PiLAB

PiLAB MCP Connector for Claude

A+

Manage infrastructure and security via PiLAB — control PiVirt virtual machines, inspect PiTrust certificates, and oversee 3SO OAuth clients directly from any AI agent.

12 tools Official Updated Oct 1, 2026 Official Vinkius Partner

Connect your PiLAB account to any AI agent and take full control of your infrastructure and security operations through natural conversation.

What you can do

  • Virtual Machine Management — List all PiVirt hosts, inspect VMs (CPU, memory, disk, network), and control lifecycle (start, stop, restart, pause, resume) from your chat
  • Certificate Management — List all TLS/SSL certificates managed by PiTrust, inspect certificate metadata, chains, and rotation status
  • ZeroTrust Access Policies — List RBAC rules, JIT access grants, and service-to-service authentication policies configured in PiTrust
  • OAuth 2.0 Client Management — List all registered applications in 3SO (Shadow SSO), inspect client configurations, scopes, and grant types
  • Token Introspection — Validate any OAuth 2.0 access token via the 3SO introspection endpoint (RFC 7662) to verify scopes and expiry
  • Session Monitoring — List active user sessions in the 3SO identity system to audit who is authenticated and what scopes they hold

How it works

  1. Subscribe to this server
  2. Register an OAuth 2.0 application in your PiLAB SSO admin console (one-time setup, ~5 minutes)
  3. Enter your Client ID and Client Secret, then click Connect with PiLAB to authorize access
  4. Start managing your infrastructure from Claude, Cursor, or any MCP-compatible client

Your AI acts as a dedicated infrastructure and security operations assistant — no more switching between the PiVirt console, PiTrust dashboard, and SSO admin panel to check a VM status or verify a certificate.

Who is this for?

  • DevOps Engineers — check VM status, control lifecycle, and verify host resources without leaving the conversation
  • Security Teams — audit certificate expiries, inspect access policies, and verify token validity in real-time
  • Platform Architects — review OAuth client configurations and active sessions to understand the identity landscape
  • IT Operations — combine VM control with certificate monitoring for end-to-end infrastructure visibility
infrastructure-managementvirtualizationzero-trust-securityoauth2certificate-managementkvm-virtualization

12 tools expose this connector's capabilities to your AI agent.

get_vm_details

Get details for a specific virtual machine

list_certificates

List all TLS/SSL certificates managed by PiTrust

list_hosts

List all PiVirt virtualization hosts

list_active_sessions

List active user sessions in the 3SO identity system

list_oauth_clients

List all registered OAuth 2.0 clients

list_virtual_machines

Optionally filter by host ID to see only VMs on a specific host. List all virtual machines across PiVirt hosts

control_vm

Valid actions: start, stop, restart, pause, resume. Use this to manage VM lifecycle from your AI agent. Start, stop, or restart a virtual machine

get_host_details

Get details for a specific PiVirt host

get_oauth_client

Get details for a specific OAuth 2.0 client

introspect_token

Returns token validity, scopes, expiry, and associated client/user. Use this to verify tokens before trusting them. Introspect an OAuth 2.0 access token

list_access_policies

List all ZeroTrust access policies

get_certificate_details

Get details for a specific certificate

See how to talk to your AI agent using PiLAB.

List all virtual machines across my PiVirt hosts.

Retrieved 8 VMs across 3 hosts. Notable machines include 'web-prod-01' (running, host node-01), 'db-replica-02' (running, host node-02), and 'staging-api' (stopped, host node-03). Would you like details or to control any specific VM?

Start the VM with ID vm-1024.

Sent the 'start' command to VM vm-1024. The VM is now in 'running' state on host node-02. CPU: 4 vCPUs, Memory: 16 GB. Is there anything else you'd like to do with this VM?

Show me all TLS certificates and flag any that are expiring soon.

Found 6 certificates in PiTrust. ⚠️ Two need attention: '*.pilab.hu' expires in 12 days (rotation pending), and 'api.internal.pilab.hu' expires in 30 days. The remaining 4 certificates have at least 60 days before expiry. Would you like the full details on either expiring certificate?

After subscribing, the setup wizard will guide you through 3 simple steps: 1) Enter your PiLAB Instance Base URL. 2) Enter the Client ID and Client Secret from your PiLAB SSO (3SO) application. 3) Click the **Connect with PiLAB** button — a popup will open where you approve access via the Shadow SSO authorization flow. That's it! No manual token exchange or curl commands required.

Related Connectors