Feature

Plug an AI agent into your monitoring

Fivenines runs a remote MCP server, so Claude, Cursor or any Model Context Protocol client can read your infrastructure directly: query metrics, pull an incident with its timeline and the error patterns captured when it broke, triage vulnerabilities, check what is down. One OAuth approval, no token to paste, and 16 tools that can only read.

Built for teams monitoring production infrastructure

Start free trial

No credit card · 2-minute setup

Claude + Cursor 16 read-only tools One-click revoke

MCP tool call

scope: read

investigate_host 1 call
instance web-01
cpu_usage 94% · 15m avg
memory_usage 71% · 15m avg
recent_incidents 2 recent

no write tools exist

investigate_host
scope: read
0 writes

How It Works

1

Step 1

Point your client at it

Add https://fivenines.io/mcp as a remote MCP server. Nothing to install, nothing to self-host.

2

Step 2

Approve once

The client is sent through OAuth. You approve the connection for your organization and it is live.

3

Step 3

Ask

The agent discovers the tools itself and calls them. It never has to guess a metric name.

4

Step 4

Revoke whenever

Settings shows how many agents you have connected, and one Disconnect all button cuts all of yours off at once. Each teammate revokes their own, and removing someone from the organization stops their agents on the next call.

  • Read-only by construction

    Not one of the 16 tools creates, changes or deletes anything, so there is no write action for an agent to reach for. The OAuth connection is read-scoped on top of that, and every request re-checks the account still has read access in your organization.

  • One call, not eight

    Two tools are built for investigation rather than listing. Ask about a server and one call returns it with its recent CPU, memory and most recent incidents. Ask about an incident and one call returns its timeline, the affected instance and the captured log patterns from when it broke.

  • Included on every plan

    MCP access is not a tier, an add-on, or an admin toggle somebody has to switch on first. It is the same account you already log into, and the same per-organization rate budget the REST API uses.

What the 16 tools cover

The agent lists the tools itself on connect, so this is what it finds. Everything is scoped to your organization by the credential it connected with.

Metrics

Query any series for instances, uptime monitors or network devices. A companion catalog tool returns the metric names that exist, so the agent picks from a real list instead of guessing.

Instances

List your monitored servers or fetch one, with its current status.

Incidents

List and filter incidents, fetch one with its full timeline of events.

Availability

Uptime percentage, downtime seconds and incident counts over a window, for instances, monitors or cron tasks.

Uptime monitors

The HTTP, TCP, ping and DNS checks you run, and what each is doing.

Network devices

SNMP devices and their interfaces.

Cron tasks

Heartbeat and cron monitors, and whether each is late.

Workflows

The alerting automations configured in your organization.

Vulnerabilities

CVE counts by severity across your fleet, and the individual CVEs for one package. See the plan note below.

Deep dive

Read-only, and what that actually rests on

Pointing an AI agent at production is a trust decision, so it is worth being precise about where the ceiling comes from. It is not a setting you have to get right, and it is not a promise about how the model behaves. It holds at three independent layers:

  • There is no write tool. All 16 tools are reads. Nothing in the set creates, updates or deletes anything, so whatever credential a client connects with, there is no destructive action available to call.
  • The connection is read-scoped. Connecting through OAuth issues a read scope, and a write scope is not something these connections can request.
  • Permission is re-checked per request. The connecting account has to still hold read access in your organization. Remove someone from the team and their agent stops working on its next call, without anyone remembering to go and revoke a token.

What an agent can see is exactly what that account can see in the web app, in one organization, and never more.

Deep dive

Built for investigating, not just listing

Most of the tools are the obvious ones: list this, fetch that. Two are shaped differently, because an agent assembling a picture out of six round trips is slow and tends to stop early.

investigate_host takes one server and returns its details, its recent CPU and memory, and its most recent incidents together. That is the first question anyone asks about a box, answered in a single call.

incident_context takes one incident and returns it with its timeline, the affected instance, that instance's recent CPU and memory, and the log digests captured when it opened, including the error patterns that appeared for the first time around that moment. On a Linux host with log monitoring enabled, that means an agent starts an investigation with the lines from when things actually broke rather than a blank page.

How It Compares

How It Compares
Approach Setup Live data Write risk Revoke
Paste screenshots into a chat Manual, every time A stale snapshot None N/A
Wire an agent to the REST API You build and maintain it Yes Whatever you granted Rotate the token
Fivenines MCP server One OAuth approval No write tools exist One click

MCP access included on every plan

No add-on. Vulnerability severity counts are included too; the per-CVE detail behind them follows the same Pro plan gate as the security pages in the app.

Frequently Asked Questions

What is MCP, and which clients can connect? +
MCP (Model Context Protocol) is the open standard AI clients use to reach external tools and data. Fivenines runs a remote MCP server at https://fivenines.io/mcp, so any MCP-capable client connects to it: Claude, Claude Code, Cursor, and anything else that speaks the protocol. There is nothing to install and nothing to self-host - it is the same account you already log into, reachable over OAuth.
Can an AI agent change anything in my account? +
No, and that holds at three independent layers rather than resting on a promise. Every one of the 16 tools is a read: not one of them creates, updates or deletes anything, so there is no write action for an agent to reach for whatever credential it holds. The OAuth connection is issued with a read scope, and a write scope is not something we offer for these connections at all. And each request re-checks that the connecting account still has read permission in your organization, so revoking someone's access in Fivenines takes their agent with it.
How do I connect an agent, and how do I disconnect one? +
Point your MCP client at https://fivenines.io/mcp. It gets pointed at our OAuth flow, you approve the connection once, and the client is live - no token to copy, paste or rotate. Settings, API tokens shows how many agents you personally have connected, and a single Disconnect all button revokes all of yours at once; they stop working on their next call and have to be re-approved. Two boundaries worth stating plainly rather than leaving you to discover them: that button is scoped to your own connections, so each teammate disconnects theirs and it is not an organization-wide kill switch, and a client you connected with an API token instead of OAuth is revoked by revoking that token. What does cut every one of a person's agents off at once is removing them from the organization, because each request re-checks that they still have read access.
Is MCP access included on my plan? +
Yes, on every plan, with no admin toggle to switch on first. There is one boundary worth stating plainly: the two vulnerability tools return severity counts on every plan, but the per-CVE detail behind them - scores, fix versions, affected packages - follows the same Pro plan gate as the security pages in the web app, and the tool says so in its own response rather than quietly returning an empty list.
What can an agent actually answer with it? +
The 16 tools cover metrics (query any series, plus a catalog tool that tells the agent which metric names exist so it does not have to guess), instances, uptime monitors, network devices, cron tasks, workflows, availability, incidents and vulnerabilities. Two of them are built for investigation rather than listing: investigate_host returns one instance with its current CPU and memory and its recent incidents in a single call, and incident_context returns an incident with its timeline, the affected instance, that instance's recent metrics, and the captured log digests from when it broke. That is the difference between an agent making eight calls to assemble a picture and making one.

Give your agent something real to read

14-day trial. No credit card required.

No credit card · 2-minute setup · Cancel anytime

Read the API documentation