Tools and resources
Look up the tools and resources each Azion MCP server exposes, the inputs each tool takes, and what each tool returns.
The Azion MCP servers expose tools, and the docs server also exposes resources, to a coding agent that connects with an Azion personal token. Each server covers one area of the platform. The docs server only reads. The build, secure, observe, and storage servers also create, change, and delete resources in your account.
| Server | URL | What it covers |
|---|---|---|
| docs | https://docs-mcp.azion.com/mcp | Search of the documentation, code samples, CLI, API, and Terraform references; static site deploy and cache test guides |
| build | https://build-mcp.azion.com/mcp | Applications, cache settings, connectors, functions, rules, workloads, deployments, and cache purge |
| secure | https://secure-mcp.azion.com/mcp | Firewalls, WAF, DNS, certificates, network lists, custom pages, account policies, and authentication |
| observe | https://observe-mcp.azion.com/mcp | Data streams, dashboards, reports, data sources, GraphQL queries, and invoices |
| storage | https://storage-mcp.azion.com/mcp | Object Storage buckets, objects, and credentials; SQL databases and queries |
Inputs the servers share
Most tools of the build, secure, observe, and storage servers follow the same patterns for reading and writing:
fields: most list tools, and the get tools of the build and secure servers, return only the comma-separated fields you name. Dot notation reaches nested fields.cursorandpage_size: most list tools return one page and anext_cursor. Passnext_cursorascursorto read the next page.page_sizedefaults to50, with a maximum of100. Two storage tools page differently:list_storage_credentialstakespageandpage_size, andlist_storage_objectstakescontinuation_token,max_object_count(up to1000), andprefix.dry_run: a tool that creates, changes, or deletes returns a preview of the request it would send, without sending it.idempotency_key: a tool that creates, changes, or deletes accepts a key that you supply. The server never generates one.
Set dry_run before every write you have not reviewed. The personal token decides what a write tool can change, so scope the token to the resources the agent needs.
Docs server tools
The docs server exposes seven tools. Each search tool returns one text item whose value is a JSON object with a results array of documents, and every document carries title, content, source, similarity, search_type, and relevance_score.
| Tool | Returns | Inputs |
|---|---|---|
search_azion_docs_and_site | Documents from the Azion documentation and website, for a question such as how to configure DDoS protection | query (string, required); docsAmount (number, optional, default 5) |
search_azion_code_samples | Code libraries and code samples, for a request such as Next.js deployment examples | query (string, required); docsAmount (number, optional, default 5) |
search_azion_cli_commands | Documents on the Azion CLI commands and their usage, for a question such as which commands manage functions | query (string, required); docsAmount (number, optional, default 5) |
search_azion_api_v4_commands | Documents from the Azion API v4 reference, such as the OpenAPI fragment of an operation | query (string, required); docsAmount (number, optional, default 5) |
search_azion_api_v3_commands | Documents from the Azion API v3 reference, the previous version of the API, which is set to be deprecated | query (string, required); docsAmount (number, optional, default 5) |
search_azion_terraform | Documents from the Azion Terraform Provider documentation, for a question such as how to create a Terraform resource | query (string, required); docsAmount (number, optional, default 5) |
deploy_azion_static_site | Guide text for deploying a static site and testing its cache; help lists the seven resources, deploy returns the four deployment steps, and test-cache returns the three cache-testing steps | action (string, optional): deploy, test-cache, or help |
docsAmount sets how many documents a search tool returns. Send it only when you want a number other than five.
Static site resources
A client that supports MCP resources lists seven guides from the docs server, under azion://guides/deploy/ and azion://guides/test-cache/, and reads each one with resources/read. Every resource is text/markdown, and its name is its URI path joined with hyphens, as in guides-deploy-step-0-preparation. The other four servers list no resources.
| URI | Content |
|---|---|
azion://guides/deploy/step-0-preparation | Instructions to analyze the project structure, detect the framework and the package manager, and gather the deployment requirements |
azion://guides/deploy/step-1-configuration | Instructions to install the Azion CLI, authenticate, link the project, and test the build configuration |
azion://guides/deploy/step-2-execute | Instructions to deploy the project and verify the deployment status |
azion://guides/deploy/step-3-basic-test | Instructions to run basic tests of the deployment and its cache behavior |
azion://guides/test-cache/step-0-preparation | Instructions to analyze the cache configuration of the deployed site and prepare test scenarios |
azion://guides/test-cache/step-1-execution | Instructions to run cache tests for every static asset type and check the hit-miss ratios |
azion://guides/test-cache/step-2-validation | Instructions to validate the test results, calculate the rate of cache hits, and write a test report |
A client without resource support reaches the same guides through deploy_azion_static_site, with action set to deploy or test-cache.
Build server tools
The build server manages the resources that serve a request. Most resources have six tools, to list, read, create, replace, change, and delete them. An update tool, such as update_application, replaces the resource. A patch tool, such as patch_application, changes only the fields you send.
| Resource | Tools |
|---|---|
| Applications | list_applications, get_application, create_application, update_application, patch_application, delete_application, and clone_application |
| Cache settings | list_cache_settings, get_cache_setting, create_cache_setting, update_cache_setting, patch_cache_setting, and delete_cache_setting |
| Connectors | list_connectors, get_connector, create_connector, update_connector, patch_connector, and delete_connector |
| Functions | list_functions, get_function, create_function, update_function, patch_function, and delete_function |
| Function instances | list_function_instances, get_function_instance, create_function_instance, update_function_instance, patch_function_instance, and delete_function_instance |
| Request rules | list_request_rules, get_request_rule, create_request_rule, update_request_rule, patch_request_rule, delete_request_rule, and reorder_request_rules |
| Response rules | list_response_rules, get_response_rule, create_response_rule, update_response_rule, patch_response_rule, delete_response_rule, and reorder_response_rules |
| Workloads | list_workloads, get_workload, create_workload, update_workload, patch_workload, and delete_workload |
| Workload deployments | list_workload_deployments, get_workload_deployment, create_workload_deployment, update_workload_deployment, patch_workload_deployment, and delete_workload_deployment |
| Cache purge | purge_url, purge_cachekey, and purge_wildcard |
A purge tool takes items, the URLs, cache keys, or wildcards to purge, and layer: cache, the default, or tiered_cache. For how to build a rule with create_request_rule, refer to Create Rules Engine rules with the MCP server.
Secure server tools
The secure server manages the resources that protect a request and an account. As on the build server, an update tool replaces the resource, and a patch tool changes only the fields you send.
| Resource | Tools |
|---|---|
| Firewalls | list_firewalls, get_firewall, create_firewall, update_firewall, patch_firewall, delete_firewall, and clone_firewall |
| Firewall rules | list_firewall_rules, get_firewall_rule, create_firewall_rule, update_firewall_rule, patch_firewall_rule, delete_firewall_rule, and reorder_firewall_rules |
| Firewall function instances | list_firewall_function_instances, get_firewall_function_instance, create_firewall_function_instance, update_firewall_function_instance, patch_firewall_function_instance, and delete_firewall_function_instance |
| WAF | list_wafs, get_waf, create_waf, update_waf, patch_waf, delete_waf, and clone_waf |
| WAF exceptions | list_waf_exceptions, get_waf_exception, create_waf_exception, update_waf_exception, patch_waf_exception, and delete_waf_exception |
| DNS zones | list_dns_zones, get_dns_zone, create_dns_zone, update_dns_zone, patch_dns_zone, and delete_dns_zone |
| DNS records | list_dns_records, get_dns_record, create_dns_record, update_dns_record, patch_dns_record, and delete_dns_record |
| DNSSEC | get_dnssec, update_dnssec, and patch_dnssec |
| Certificates | list_certificates, get_certificate, create_certificate, update_certificate, patch_certificate, delete_certificate, request_certificate, and create_certificate_signing_request |
| Certificate revocation lists | list_certificate_revocation_lists, get_certificate_revocation_list, create_certificate_revocation_list, update_certificate_revocation_list, patch_certificate_revocation_list, and delete_certificate_revocation_list |
| Network lists | list_network_lists, get_network_list, create_network_list, update_network_list, patch_network_list, and delete_network_list |
| Custom pages | list_custom_pages, get_custom_page, create_custom_page, update_custom_page, patch_custom_page, and delete_custom_page |
| Policies | list_policies, get_policy, create_policy, update_policy, patch_policy, and delete_policy |
| Lockout policy | get_lockout_policy and update_lockout_policy |
| Session timeout policy | get_session_timeout_policy and update_session_timeout_policy |
| TOTP devices | list_totp_devices, create_totp_device, delete_totp_device, and verify_totp |
| Authentication | auth_login, check_login_method, refresh_access_token, and revoke_refresh_token |
auth_login takes an email address and a password and issues JWT tokens. The other tools authenticate with the personal token in the Authorization header, so an agent never needs your password to manage the account.
Observe server tools
The observe server manages the resources that collect and report data about your account, and it writes GraphQL queries.
| Resource | Tools |
|---|---|
| Data streams | list_data_streams, get_data_stream, create_data_stream, update_data_stream, patch_data_stream, and delete_data_stream |
| Data stream templates | list_data_stream_templates, get_data_stream_template, create_data_stream_template, update_data_stream_template, patch_data_stream_template, and delete_data_stream_template |
| Data sources | list_data_sources |
| Dashboards | list_dashboards and create_dashboard |
| Folders | list_folders and create_folder |
| Rows | list_rows, get_row, create_row, update_row, and delete_row |
| Reports | list_reports, get_report, create_report, update_report, delete_report, and update_report_order |
| Library reports | list_library_reports, create_library_report, and delete_library_report |
| Recommendations | list_recommendations, create_recommendation, and delete_recommendation |
| Invoices | retrieve_invoice |
| GraphQL queries | create_graphql_query |
create_graphql_query takes two inputs: query (string, required), the goal in plain words, and dataSource (string, required): real-time-metrics, real-time-events, accounting, or consumption. A language model writes a query for the GraphQL API, and the tool runs it against the selected endpoint with your token, correcting it through GraphQL introspection for up to six attempts. When no attempt returns a valid query, the text says so and points to the GraphQL API documentation.
Storage server tools
The storage server manages Object Storage and SQL Database.
| Resource | Tools |
|---|---|
| Buckets | list_storage_buckets, get_storage_bucket, create_storage_bucket, update_storage_bucket, and delete_storage_bucket |
| Objects | list_storage_objects, create_storage_object, update_storage_object, delete_storage_object, and download_storage_object |
| Credentials | list_storage_credentials, get_storage_credential, create_storage_credential, and delete_storage_credential |
| SQL databases | list_sql_databases, get_sql_database, create_sql_database, and delete_sql_database |
| SQL queries | execute_sql_query |
execute_sql_query takes the database id and statements, an array of up to 1,000 SQL statements, and returns the columns and rows of the result. delete_storage_object deletes the object permanently after a 24-hour grace period.
Search tool call
The request below calls search_azion_docs_and_site with a query and two documents. It is a POST to https://docs-mcp.azion.com/mcp with the headers Authorization: Token [TOKEN VALUE], Content-Type: application/json, and Accept: application/json, text/event-stream, and this body:
The result holds one text item. Its value is a JSON object whose results array holds the two documents that docsAmount asks for. Below, the second document is left out, and the content and source of the first are cut at …: