Resources · Claude connector

Claude Control Plane connectorWhat Claude can do in your Control Plane account.

The Claude Control Plane connector exposes 55 tools: 26 read, 29 write. Claude deploys, configures, and debugs your cloud apps there; 15 destructive operations ask for your confirmation. Below: what it reads, what it changes, and who sets the limits.

Verified Trustpilot reviews · AI, automation & growth agency

Overview

What changes for your ops team

Control Plane runs containerized apps across several clouds and your own hardware as one platform. With the connector, you describe the outcome to Claude: it picks the tools, chains the calls, deploys or fixes. You stay the one who signs off on the heaviest operations.

Ship a service. build_image builds the image from your repo, create_workload deploys it, create_domain and add_domain_route give it an address, and list_deployments confirms every location is ready.

Make sense of an outage. get_workload_events surfaces startup failures, get_workload_logs and query_traces dig through logs and slow requests, and query_metrics charts the load.

Keep a paper trail. export_terraform generates infrastructure code for what's already running, and query_audit_events finds out who touched what.

What Claude won't do here: the directory connector stays on the default tool profile, without Kubernetes cluster management or full administration, which require a custom connection. No secret can be deleted, and no secret value ever comes back. Nothing runs by itself either: no alert wakes Claude up at night. That always-on watch belongs to an automation tool, a different job covered on the Integrations hub.

Vocabulary

The vocabulary in one minute

Five words before you plug in Control Plane.

Connector
The link you set up once between Claude and an account you already have, so Claude can work in it while it answers you.
Tool
A named capability the connector opens to Claude. Claude picks the ones it needs by itself; the directory sheet lists them by name.
Authorization
The service's sign-in screen, where you pick the organizations you hand over to Claude. Given once per person, revocable any time.
Approval
The confirmation Claude waits for before completing anything that changes an account, shown in the conversation at the right moment.
MCP
The shared standard behind connectors: it's what lets an assistant like Claude talk to an outside service.
Connect

Plug Control Plane into Claude in three steps

  1. 01

    Find Control Plane

    In Claude's settings, open Customize, then Connectors, and look for Control Plane. On a Team or Enterprise workspace, an Owner or Primary Owner enables it for the organization first.

  2. 02

    Start the connection

    Click Connect on its row, then sign in through the window the service opens itself. If the link breaks, Disconnect followed by a fresh connection sets things right.

  3. 03

    Approve the authorization

    Read the authorization screen before you accept. It's Control Plane's screen, not Claude's, and it sets what the access covers. You can also revoke it later from your account.

Tools

The 55 tools of the Claude Control Plane connector

Control Plane gives Claude 55 tools: 26 that read your account, 29 that change something in it.

Twenty-six tools that read, twenty-nine that create, modify, or delete. Names stay exactly as Claude shows them.

  • 26 read
  • 29 write

What Claude looks up (26)

26 tools

Twenty-six tools that read state, logs, and documentation without touching anything.

browse_templates

Browses the catalog of ready-to-install templates: name, category, latest version, and whether each one brings its own GVC.

When it helps
you're looking for a common database or tool to deploy without starting from scratch.
Watch out
the catalog doesn't say whether a template fits your case, only what it contains.

Sourcedocs.controlplane.com · October 1, 2026 ↗

convert_to_terraform

Translates a resource manifest into Terraform code, after a dry-run check against the API.

When it helps
your team manages infrastructure as code and wants to take over a resource described by hand.
Watch out
only text comes out; nothing gets applied on the platform.

Sourcedocs.controlplane.com · October 1, 2026 ↗

export_terraform

Generates Terraform code for resources already in place, one at a time or in bulk, from their link.

When it helps
you want to version an infrastructure set up by hand in Git.
Watch out
only text comes out; nothing is applied on the platform.

Sourcedocs.controlplane.com · October 1, 2026 ↗

get_command

Fetches one asynchronous command by its ID, to see where a long-running operation stands: in progress, done, or failed, without relaunching anything.

When it helps
you stopped a replica and want to know whether it's finished.
Watch out
without an ID, go through list_commands first.

Sourcedocs.controlplane.com · October 1, 2026 ↗

get_cpln_rules

Loads the platform's operating guide: its resource model, production defaults, and how to verify that an operation actually landed.

When it helps
Claude is preparing a deployment and needs the house best practices first.
Watch out
it's documentation, not the state of your account.

Sourcedocs.controlplane.com · October 1, 2026 ↗

get_cpln_skill

Loads the runbook for one family of tasks: how to use a feature properly, the constraints that are easy to miss, and when it's the wrong tool.

When it helps
you ask for a rare operation and Claude wants to dodge the classic trap.

Sourcedocs.controlplane.com · October 1, 2026 ↗

get_image_build

Reads a build's status, progress events, and log from its build ID.

When it helps
the build you started ten minutes ago looks stuck and you want to know why.
Watch out
you need the ID handed back when the build started.

Sourcedocs.controlplane.com · October 1, 2026 ↗

get_installed_template

Shows an installed template's status, its revision number, and the full set of resources tied to it on the platform.

When it helps
you want to know what last week's database install actually deployed.
Watch out
you need to know which one; the list of installs helps.

Sourcedocs.controlplane.com · October 1, 2026 ↗

get_permissions

Lists the permissions that can be granted on a resource kind, to build an accurate access policy.

When it helps
you want to give someone one precise right without opening everything else.
Watch out
the list shows what's possible, not what's already granted.

Sourcedocs.controlplane.com · October 1, 2026 ↗

get_resource

Fetches one resource by kind and name, with its full definition in JSON, so Claude sees every setting exactly as the platform stores it.

When it helps
Claude needs a workload's exact configuration before touching it.
Watch out
for a secret, only metadata comes back, never its value.

Sourcedocs.controlplane.com · October 1, 2026 ↗

get_resource_schema

Returns the exact schema of a resource kind and its API endpoints, for drafting a correct manifest.

When it helps
Claude is preparing a complex definition and wants to avoid a misnamed field.
Watch out
it's a technical reference, not a resource in your account.

Sourcedocs.controlplane.com · October 1, 2026 ↗

get_template

Shows a catalog template's available versions, its prerequisites, and an example values file to start from.

When it helps
before installing a template, you want to know what it requires.
Watch out
the example values are a starting point, not your configuration.

Sourcedocs.controlplane.com · October 1, 2026 ↗

get_trace

Fetches one trace by ID and summarizes its span tree, durations, and errors.

When it helps
one specific request was slow and you want to see where the time went.
Watch out
you need the trace ID; query_traces helps you find it.

Sourcedocs.controlplane.com · October 1, 2026 ↗

get_workload_events

Fetches a workload's event log to diagnose a failed start, a failing health check, or a stuck deployment.

When it helps
a service stays "not ready" after a deploy and nobody knows why.
Watch out
events show the symptom; logs often show the cause.

Sourcedocs.controlplane.com · October 1, 2026 ↗

get_workload_logs

Queries a workload's logs through simple parameters or a raw LogQL query.

When it helps
a server error shows up in production and you want the lines around it.
Watch out
set a time window so the answer doesn't drown you.

Sourcedocs.controlplane.com · October 1, 2026 ↗

list_commands

Lists the asynchronous commands issued against a workload or a volume set: cron runs, replica stops, volume operations. Claude finds the ID to follow up on there.

When it helps
you want the run history of a scheduled task.
Watch out
only asynchronous operations appear there.

Sourcedocs.controlplane.com · October 1, 2026 ↗

list_deployments

Reports a workload's rollout status location by location. It's the first check after going live.

When it helps
you want to know whether the new version runs everywhere or in just one location.
Watch out
a rollout in progress can show a transitional state.

Sourcedocs.controlplane.com · October 1, 2026 ↗

list_installed_templates

Lists the template releases present in an organization, so Claude can tell what came from the catalog and what was set up another way.

When it helps
you're taking stock of everything installed from the catalog.
Watch out
a resource set up by hand won't appear.

Sourcedocs.controlplane.com · October 1, 2026 ↗

list_metrics

Catalogs the metrics and labels you can query, each with a correct PromQL template, the query language for metrics. Claude starts there so it doesn't aim at a metric that doesn't exist.

When it helps
Claude needs to know which metric to follow before plotting anything.

Sourcedocs.controlplane.com · October 1, 2026 ↗

list_quotas

Lists the organization's resource quotas and current usage, with a filter for those close to the limit.

When it helps
a deployment fails and you suspect a quota was hit.
Watch out
a quota near its limit can block the next deployment.

Sourcedocs.controlplane.com · October 1, 2026 ↗

list_resources

Builds a summary table of the resources of one kind, workloads, domains, or volumes, to give Claude the big picture before digging in.

When it helps
you want the list of all your workloads or all your domains at once.

Sourcedocs.controlplane.com · October 1, 2026 ↗

list_workload_replicas

Lists a workload's running replicas in one location, meaning the copies of the app actually serving traffic right now.

When it helps
you want to know how many instances really run after a scale-up.
Watch out
the list covers one location at a time.

Sourcedocs.controlplane.com · October 1, 2026 ↗

query_audit_events

Queries the audit trail of operations performed on a resource kind, with who did what and when.

When it helps
a workload vanished and you want to know who took it down, and when.
Watch out
the query covers one resource kind at a time.

Sourcedocs.controlplane.com · October 1, 2026 ↗

query_metrics

Runs a PromQL query against the platform's metrics and returns the values, which Claude can then comment on, compare, or sum up in one sentence.

When it helps
you want a service's memory usage over the last few hours.
Watch out
list_metrics helps you find the right metric name first.

Sourcedocs.controlplane.com · October 1, 2026 ↗

query_traces

Searches distributed traces, in TraceQL, for slow or failing requests. A trace follows a request's full path through your services.

When it helps
users complain about slowness and you want the culprit requests.
Watch out
for the detail of a trace you found, follow up with get_trace.

Sourcedocs.controlplane.com · October 1, 2026 ↗

search_control_plane

Searches Control Plane's documentation base: guides, examples, and API references. Claude leans on it so it doesn't answer about the platform from memory.

When it helps
Claude wants to check a syntax before suggesting a configuration.
Watch out
it's public documentation, not the state of your account.

Sourcedocs.controlplane.com · October 1, 2026 ↗

What Claude changes (29)

29 tools

Twenty-nine tools that act on your resources. Fifteen are flagged destructive by the publisher and go through your confirmation; for the rest, the general rule below applies.

add_domain_port

Approval: see the rule

Opens a new listening port on a domain, such as 443 over HTTP/2, so it accepts that kind of traffic.

What Claude asks for
no confirmation of its own is described for this tool, so the general approval rule applies.
When it helps
your domain needs to accept a protocol it didn't serve before.

Sourcedocs.controlplane.com · October 1, 2026 ↗

add_domain_route

Approval: see the rule

Maps a path or address prefix on a domain to a workload, the app that should answer.

What Claude asks for
nothing tool-specific is published on confirmation, so the general approval rule covers it.
When it helps
you want /api to point to one service and everything else to the site.

Sourcedocs.controlplane.com · October 1, 2026 ↗

build_image

Approval: see the rule

Builds a container image from a GitHub or GitLab repository and pushes it to your organization's private registry. The tool hands back a build ID.

What Claude asks for
no source describes a prompt specific to this one; the general approval rule is what holds.
When it helps
you just merged a fix and want the updated image.
Watch out
the build keeps running after the call, so follow it with get_image_build.

Sourcedocs.controlplane.com · October 1, 2026 ↗

clear_domain_tls

Asks you first

Strips the TLS configuration, the part that encrypts traffic, from a domain listener.

What Claude asks for
Control Plane flags this tool as destructive: the assistant lays out the impact and asks for your confirmation before running it.
When it helps
you're swapping a certificate and want a clean slate.

Sourcedocs.controlplane.com · October 1, 2026 ↗

create_gvc

Approval: see the rule

Creates a GVC, the space that groups one or more cloud locations where your workloads will run.

What Claude asks for
on confirmation, nothing is published beyond the general approval rule.
When it helps
you're opening a new environment, staging or production, across two locations.

Sourcedocs.controlplane.com · October 1, 2026 ↗

create_identity

Approval: see the rule

Creates a GVC-scoped identity that gives a workload access to secrets, cloud resources, or private networks.

What Claude asks for
with no rule of its own published, the general approval rule applies.
When it helps
a service needs to read a storage bucket at your cloud provider.

Sourcedocs.controlplane.com · October 1, 2026 ↗

create_policy

Approval: see the rule

Creates a policy that grants permissions on resources to people or services.

What Claude asks for
the publisher describes no specific confirmation, so the general approval rule takes over.
When it helps
a new developer should be able to read logs without being able to delete anything.
Watch out
get_permissions helps you see which permissions can be granted before you draft it.

Sourcedocs.controlplane.com · October 1, 2026 ↗

create_volumeset

Approval: see the rule

Creates a volume set for your workloads' persistent storage.

What Claude asks for
no rule of its own is published; the general approval rule is what applies.
When it helps
a database needs a disk that survives restarts.
Watch out
you then have to mount it on a workload for it to be useful.

Sourcedocs.controlplane.com · October 1, 2026 ↗

create_workload

Approval: see the rule

Creates a workload, serverless, standard, cron, stateful, or VM, with its containers and exposure.

What Claude asks for
on confirmation, the sheet points back to the general approval rule.
When it helps
you want to put a new service online from a ready image.

Sourcedocs.controlplane.com · October 1, 2026 ↗

delete_resource

Asks you first

Deletes one resource identified by kind and name. It's the single delete tool for everything that can be deleted.

What Claude asks for
Being a deletion, Control Plane flags it destructive: the assistant spells out what will disappear and waits for your go-ahead.
When it helps
you're cleaning up after a test and want to drop a workload you no longer need.
Watch out
secrets can't be deleted with this tool.

Sourcedocs.controlplane.com · October 1, 2026 ↗

expand_volumeset

Approval: see the rule

Grows a volume's capacity, with no downtime or data loss according to the publisher.

What Claude asks for
for this capacity bump, only the general approval rule is documented.
When it helps
your database is getting close to filling its disk.
Watch out
the publisher describes growing volumes, not shrinking them.

Sourcedocs.controlplane.com · October 1, 2026 ↗

grant_workload_secret_access

Approval: see the rule

Gives an existing workload access to a secret by wiring up its identity and access policy. The secret's value never comes back.

What Claude asks for
no confirmation of its own is described, so the general approval rule applies here.
When it helps
a service needs to read an API key stored as a secret.

Sourcedocs.controlplane.com · October 1, 2026 ↗

install_template

Approval: see the rule

Installs a catalog template as a new release.

What Claude asks for
for confirmation, the general approval rule is the only one documented.
When it helps
you want a ready-to-use database in a single request.
Watch out
a template can bring its own GVC, so check with get_template.

Sourcedocs.controlplane.com · October 1, 2026 ↗

mount_volumeset_to_workload

Approval: see the rule

Attaches a volume set to a workload at a given path, so it can read and store its files there.

What Claude asks for
for this operation, no confirmation of its own is published; the general approval rule remains.
When it helps
your database must keep its files between two restarts.
Watch out
ext4 and xfs mounts require a stateful workload or a VM.

Sourcedocs.controlplane.com · October 1, 2026 ↗

remove_domain_port

Asks you first

Takes a listening port off a domain.

What Claude asks for
The publisher files this removal among destructive operations, with the impact laid out and confirmation requested before it runs.
When it helps
an old protocol shouldn't be served anymore.
Watch out
traffic that used that port gets cut off at once.

Sourcedocs.controlplane.com · October 1, 2026 ↗

remove_domain_route

Asks you first

Takes a route off a domain listener.

What Claude asks for
Destructive per the publisher, this tool goes through an impact summary and your confirmation before it fires.
When it helps
an old path still points to a service that's been shut down.

Sourcedocs.controlplane.com · October 1, 2026 ↗

set_domain_tls

Asks you first

Sets the TLS configuration on a domain listener, the part that encrypts traffic.

What Claude asks for
Like every operation Control Plane flags as destructive, this one is presented with its impact and waits for your green light.
When it helps
you're installing a new certificate on your domain.

Sourcedocs.controlplane.com · October 1, 2026 ↗

uninstall_template

Asks you first

Uninstalls a template release and takes down the resources it had put in place.

What Claude asks for
The publisher ranks this uninstall among destructive operations: impact shown, then confirmation requested.
When it helps
a tool installed for a test is no longer needed.

Sourcedocs.controlplane.com · October 1, 2026 ↗

update_domain

Asks you first

Updates a domain's metadata, its host and subdomain acceptance flags, and its binding to a GVC or workload.

What Claude asks for
Marked destructive by Control Plane, this tool stops on the impact and your confirmation.
When it helps
you're moving your domain over to a new workload.

Sourcedocs.controlplane.com · October 1, 2026 ↗

update_domain_route

Asks you first

Updates an existing route on a domain listener.

What Claude asks for
Before acting, the assistant details the impact and asks for your confirmation, since the publisher classes the tool as destructive.
When it helps
you're redirecting a path to a service's new version.

Sourcedocs.controlplane.com · October 1, 2026 ↗

update_gvc

Asks you first

Updates a GVC's settings, such as its description, tags, or registry pull secrets.

What Claude asks for
Classed destructive by the publisher: the impact shows up and your confirmation is required.
When it helps
you're adding a pull secret for a private registry.

Sourcedocs.controlplane.com · October 1, 2026 ↗

update_identity

Asks you first

Adjusts an existing identity: its settings and the cloud credentials bound to it.

What Claude asks for
Control Plane lists it among destructive operations, which go through an impact summary and your confirmation.
When it helps
a service needs access to a new storage bucket.

Sourcedocs.controlplane.com · October 1, 2026 ↗

update_policy

Asks you first

Updates a policy's bindings, targets, or permissions.

What Claude asks for
Because the publisher deems it destructive, this operation is put to you with its impact before it runs.
When it helps
a contractor leaves the project and must lose access.

Sourcedocs.controlplane.com · October 1, 2026 ↗

update_volumeset

Asks you first

Revises the configuration of a volume set that already exists.

What Claude asks for
Flagged destructive by Control Plane, the tool presents the impact and asks for your approval.
When it helps
you're tuning a database's storage settings.
Watch out
the publisher doesn't detail which settings can be updated.

Sourcedocs.controlplane.com · October 1, 2026 ↗

update_workload

Asks you first

Reworks a running workload's definition: image, resources, scaling, environment variables, and more.

What Claude asks for
Ranked among destructive operations by the publisher, it lays out the impact and waits for your confirmation.
When it helps
you're shipping a new version or giving a service more memory.

Sourcedocs.controlplane.com · October 1, 2026 ↗

upgrade_template

Asks you first

Moves a template release to a new version or to updated values.

What Claude asks for
Control Plane classes this upgrade as destructive: impact presented, confirmation required.
When it helps
a new version of an installed tool patches a flaw.

Sourcedocs.controlplane.com · October 1, 2026 ↗

workload_start_cron

Approval: see the rule

Triggers an immediate run of a cron workload, without waiting for its schedule.

What Claude asks for
for this trigger, the general approval rule is the only one documented.
When it helps
you want to test a scheduled task right away.
Watch out
the run counts as a real one, so its effects are real.

Sourcedocs.controlplane.com · October 1, 2026 ↗

workload_stop_replica

Asks you first

Terminates one running replica of a workload; the platform schedules a replacement according to its scaling settings.

What Claude asks for
A destructive operation for the publisher: the assistant shows the impact and waits for your confirmation.
When it helps
one replica looks stuck and you want it replaced.

Sourcedocs.controlplane.com · October 1, 2026 ↗

Approvals

What Claude asks before it acts

By default, Claude stops and asks for your go-ahead before any action it takes on an account for you. Control Plane adds its own rule for its 15 destructive operations.

According to Control Plane's documentation, tools that delete, remove, or overwrite data make the assistant present the impact and then ask for your confirmation. On a Team or Enterprise workspace, owners decide whether a member can let certain actions through, and they can cap what the connector does for the whole organization. And Claude works with your permissions: an organization you didn't tick on the consent screen stays closed to it.

Plans

Which plans it's available on

None of the 819 sheets in the official directory shows availability by plan. A connector-by-connector answer isn't published anywhere.

The general rule is sourced: remote connectors are open to all users on Claude, Cowork, Claude Desktop, and mobile. On Team and Enterprise, an Owner or Primary Owner enables the connector for the organization before each member connects. For the current status, check the Control Plane sheet in the official directory.

Limits

Where Control Plane stops

A connector isn't an automation. Claude calls these tools while it answers you: no deployment goes out on its own when a repo changes.

Only the publisher documents this connector: neither Claude's help center nor Anthropic's documentation has a page about it. The directory version is locked to the default tool profile, which has 55 tools; the broader profiles, with 77 and 131 tools, require a custom connection. The directory badge isn't a security audit. To compare with another sheet, see the Claude activecampaign connector page.

Need help

Need help connecting Control Plane to Claude?

A person reads every message.

FAQ

Claude Control Plane connector FAQ

01What can Claude do with the Control Plane connector?
Claude can deploy, configure, and debug your apps on Control Plane from the conversation. Twenty-six tools read workload state, logs, metrics, traces, quotas, the audit trail, and the documentation. Twenty-nine act: building images, creating workloads, domains, volumes, or access policies, installing templates, updates, and deletions. You describe the outcome you want in plain words, and Claude picks on its own which of these tools to chain together to get there.
02Can Claude delete or modify my Control Plane resources?
Yes. The connector has 29 write tools, including a single delete tool that removes any deletable resource by kind and name, plus update tools for workloads, domains, routes, access policies, identities, and volumes. One documented exception: secrets can't be deleted through this connector. Everything stays bounded by your own rights on the platform and by the organizations you ticked when you connected, so a narrow account means a narrow Claude.
03Does Claude ask before acting on Control Plane?
For 15 operations, yes, according to the publisher: the tools flagged destructive, which delete, remove, or overwrite data, make the assistant present the impact and then ask for your confirmation. For the other writes, no source describes a rule of their own, so Claude's general rule applies: by default, it asks for your go-ahead before any action it takes for you. On Team and Enterprise, owners can loosen or tighten that behavior for everyone.
04Which plans is the Control Plane connector available on?
No official source publishes plan availability connector by connector, and none of the 819 directory sheets shows it. The general rule is that remote connectors are open to all users on Claude, Cowork, Claude Desktop, and mobile. On Team and Enterprise, an Owner or Primary Owner first has to enable the connector for the organization. For the exact status on your account, open the Control Plane sheet in the official directory.
05Does Claude see all my Control Plane organizations?
No. On the consent screen, you tick the organizations Claude will be able to reach, and it only sees those. It also works with your permissions: whatever you can't do on the platform, it won't do either. To add an organization you missed, disconnect, reconnect, and adjust your selection. On Claude's side, an owner of a Team or Enterprise workspace can also restrict the connector for everyone, and a member can't lift that alone.
06Why can't Claude find a Control Plane tool?
Because the directory connector is locked to the default tool profile, which has 55 tools. Kubernetes cluster management and full administration belong to broader profiles, with 77 and 131 tools, available only through a custom connection. The profile never changes mid-conversation, so you have to reconnect with the right one first. On the flip side, a 30-tool read-only profile exists for investigating production with no risk of an unintended modification.
07Claude or an automation tool for Control Plane?
They don't do the same job. With Claude, you drive the platform on demand: a deployment, a diagnosis, a cleanup, in the flow of the conversation. After that, nothing happens until you type again. The connector doesn't monitor your services and doesn't deploy on every commit. For a continuous delivery pipeline or an automatic alert, that's what an automation tool is for. To understand and act fast, the connector does the work.