Connect an MCP client
Infrared ships an MCP server, so agents can read Infrared through the same API a person uses. The UI serves it at /mcp over streamable HTTP, next to the UI itself.
The access token
Every request to /mcp must send Authorization: Bearer <token>. Without it, or with the wrong token, the server answers 401. From chart 0.1.0-alpha.6 on, the chart generates the token once into the Secret infrared-mcp-access, key token, in the release namespace, and keeps it across upgrades.
kubectl -n infrared get secret infrared-mcp-access -o jsonpath='{.data.token}' | base64 -d; echo
To choose the token yourself, pass --set mcp.access.token=<token> at install time, or point mcp.access.existingSecret at a Secret you created with a token key.
This token only admits a client to the MCP server. The MCP server then calls the API with its own token (infrared-mcp-token), which you never hand out.
Claude Code
claude mcp add --transport http infrared https://<your Infrared host>/mcp \
--header "Authorization: Bearer $(kubectl -n infrared get secret infrared-mcp-access -o jsonpath='{.data.token}' | base64 -d)"
Through a port-forward, use http://localhost:8080/mcp instead.
Tools
| Tool | What it returns |
|---|---|
infrared_status | The installation phase, version, platform org and management cluster |
list_clusters | Clusters Infrared manages |
list_products | Products in an org |
list_agentroles | AgentRoles in an org, with whether each is enabled |
Rotating the token
Replace the token key in infrared-mcp-access, restart the MCP server (kubectl -n infrared rollout restart deploy/infrared-mcp), and update your clients.
Upgrading an install adopted before alpha.6
An install that Argo CD adopted before chart 0.1.0-alpha.6 has no infrared-mcp-access Secret, and Argo CD can't create a stable one, because it renders the chart without lookup. Create the Secret once:
kubectl -n infrared create secret generic infrared-mcp-access \
--from-literal=token="$(LC_ALL=C tr -dc 'A-Za-z0-9' </dev/urandom | head -c 48)"
Then open the pin PR to 0.1.0-alpha.6. Along with targetRevision, it adds this under the infrared Application's valuesObject:
mcp:
existingSecret: infrared-mcp-token
access:
existingSecret: infrared-mcp-access
Gitops template v0.1.7 and later render this value, so a later template upgrade keeps it.