MCP Server
cpum.ai for Claude, Cursor & MCP Clients
cpum.ai exposes its full investigation engine as an MCP server. Drop the config below into Claude Desktop or Cursor and your AI assistant can diagnose Linux server incidents — no copy-paste, no switching tabs.
What it is
The cpum.ai MCP server gives any MCP-compatible AI client direct access to 16 purpose-built tools: instant host classification, a full deep-investigation pipeline (perf / iostat / pidstat + OTel evidence + causal graph), OTel trace queries, incident listing, spend tracking, and five fleet-management tools (host listing, diagnostic findings, SLO burn rates, incident acknowledgement, and alert-rule auditing). The server implements the MCP 2025-06-18 Streamable HTTP transport — deep investigations stream reasoning-trace progress events over SSE as they arrive, so the AI can narrate what it's finding in real time.
All data is tenant-scoped: every evidence store (spans, logs, anomalies, incidents) filters by your API key at the database layer. A machine-readable manifest listing every tool is available at GET https://cpum.ai/api/mcp/manifest.
Quickstart
1. Get an API key
Sign in and create a key at cpum.ai/settings/api-keys. Keys start with cpum_.
2a. Claude Desktop
Add the following to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or the equivalent path on Windows/Linux:
{
"mcpServers": {
"cpum-ai": {
"url": "https://cpum.ai/api/mcp",
"headers": {
"Authorization": "Bearer cpum_YOUR_KEY_HERE"
}
}
}
}Restart Claude Desktop after saving. You should see cpum-ai listed under Settings → MCP Servers.
2b. Cursor
Create or update .cursor/mcp.json in your project root (or ~/.cursor/mcp.json for a global config):
{
"mcpServers": {
"cpum-ai": {
"url": "https://cpum.ai/api/mcp",
"headers": {
"Authorization": "Bearer cpum_YOUR_KEY_HERE"
}
}
}
}Open Cursor Settings → Features → MCP and confirm the server shows a green status dot.
3. Verify with curl
curl -X POST https://cpum.ai/api/mcp \
-H "Authorization: Bearer cpum_YOUR_KEY_HERE" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "investigate_host",
"arguments": { "cpuPercent": 87, "iowaitPercent": 12, "loadAvg": 4.2 }
}
}'A successful response returns a JSON-RPC result with a classification, confidence, hypotheses, and recommendations.
Available tools
| Tool | Description |
|---|---|
| investigate_host | Instant layer-1 classification (cpu-bound, io-bound, scheduler-pressure, …) with supporting hypotheses, log signals, recent deploys, and active anomalies. |
| investigate_host_deep | Full deep-investigation pipeline: perf/iostat/pidstat profiling + OTel evidence + causal-graph analysis. Streams reasoning trace over SSE when the client supports it. Costs $0.50/call. |
| get_recent_incidents | List your recent cpum.ai incidents. Filter by status (active | open | acknowledged | resolved | all) and look-back window (1–365 days). |
| query_traces_by_service | Search OpenTelemetry traces ingested by cpum.ai for a service. Returns recent root spans plus error and slow-span samples. |
| list_services | Discover every investigation service available on your tier, with typical runtimes. Call this first so the AI can pick the right tool. |
| check_spend_headroom | Return current usage counts, monthly and hourly limits, and window-reset timestamps — plus per-key spend caps when authenticated. |
| get_log_signals | Fetch recent system log lines and run anomaly signal detection (OOM kills, segfaults, disk-full, service restarts) over them. Configurable lookback window and line limit. |
| get_investigation | Fetch a completed investigation by ID — returns the full causal graph, hypotheses, recommendations, and reasoning trace from a prior investigate_host_deep call. |
| get_service_health | List registered services with live RED metrics (request count, error rate, p50/p95/p99) derived from ingested OTel spans over a configurable lookback window. |
| list_slos | List all SLOs with current breach status. Optionally filter by service name. Returns objective, window, SLI kind, and whether the SLO is currently breaching. |
| get_current_anomalies | Run anomaly detection against stored latest-metrics snapshots for each registered host. Returns per-host metric deviations, z-scores, and explanations. Optionally scope to a deploy environment (e.g. 'production', 'staging') or a host tag. Response includes a filtered_by key confirming applied filters. |
| list_hosts | List your registered hosts with live status (online/warning/critical/offline), last-seen timestamp, cloud metadata (provider, instance type, environment), and latest CPU/memory/disk metrics. Filter by deployEnvironment (e.g. 'production', 'staging') or hostTag to scope large fleets. Response includes a filtered_by key confirming applied filters. |
| list_findings | List recent diagnostic findings across your fleet. Returns severity, classification, confidence, host ID, and a brief detail for each finding. Filter by severity (critical | high | medium | low | info), look-back window (up to 7 days), or hostId to narrow findings to one host. Response includes a filtered_by key confirming applied filters. |
| get_slo_status | Get burn rates (1h / 6h / 24h / 3d windows), current SLI%, error budget remaining, and breach severity for one or all SLOs. Pass sloId or name to scope to a single SLO; omit both to see all at once. |
| acknowledge_incident | Acknowledge an open incident by its numeric ID, optionally attaching a note to the incident timeline. Returns the updated status and whether the incident was changed. Tenant-safe — only the incident owner can acknowledge it. |
| list_alert_rules | List your configured alert rules with metric names, threshold operators, destination types (email, webhook, Slack, PagerDuty), enabled state, and last-fired timestamp. Filter to only enabled or disabled rules. |
Full input schemas are listed in GET https://cpum.ai/api/mcp/manifest.
Authentication
Every request must include your API key in one of two headers:
Option A — Bearer token
Authorization: Bearer cpum_<key>
Option B — x-api-key header
x-api-key: cpum_<key>
Requests without a valid key receive HTTP 401 with a JSON-RPC error body. Revoked keys are rejected immediately.
Rate limits
Limits are enforced per API key and vary by plan tier. When a limit is exceeded the server returns JSON-RPC error code -32029 (the JSON-RPC analogue of HTTP 429). Use check_spend_headroom at any time to check your current usage without consuming a credit.
| Tier | Investigations / month | Deep investigation cost |
|---|---|---|
| Free | 3 | — |
| Pro | Plan limit | $0.50 / call |
| Team | Plan limit | $0.50 / call |
| Scale | Plan limit | $0.50 / call |
Spend caps are configurable per API key and are checked before each deep investigation starts. See cpum.ai/pricing for full tier details.
See what's causing your CPU
cpum.ai turns CPU, process, disk, and memory signals into plain-English explanations with evidence.
Open cpum.aiSee also: agent downloads, cpum.ai vs Datadog, changelog.