://build-mcp.azion.com/mcp`   | Applications, cache settings, connectors, functions, rules, workloads, deployments, and cache purge                     |
| secure  | `https://secure-mcp.azion.com/mcp`  | Firewalls, WAF, DNS, certificates, network lists, custom pages, account policies, and authentication                    |
| observe | `https://observe-mcp.azion.com/mcp` | Data streams, dashboards, reports, data sources, GraphQL queries, and invoices                                          |
| storage | `https://storage-mcp.azion.com/mcp` | Object Storage buckets, objects, and credentials; SQL databases and queries                                             |

---

## Inputs the servers share

Most tools of the build, secure, observe, and storage servers follow the same patterns for reading and writing:

- **`fields`**: most list tools, and the get tools of the build and secure servers, return only the comma-separated fields you name. Dot notation reaches nested fields.
- **`cursor` and `page_size`**: most list tools return one page and a `next_cursor`. Pass `next_cursor` as `cursor` to read the next page. `page_size` defaults to `50`, with a maximum of `100`. Two storage tools page differently: `list_storage_credentials` takes `page` and `page_size`, and `list_storage_objects` takes `continuation_token`, `max_object_count` (up to `1000`), and `prefix`.
- **`dry_run`**: a tool that creates, changes, or deletes returns a preview of the request it would send, without sending it.
- **`idempotency_key`**: a tool that creates, changes, or deletes accepts a key that you supply. The server never generates one.

Set `dry_run` before every write you have not reviewed. The personal token decides what a write tool can change, so scope the token to the resources the agent needs.

---

## Docs server tools

The docs server exposes seven tools. Each search tool returns one `text` item whose value is a JSON object with a `results` array of documents, and every document carries `title`, `content`, `source`, `similarity`, `search_type`, and `relevance_score`.

| Tool                           | Returns                                                                                                                                                                                            | Inputs                                                                   |
| ------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------ |
| `search_azion_docs_and_site`   | Documents from the Azion documentation and website, for a question such as how to configure DDoS protection                                                                                        | `query` (string, required); `docsAmount` (number, optional, default `5`) |
| `search_azion_code_samples`    | Code libraries and code samples, for a request such as Next.js deployment examples                                                                                                                 | `query` (string, required); `docsAmount` (number, optional, default `5`) |
| `search_azion_cli_commands`    | Documents on the [Azion CLI](/en/documentation/devtools/cli/) commands and their usage, for a question such as which commands manage functions                                                     | `query` (string, required); `docsAmount` (number, optional, default `5`) |
| `search_azion_api_v4_commands` | Documents from the [Azion API](/en/documentation/devtools/api/) v4 reference, such as the OpenAPI fragment of an operation                                                                         | `query` (string, required); `docsAmount` (number, optional, default `5`) |
| `search_azion_api_v3_commands` | Documents from the Azion API v3 reference, the previous version of the API, which is set to be deprecated                                                                                          | `query` (string, required); `docsAmount` (number, optional, default `5`) |
| `search_azion_terraform`       | Documents from the [Azion Terraform Provider](/en/documentation/devtools/terraform/) documentation, for a question such as how to create a Terraform resource                                      | `query` (string, required); `docsAmount` (number, optional, default `5`) |
| `deploy_azion_static_site`     | Guide text for deploying a static site and testing its cache; `help` lists the seven resources, `deploy` returns the four deployment steps, and `test-cache` returns the three cache-testing steps | `action` (string, optional): `deploy`, `test-cache`, or `help`           |

`docsAmount` sets how many documents a search tool returns. Send it only when you want a number other than five.

---

## Static site resources

A client that supports MCP resources lists seven guides from the docs server, under `azion://guides/deploy/` and `azion://guides/test-cache/`, and reads each one with `resources/read`. Every resource is `text/markdown`, and its name is its URI path joined with hyphens, as in `guides-deploy-step-0-preparation`. The other four servers list no resources.

| URI                                            | Content                                                                                                                             |
| ---------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| `azion://guides/deploy/step-0-preparation`     | Instructions to analyze the project structure, detect the framework and the package manager, and gather the deployment requirements |
| `azion://guides/deploy/step-1-configuration`   | Instructions to install the Azion CLI, authenticate, link the project, and test the build configuration                             |
| `azion://guides/deploy/step-2-execute`         | Instructions to deploy the project and verify the deployment status                                                                 |
| `azion://guides/deploy/step-3-basic-test`      | Instructions to run basic tests of the deployment and its cache behavior                                                            |
| `azion://guides/test-cache/step-0-preparation` | Instructions to analyze the cache configuration of the deployed site and prepare test scenarios                                     |
| `azion://guides/test-cache/step-1-execution`   | Instructions to run cache tests for every static asset type and check the hit-miss ratios                                           |
| `azion://guides/test-cache/step-2-validation`  | Instructions to validate the test results, calculate the rate of cache hits, and write a test report                                |

A client without resource support reaches the same guides through `deploy_azion_static_site`, with `action` set to `deploy` or `test-cache`.

---

## Build server tools

The build server manages the resources that serve a request. Most resources have six tools, to list, read, create, replace, change, and delete them. An update tool, such as `update_application`, replaces the resource. A patch tool, such as `patch_application`, changes only the fields you send.

| Resource                                                 | Tools                                                                                                                                                                             |
| -------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| [Applications](/en/documentation/platform/applications/) | `list_applications`, `get_application`, `create_application`, `update_application`, `patch_application`, `delete_application`, and `clone_application`                            |
| Cache settings                                           | `list_cache_settings`, `get_cache_setting`, `create_cache_setting`, `update_cache_setting`, `patch_cache_setting`, and `delete_cache_setting`                                     |
| [Connectors](/en/documentation/platform/connectors/)     | `list_connectors`, `get_connector`, `create_connector`, `update_connector`, `patch_connector`, and `delete_connector`                                                             |
| [Functions](/en/documentation/platform/functions/)       | `list_functions`, `get_function`, `create_function`, `update_function`, `patch_function`, and `delete_function`                                                                   |
| Function instances                                       | `list_function_instances`, `get_function_instance`, `create_function_instance`, `update_function_instance`, `patch_function_instance`, and `delete_function_instance`             |
| Request rules                                            | `list_request_rules`, `get_request_rule`, `create_request_rule`, `update_request_rule`, `patch_request_rule`, `delete_request_rule`, and `reorder_request_rules`                  |
| Response rules                                           | `list_response_rules`, `get_response_rule`, `create_response_rule`, `update_response_rule`, `patch_response_rule`, `delete_response_rule`, and `reorder_response_rules`           |
| Workloads                                                | `list_workloads`, `get_workload`, `create_workload`, `update_workload`, `patch_workload`, and `delete_workload`                                                                   |
| Workload deployments                                     | `list_workload_deployments`, `get_workload_deployment`, `create_workload_deployment`, `update_workload_deployment`, `patch_workload_deployment`, and `delete_workload_deployment` |
| Cache purge                                              | `purge_url`, `purge_cachekey`, and `purge_wildcard`                                                                                                                               |

A purge tool takes `items`, the URLs, cache keys, or wildcards to purge, and `layer`: `cache`, the default, or `tiered_cache`. For how to build a rule with `create_request_rule`, refer to [Create Rules Engine rules with the MCP server](/en/documentation/guides/application-development/getting-started/generate-rules-engine-rules-with-mcp/).

---

## Secure server tools

The secure server manages the resources that protect a request and an account. As on the build server, an update tool replaces the resource, and a patch tool changes only the fields you send.

| Resource                     | Tools                                                                                                                                                                                                                             |
| ---------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Firewalls                    | `list_firewalls`, `get_firewall`, `create_firewall`, `update_firewall`, `patch_firewall`, `delete_firewall`, and `clone_firewall`                                                                                                 |
| Firewall rules               | `list_firewall_rules`, `get_firewall_rule`, `create_firewall_rule`, `update_firewall_rule`, `patch_firewall_rule`, `delete_firewall_rule`, and `reorder_firewall_rules`                                                           |
| Firewall function instances  | `list_firewall_function_instances`, `get_firewall_function_instance`, `create_firewall_function_instance`, `update_firewall_function_instance`, `patch_firewall_function_instance`, and `delete_firewall_function_instance`       |
| WAF                          | `list_wafs`, `get_waf`, `create_waf`, `update_waf`, `patch_waf`, `delete_waf`, and `clone_waf`                                                                                                                                    |
| WAF exceptions               | `list_waf_exceptions`, `get_waf_exception`, `create_waf_exception`, `update_waf_exception`, `patch_waf_exception`, and `delete_waf_exception`                                                                                     |
| DNS zones                    | `list_dns_zones`, `get_dns_zone`, `create_dns_zone`, `update_dns_zone`, `patch_dns_zone`, and `delete_dns_zone`                                                                                                                   |
| DNS records                  | `list_dns_records`, `get_dns_record`, `create_dns_record`, `update_dns_record`, `patch_dns_record`, and `delete_dns_record`                                                                                                       |
| DNSSEC                       | `get_dnssec`, `update_dnssec`, and `patch_dnssec`                                                                                                                                                                                 |
| Certificates                 | `list_certificates`, `get_certificate`, `create_certificate`, `update_certificate`, `patch_certificate`, `delete_certificate`, `request_certificate`, and `create_certificate_signing_request`                                    |
| Certificate revocation lists | `list_certificate_revocation_lists`, `get_certificate_revocation_list`, `create_certificate_revocation_list`, `update_certificate_revocation_list`, `patch_certificate_revocation_list`, and `delete_certificate_revocation_list` |
| Network lists                | `list_network_lists`, `get_network_list`, `create_network_list`, `update_network_list`, `patch_network_list`, and `delete_network_list`                                                                                           |
| Custom pages                 | `list_custom_pages`, `get_custom_page`, `create_custom_page`, `update_custom_page`, `patch_custom_page`, and `delete_custom_page`                                                                                                 |
| Policies                     | `list_policies`, `get_policy`, `create_policy`, `update_policy`, `patch_policy`, and `delete_policy`                                                                                                                              |
| Lockout policy               | `get_lockout_policy` and `update_lockout_policy`                                                                                                                                                                                  |
| Session timeout policy       | `get_session_timeout_policy` and `update_session_timeout_policy`                                                                                                                                                                  |
| TOTP devices                 | `list_totp_devices`, `create_totp_device`, `delete_totp_device`, and `verify_totp`                                                                                                                                                |
| Authentication               | `auth_login`, `check_login_method`, `refresh_access_token`, and `revoke_refresh_token`                                                                                                                                            |

`auth_login` takes an email address and a password and issues JWT tokens. The other tools authenticate with the personal token in the `Authorization` header, so an agent never needs your password to manage the account.

---

## Observe server tools

The observe server manages the resources that collect and report data about your account, and it writes GraphQL queries.

| Resource              | Tools                                                                                                                                                                                   |
| --------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Data streams          | `list_data_streams`, `get_data_stream`, `create_data_stream`, `update_data_stream`, `patch_data_stream`, and `delete_data_stream`                                                       |
| Data stream templates | `list_data_stream_templates`, `get_data_stream_template`, `create_data_stream_template`, `update_data_stream_template`, `patch_data_stream_template`, and `delete_data_stream_template` |
| Data sources          | `list_data_sources`                                                                                                                                                                     |
| Dashboards            | `list_dashboards` and `create_dashboard`                                                                                                                                                |
| Folders               | `list_folders` and `create_folder`                                                                                                                                                      |
| Rows                  | `list_rows`, `get_row`, `create_row`, `update_row`, and `delete_row`                                                                                                                    |
| Reports               | `list_reports`, `get_report`, `create_report`, `update_report`, `delete_report`, and `update_report_order`                                                                              |
| Library reports       | `list_library_reports`, `create_library_report`, and `delete_library_report`                                                                                                            |
| Recommendations       | `list_recommendations`, `create_recommendation`, and `delete_recommendation`                                                                                                            |
| Invoices              | `retrieve_invoice`                                                                                                                                                                      |
| GraphQL queries       | `create_graphql_query`                                                                                                                                                                  |

`create_graphql_query` takes two inputs: `query` (string, required), the goal in plain words, and `dataSource` (string, required): `real-time-metrics`, `real-time-events`, `accounting`, or `consumption`. A language model writes a query for the [GraphQL API](/en/documentation/devtools/graphql/), and the tool runs it against the selected endpoint with your token, correcting it through GraphQL introspection for up to six attempts. When no attempt returns a valid query, the text says so and points to the GraphQL API documentation.

---

## Storage server tools

The storage server manages [Object Storage](/en/documentation/platform/object-storage/) and [SQL Database](/en/documentation/platform/sql-database/).

| Resource      | Tools                                                                                                                            |
| ------------- | -------------------------------------------------------------------------------------------------------------------------------- |
| Buckets       | `list_storage_buckets`, `get_storage_bucket`, `create_storage_bucket`, `update_storage_bucket`, and `delete_storage_bucket`      |
| Objects       | `list_storage_objects`, `create_storage_object`, `update_storage_object`, `delete_storage_object`, and `download_storage_object` |
| Credentials   | `list_storage_credentials`, `get_storage_credential`, `create_storage_credential`, and `delete_storage_credential`               |
| SQL databases | `list_sql_databases`, `get_sql_database`, `create_sql_database`, and `delete_sql_database`                                       |
| SQL queries   | `execute_sql_query`                                                                                                              |

`execute_sql_query` takes the database `id` and `statements`, an array of up to 1,000 SQL statements, and returns the `columns` and `rows` of the result. `delete_storage_object` deletes the object permanently after a 24-hour grace period.

---

## Search tool call

The request below calls `search_azion_docs_and_site` with a query and two documents. It is a `POST` to `https://docs-mcp.azion.com/mcp` with the headers `Authorization: Token [TOKEN VALUE]`, `Content-Type: application/json`, and `Accept: application/json, text/event-stream`, and this body:

```json
{
  "jsonrpc": "2.0",
  "method": "tools/call",
  "id": 1,
  "params": {
    "name": "search_azion_docs_and_site",
    "arguments": {
      "query": "how to configure cache",
      "docsAmount": 2
    }
  }
}
```

The result holds one `text` item. Its value is a JSON object whose `results` array holds the two documents that `docsAmount` asks for. Below, the second document is left out, and the `content` and `source` of the first are cut at `…`:

```json
{
  "results": [
    {
      "title": "application-acceleration",
      "content": "Title: application-acceleration\nDescription: Application Accelerator speeds up web applications and APIs through protocol optimizations and manages dynamic content requirements.…",
      "source": "https://www.azion.com/en/documentation/…",
      "similarity": 1,
      "search_type": "fts",
      "relevance_score": 0.72607421875
    }
  ]
}
```

---

## Related resources

- [How the MCP server works](/en/documentation/devtools/mcp/how-it-works.md): How the servers authenticate a call, which transport they use, and what a tool does with the request.
- [MCP server quickstart](/en/documentation/devtools/mcp/quickstart.md): How to connect a coding agent to a server with a personal token.
- [Test cache behavior with the MCP server](/en/documentation/guides/application-performance/cache-and-purge/test-cache-with-mcp.md): How to check the cache of a deployed site with the debug headers Azion returns.
- [Troubleshoot the MCP server](/en/documentation/devtools/mcp/troubleshooting.md): What to do when a tool is missing or a call is refused.
