Overview

Live
Data Sources
-
configured
Sources Up
-
connected
Services
-
discovered
Services Healthy
-
live
MCP Endpoint: http://localhost:3000/mcp

How it works

AgentMCP call
Gateentitlement · RBAC · catalog
ConnectorsPrometheus · Loki
Analysisscored health

Sources

Loading...

Services

Loading...

Needs attention

Loading…

Services by health score

Loading…

Data Sources

All sources

Loading...

Services

Discovered services

Loading...

Connectors

Installed connectors

Loading...

Available from the Connector Hub

Open Hub ↗
Loading...

Upload a connector bundle

Install a signed connector .tgz directly — handy for air-gapped environments. The bundle is always verified against the configured trust root before it is loaded.

Service Health

Loading health data...

Infrastructure Topology

Sources & counts

Loading topology...

Grouped by host (pivots on the RUNS_ON relation)

Scope = any resource pointed to by an IN_NAMESPACE edge (e.g. k8s namespaces, future: vCenter folders).
Loading...

Layered graph

click a resource to inspect · drag to reposition · wheel to zoom · drag the background to pan
Tab to focus · Enter to inspect · arrows to move focus · Esc to clear

Settings

How often the agent scans for anomalies

Configure how service health scores are calculated. Weights must sum to 1.0.

Weights

Thresholds

CPU (%)

Error Rate (req/s)

Latency P99 (seconds)

Log Errors (/min)

Status Boundaries

Each data source has its own metric definitions with backend-specific queries (PromQL, LogQL, etc.). Use {{service}} as placeholder for the service/job name.

NameUnitQueryDescription
Select a source above

Access Control

Roles & bindings

Loading…
Use Edit policy above — no command line needed. The block below is the optional API equivalent for automation/CI.

Context Products

The catalog publishes context products — reusable bundles of sources, services and tools — and the grants that decide which principals may consume each product. Browse below as cards or a table; an admin can create or change products via the editor or the API example.

About Products

click to collapse

What is a product?

A curated, named bundle of MCP tools you expose to one agent. The bundle's tools allow-list filters tools/list at the /mcp transport, so an agent bound to Ops Bundle sees only the operations tools and not the developer tools.

When do I need one?

Whenever more than one agent connects. Each team / use-case gets its own product — SRE on-call vs coding assistant vs compliance auditor. Without a product the credential sees every registered tool, which is fine for a single-operator demo but not for a production multi-agent deployment.

How do agents pick one up?

Bind a credential to a product via OMCP_KEY_PRODUCTS:

OMCP_API_KEYS="agent:tok_ops,ci:tok_dev"
OMCP_KEY_PRODUCTS="agent=ops-bundle;ci=dev-bundle"

The next /mcp session of agent sees only the tools in ops-bundle. Full docs →

MCP Products

Loading…

Products (legacy / enterprise catalog)

Loading…
Use Edit catalog above — no command line needed. The block below is the optional API equivalent for automation/CI.

Policies

Probe a permission

Roles

Loading…
Select a role on the left to see its permission matrix.

Audit Log

Recent decisions

Loading…

Management changes

Loading…

Entitlement

Read-only

Access-control gate

Loading…