Back to the MCP Gateway catalog

MCP Gateway · Catalog

Pulumi MCP Server icon

Pulumi MCP server

Official

Pulumi MCP is the official Model Context Protocol server for Pulumi, with OAuth and tools that let agents inspect stacks, search resources, review policy violations, and run deployments. Connect it through the Speakeasy MCP Gateway and agents such as Claude, Cursor, and ChatGPT get one governed URL for it, with SSO, RBAC, and a full audit trail.

Infrastructure14 toolsAuth: oauth

Behind the MCP Gateway

Run Pulumi MCP behind the MCP Gateway

One URL for every agent, sign-in through your IdP, RBAC down to the tool, and every Pulumi call inspected and logged.

Deploy on MCP Gateway

Tools · 14

Each tool below can be allowed or denied per team and role at the MCP Gateway, and every call is inspected and logged.

get-stacks

Call this tool to list Pulumi stacks for the authenticated user and organization. Do not use this tool when the user wants to filter or search for specific stacks by name, type, or other criteria (e.g., "stacks with 'prod' in the name", "stacks created after 2024", "show me stacks containing 'bob'"). Use resource-search instead for these filtered queries. Use this tool only when you need to: - List ALL stacks in the organization - Get a complete inventory of stacks without any filtering - Browse all available stacks when the user wants a general overview.

resource-search

Search and analyze Pulumi-managed cloud resources. This tool should be used to find stacks when the user query has a filter, such as "with name 'Bob'". Use this tool to answer questions like: - "What cloud resources do I have?" - "Do I have any untagged S3 buckets?" - "Show me all resources in my production stack" - "What Lambda functions are running?" - "Find resources by type, name, project, or stack" - "Find stacks with name containing 'Bob'" Uses Lucene query syntax. See the 'query' parameter description for complete syntax rules and examples.

get-policy-violations

Get policy violations for Pulumi stacks. Use this tool to answer questions like: - "Do I have any policy violations?" - "What security issues are in my infrastructure?" - "Show me policy violations for my production stack" - "Are there any compliance issues in my project?" Returns open policy violations filtered by project, stack, or organization. Policy violations represent security, compliance, or best practice issues detected in your Pulumi resources.

get-users

List all users (members) in the organization. Use this when asked about users, members, admins, or team members.

neo-bridge

Launch and monitor Neo tasks step by step. Pulumi Neo is a purpose-built cloud infrastructure automation agent. If the JSON result has `has_more=true`, call this tool again to read more data. Continue calling until `has_more=false`. If you stop calling the tool, tell the user that the task continues running in Pulumi Console. When displaying messages to the user, try to return the data as-is with minimal summarization. IMPORTANT: Only set the approval parameter when the user explicitly approves/rejects in response to Neo requesting approval. Never automatically approve - wait for explicit user consent. CRITICAL: Once you receive a taskId from this tool, YOU MUST CONTINUE USING THAT SAME taskId for ALL subsequent calls until the conversation is explicitly reset. DO NOT create new tasks for follow-up questions - always use the existing taskId to send follow-up messages to the same Neo conversation. Each Neo task represents a continuous conversation thread that should be maintained throughout the user session. ENTITIES USAGE: When creating a NEW task (no taskId), if the user mentions specific infrastructure resources, you MUST provide them in the entities array: - If user mentions a GitHub repository like "github.com/owner/repo" or "analyze repository X", provide a repository entity - If user mentions a Pulumi stack like "my-stack in my-project" or "my-project/my-stack", provide a stack entity - If user mentions a policy issue ID, provide a policy_issue entity Examples: - "analyze repository github.com/pulumi/workshop" -> entities: [{type: "repository", name: "workshop", org: "pulumi", forge: "github"}] - "check the prod stack in infra-project" -> entities: [{type: "stack", name: "prod", project: "infra-project"}]

neo-reset-conversation

Reset the Neo conversation for a specific task

neo-continue-task

Continue or return to an existing Neo task. Use this to resume work on a previous task, check its status, or see what happened. You can specify a task by its ID, by position (e.g., "the second task", "the last task"), or by description (e.g., "the task about Pulumi ESC"). This command will poll the task and return any new messages. IMPORTANT: This tool is READ-ONLY for checking status and retrieving messages. To send follow-up questions or new instructions to an existing task, use neo-bridge with the taskId and query parameters instead.

neo-get-tasks

List Neo tasks for the organization. Returns task names, IDs, statuses, and links to view them in Pulumi Console.

get-type

Get the JSON schema for a specific JSON schema type reference

get-resource

Returns information about a Pulumi Registry resource

get-function

Returns information about a Pulumi Registry function

list-resources

List all resource types for a given provider and module

list-functions

List all function types for a given provider and module

deploy-to-aws

Deploy application code to AWS by generating Pulumi infrastructure. This tool automatically analyzes your application files and provisions the appropriate AWS resources (S3, Lambda, EC2, etc.) based on what it finds. No prior analysis needed - just invoke directly.

Questions

What is a Pulumi MCP server?
A Pulumi MCP server exposes Pulumi to AI agents as Model Context Protocol tools. Instead of a custom integration per agent, any MCP client can connect to the server and call tools such as get-stacks or resource-search to work with Pulumi. The server in this catalog is the official Pulumi MCP server, which authenticates with OAuth.
What can you do with Pulumi MCP?
Agents can inspect stacks, search resources, review policy violations, and run deployments. The catalog lists 14 tools for this server, including get-stacks, resource-search, and get-policy-violations. The full list with descriptions is on this page.
Why put Pulumi MCP behind an MCP gateway?
Connecting the Pulumi MCP server directly to each client means a separate credential per developer, no inventory of who can reach Pulumi through an agent, and no record of what agents did with it. An MCP gateway sits between every agent and the Pulumi server, so sign-in runs through your identity provider, role-based access decides which teams can call which Pulumi tools, and every call is inspected and logged in one place. The Speakeasy MCP Gateway applies those controls to Pulumi and to every other server in your catalog.
How do you connect Pulumi MCP through a gateway?
Add the Pulumi server from the Speakeasy MCP catalog and every agent reaches it through one gateway URL, next to the rest of your approved servers. Authentication uses OAuth 2.1 with PKCE and dynamic client registration, sign-in runs through your identity provider, and role-based access controls decide which teams can use which Pulumi tools. Every prompt, response, and tool call is inspected and logged at the gateway.
How is this different from an unofficial Pulumi MCP?
Community-built Pulumi MCP servers wrap the same Pulumi surface but are not vendor-maintained, and most authenticate with a static credential that gives an agent everything the credential owner can touch. This catalog lists the official Pulumi MCP server, which uses OAuth. Running it behind the Speakeasy MCP Gateway adds SSO, role-based access, and an audit trail of every call.

AI everywhere.

Control here.