[ agent capabilities ]

The MCP tool directory.

Each row is one tool from one provider. Tools sharing a name across providers (e.g. search) are listed separately because they aren't interchangeable.

[ 3624 tools indexed ]

[ all tools ]

30 / 3624

Keycloak /

skycloak_create_export

[  remote  ]

Start a database export for a cluster. Asynchronous: poll skycloak_get_export until the status is 'completed' to obtain the download URL. Including credentials requires an encryption_password.

Keycloak /

skycloak_create_identity_provider

[  remote  ]

Create an OIDC identity provider (SSO connection) in a realm.

Keycloak /

skycloak_create_realm

[  remote  ]

Create a new Keycloak realm in a cluster. Requires the server to be started with --allow-writes and a write-scoped API key.

Keycloak /

skycloak_create_realm_export

[  remote  ]

Export a Keycloak realm to an encrypted archive. Asynchronous: poll skycloak_get_realm_export until status is 'completed'. The archive is always encrypted, so encryption_password is required, and the same password is needed to import it again. This is a realm export (one realm's configuration); skycloak_create_export is the separate whole-cluster database export.

Keycloak /

skycloak_create_realm_group

[  remote  ]

Create a realm group, optionally nested under a parent group.

Keycloak /

skycloak_create_realm_import

[  remote  ]

Import a Keycloak realm into a cluster from an uploaded archive or an existing realm export. Asynchronous: poll skycloak_get_realm_import. Creates a new realm: preflight refuses a name collision rather than overwriting, so an existing realm of the same name fails with 409. It does import users and their credentials, so set confirm=true to proceed.

Keycloak /

skycloak_create_realm_import_upload_url

[  remote  ]

Get a presigned URL to upload a realm archive to. PUT the archive to upload_url, then pass the returned s3_key to skycloak_create_realm_import as upload_s3_key. Not needed when importing an existing export: pass that export's ID as source_export_id instead.

Keycloak /

skycloak_create_realm_role

[  remote  ]

Create a realm-scoped role.

Keycloak /

skycloak_create_realm_user

[  remote  ]

Create a realm user with an initial temporary password.

Keycloak /

skycloak_create_siem_destination

[  remote  ]

Create a SIEM destination. Credentials are write-only and are not returned.

Keycloak /

skycloak_create_webhook_subscription

[  remote  ]

Create a webhook subscription. Signing secrets and authorization headers are write-only.

Keycloak /

skycloak_delete_application

[  remote  ]

Delete an application (OIDC/SAML client) from a realm. Set confirm=true to proceed.

Keycloak /

skycloak_delete_cluster

[  remote  ]

Permanently delete a Keycloak cluster and all of its realms and data. Irreversible. Set confirm=true to proceed.

Keycloak /

skycloak_delete_cluster_maintenance_window

[  remote  ]

Delete a cluster-specific maintenance window so the cluster follows the workspace default. Set confirm=true to proceed.

Keycloak /

skycloak_delete_domain

[  remote  ]

Remove a custom domain from a cluster. Set confirm=true to proceed.

Keycloak /

skycloak_delete_domain_route

[  remote  ]

Remove a realm route from a custom domain. Set confirm=true to proceed.

Keycloak /

skycloak_delete_email_branding

[  remote  ]

Revert email branding to defaults. Set confirm=true to proceed.

Keycloak /

skycloak_delete_export

[  remote  ]

Delete a database export archive. Set confirm=true to proceed.

Keycloak /

skycloak_delete_extension

[  remote  ]

Delete a custom extension from the workspace catalog. Set confirm=true to proceed.

Keycloak /

skycloak_delete_identity_provider

[  remote  ]

Delete an identity provider from a realm. Set confirm=true to proceed.

Keycloak /

skycloak_delete_login_branding

[  remote  ]

Revert login branding to defaults. Set confirm=true to proceed.

Keycloak /

skycloak_delete_realm

[  remote  ]

Permanently delete a realm and all of its users, clients and configuration. This is irreversible. Set confirm=true to proceed.

Keycloak /

skycloak_delete_realm_group

[  remote  ]

Delete a realm group. Set confirm=true to proceed.

Keycloak /

skycloak_delete_realm_role

[  remote  ]

Delete a realm role. Set confirm=true to proceed.

Keycloak /

skycloak_delete_realm_user

[  remote  ]

Delete a realm user. Set confirm=true to proceed.

Keycloak /

skycloak_delete_siem_destination

[  remote  ]

Delete a SIEM destination. Set confirm=true to proceed.

Keycloak /

skycloak_delete_smtp

[  remote  ]

Remove a realm's SMTP configuration. Set confirm=true to proceed.

Keycloak /

skycloak_delete_theme

[  remote  ]

Delete a custom theme. Set confirm=true to proceed.

Keycloak /

skycloak_delete_webhook_subscription

[  remote  ]

Delete a webhook subscription. Set confirm=true to proceed.

Keycloak /

skycloak_discover_oidc

[  remote  ]

Resolve an OIDC issuer's discovery document to obtain its authorization, token, and userinfo endpoints. Use the result when creating an identity provider.