Best of · Developer & infrastructure

Best cloud infrastructure tools for AI agents

All 7 ranked cloud infrastructure tools on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change.

  • 7 ranked
  • 2 agent-ready
  • 5 hosted endpoints
  • Updated 9 October 2026

Top three

Picks by need

Worked out from the scores, prices and facts, so they change when the research does.

Highest score overall

Terraform MCP Server BB

BB, 71.9/100 on the benchmark.

Also Cloudflare MCP Servers, BB, 70.9/100.

Agent ergonomics

Cloudflare MCP Servers BB

77/100 on agent ergonomics, against 74 for the overall leader.

Security & auth

AWS MCP Servers B

84/100 on security & auth, against 65 for the overall leader.

Maintenance & community

Azure MCP Server B

89/100 on maintenance & community, against 78 for the overall leader.

Transparency & trust

Cloudflare MCP Servers BB

88/100 on transparency & trust, against 86 for the overall leader.

A hosted MCP endpoint

Cloudflare MCP Servers BB

remote MCP server, nothing to install.

The shortlist

#ToolGradeBest forPriceWhere
1 Terraform MCP Server
HashiCorp
BB 71.9 Agents writing or reviewing Terraform that need the real provider schema, and for teams on HCP Terraform who want plan and run inspection from chat. Free · OSS local
2 Cloudflare MCP Servers
Cloudflare
BB 70.9 Agents that manage Workers, DNS, R2, D1 and other Cloudflare resources, or read Cloudflare docs without an account. Your plan hosted
3 Azure MCP Server
Microsoft
B 67.7 Agents inspecting or operating Azure resources under a developer's or service principal's own RBAC. Free · OSS local
4 Render MCP Server
Render Services, Inc.
B 63.6 Agents that deploy and debug applications on Render, reading logs and metrics and querying Postgres. Your plan hosted and local
5 AWS MCP Servers
Amazon Web Services (AWS Labs)
B 63.3 Knowledge suits any agent answering AWS documentation or regional availability questions with no setup. Free · OSS hosted and local
6 DigitalOcean MCP Server
DigitalOcean, LLC
C 60.6 Agents that operate DigitalOcean accounts, across Droplets, App Platform, Kubernetes, databases, networking and the AI platform, with one endpoint a service. Your plan hosted and local
7 Railway MCP Server
Railway Corporation
C 56.7 Agents that deploy and operate applications on Railway from an editor and are content to hand multi-step work to Railway's own agent. Your plan hosted and local

How to choose

  1. Read-only or mutating toolsCheck which tools change infrastructure and which only read it, since an agent with a mutating tool can create, delete or reconfigure live resources without a separate approval step.
  2. Own account and credentialsCheck whether the tool needs your own cloud account and credentials, since a bring-your-own-plan server can only act within the permissions of the key the agent is given.
  3. Covered providers and gapsCheck which providers and resource types the server covers and which are marked not supported, so the agent does not plan around an operation that cannot run.
  4. Release and tool version changesCheck how often the server changes and whether its tool names and arguments are versioned, because an agent scripted against renamed tools will fail on a routine upgrade.

Each one in detail

#1

Terraform MCP Server

BB 71.9/100

HashiCorp's official MCP server for Terraform and its registry.

Verdict Nine registry tools load by default and need no credentials. Workspace updates, variable writes, team membership and access grants run without the operations flag.

Choose it for Agents writing or reviewing Terraform that need the real provider schema, and for teams on HCP Terraform who want plan and run inspection from chat.

Strengths

  • Nine registry tools load by default and need no credentials
  • Deletes, force-unlock and apply-capable runs stay off until ENABLE_TF_OPERATIONS=true
  • Refuses an HCP Terraform token sent in a query string and can pin HTTP deployments to an organisation allowlist

Weaknesses

  • Workspace updates, variable writes, team membership and access grants run without the operations flag
  • Nine variable and variable-set tools have no readOnly or destructive hints
  • Provider docs come back whole, with no section-level fetch

Price Free · OSSAuth OAuth or keyx402 nolocal

Full assessment

#2

Cloudflare MCP Servers

BB 70.9/100

A family of Cloudflare-hosted remote MCP servers.

Verdict OAuth on every account server, with the Code Mode consent page defaulting to read-only scopes. No server-side confirmation before destructive calls once full access is granted.

Choose it for Agents that manage Workers, DNS, R2, D1 and other Cloudflare resources, or read Cloudflare docs without an account.

Strengths

  • OAuth on every account server, with the Code Mode consent page defaulting to read-only scopes
  • The whole Cloudflare API behind three Code Mode tools, with results capped at about 6,000 tokens
  • The Documentation server works with no account or key

Weaknesses

  • No server-side confirmation before destructive calls once full access is granted
  • No prompt-injection guidance for Browser Run pages or AI Gateway logs
  • 40 open issues, several bug reports from May to August with no reply

Price Your planAuth OAuth or keyx402 nohosted

Full assessment

#3

Azure MCP Server

B 67.7/100

Microsoft's official local MCP server for Azure (@azure/mcp, also on NuGet as Azure.Mcp).

Verdict Entra ID through DefaultAzureCredential, so access follows RBAC and no secret sits in the MCP config. npm latest installs a 3.0.0 beta, and betas rename and remove tools without a notice period.

Choose it for Agents inspecting or operating Azure resources under a developer's or service principal's own RBAC.

Strengths

  • Entra ID through DefaultAzureCredential, so access follows RBAC and no secret sits in the MCP config
  • --read-only, --namespace, --tool, consolidated and single-tool modes for cutting the surface down
  • Secret, connection-string and private-key reads ask the user first through elicitation

Weaknesses

  • npm latest installs a 3.0.0 beta, and betas rename and remove tools without a notice period
  • No confirmation step before deletes and other destructive calls
  • Telemetry to Microsoft is on by default

Price Free · OSSAuth OAuth or keyx402 nolocal

Full assessment

#4

Render MCP Server

B 63.6/100

Render's official MCP server lets an agent create services and data stores on the Render cloud platform, trigger deploys, read logs and metrics, and run read-only SQL on Render Postgres. It is hosted at mcp.render.com.

Verdict A hosted server with 26 typed and annotated tools, OAuth or API key access and Apache-2.0 source. It cannot delete resources and wraps SQL in a read-only transaction. There are no scopes and no read-only mode, a key reaches every workspace its owner belongs to, and Render's status page recorded several major incidents in 90 days.

Choose it for Agents that deploy and debug applications on Render, reading logs and metrics and querying Postgres.

Strengths

  • All 26 tools declare typed inputs and carry read-only, destructive and open-world annotations in the Apache-2.0 source.
  • The server has no delete tools, and query_render_postgres runs each query inside a read-only transaction.
  • OAuth with PKCE and token revocation since 22 July 2026, with API keys kept for CI and other non-interactive use.

Weaknesses

  • No scopes and no read-only mode. An API key reaches every workspace its owner belongs to, and a read-only toolset request has been open since 8 October 2025.
  • status.render.com lists 16 incidents from 15 July to 3 October 2026, four critical and five major, mostly on builds, deploys and the dashboard.
  • Logs and database rows reach the model with no prompt-injection guidance found, and the docs say secrets may be exposed.

Price Your planAuth OAuth or keyx402 nohosted and local

Full assessment · Against #1, Terraform MCP Server

#5

AWS MCP Servers

B 63.3/100

AWS MCP servers for documentation, infrastructure, operations and development. Includes local servers and a hosted knowledge server.

Verdict Knowledge server is hosted, free, GA and needs no account or key. No published rate-limit numbers, retry guidance or status component for the Knowledge server.

Choose it for Knowledge suits any agent answering AWS documentation or regional availability questions with no setup.

Strengths

  • Knowledge server is hosted, free, GA and needs no account or key
  • Local servers use IAM credentials, so every call lands in CloudTrail
  • Writes off by default on most servers, and the AWS API server adds read-only mode, mutation consent and a deny list

Weaknesses

  • No published rate-limit numbers, retry guidance or status component for the Knowledge server
  • READ_OPERATIONS_ONLY and REQUIRE_MUTATION_CONSENT default to false on the AWS API server
  • Seven security advisories in 2026, including a policy bypass in the AWS API server

Price Free · OSSAuth OAuth or keyx402 nohosted and local

Full assessment

#6

DigitalOcean MCP Server

C 60.6/100

DigitalOcean's official MCP servers let an agent manage Droplets, App Platform apps, Kubernetes, managed databases, networking and other DigitalOcean resources. Each service has a hosted endpoint, and the same MIT server runs locally from npm.

Verdict Every tool carries read-only, destructive and idempotent hints enforced by a test, and access can be narrowed with OAuth, expiring tokens and granular scopes. The server has no read-only mode, database tools return cluster objects unredacted, and DigitalOcean's status feed shows several long platform incidents since late July 2026.

Choose it for Agents that operate DigitalOcean accounts, across Droplets, App Platform, Kubernetes, databases, networking and the AI platform, with one endpoint a service.

Strengths

  • All tools carry read-only, destructive, idempotent and open-world hints plus a low, medium or high risk label, enforced by a test in CI.
  • Tools are split across 22 hosted endpoints, and the local server takes --services, so a client loads only the services it needs.
  • Hosted servers accept OAuth sign-in with short-lived tokens, or a personal access token with an expiry and granular custom scopes.

Weaknesses

  • No read-only mode on the server. A request for one has been open since 2 March 2026.
  • db-cluster-list and db-cluster-get return the API's database object unredacted. An issue reporting plaintext passwords has been open since 26 May 2026.
  • The status feed lists several long incidents since 24 July 2026, including the public API and control panel on 24 and 25 August.

Price Your planAuth OAuth or keyx402 nohosted and local

Full assessment · Against #1, Terraform MCP Server

#7

Railway MCP Server

C 56.7/100

Railway's official MCP server is hosted at mcp.railway.com. It lets an agent list and create projects, redeploy services, manage feature flags and hand multi-step work to Railway's own agent, through OAuth or the Railway CLI.

Verdict A small hosted server with 11 tools, OAuth grants limited to chosen workspaces and one-hour tokens. Most infrastructure work goes through the railway-agent tool, which is billed by model tokens. The hosted server's source and tool schemas are not public, there is no read-only scope, and the status page lists about 25 incidents in 90 days.

Choose it for Agents that deploy and operate applications on Railway from an editor and are content to hand multi-step work to Railway's own agent.

Strengths

  • OAuth with PKCE, dynamic client registration and a device code grant. A person picks the workspaces and projects a client reaches.
  • Access tokens last one hour, refresh tokens rotate, and the CLI route keeps any long-lived credential out of editor configuration.
  • Eleven tools keep the context cost low, with railway-agent taking multi-step work in one call.

Weaknesses

  • The hosted server's source and tool schemas are not public, so inputs can only be read after signing in.
  • The MCP resource lists one scope, workspace:member, with no read-only grant.
  • The docs say the server can deploy templates, manage environments and pull variables, but no hosted tool is named for those. They go through railway-agent or the local server.

Price Your planAuth OAuthx402 nohosted and local

Full assessment · Against #1, Terraform MCP Server

Head to head

All 12 comparisons in this category

Questions

What are the highest-rated cloud infrastructure tools for AI agents?

Terraform MCP Server has the highest benchmark score of the 7 ranked cloud infrastructure tools, 71.9 (BB). Cloudflare MCP Servers is second with 70.9 (BB).

How many cloud infrastructure tools are agent-ready?

2 of the 7 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.

Which cloud infrastructure tools accept x402 payments?

None of the ranked listings here accepts x402 for its main call yet.

How is this list ranked?

By the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 9 October 2026.

How this list is made

The order is the Anchor benchmark score, the same number as on each listing and in the top list. Each listing is graded from public evidence against the benchmark checklist, and the picks above are worked out from those grades, prices and facts. No listing pays for its place, and paid audits or listing help never change a score.

Full ranked table · 12 head-to-head comparisons · Best tools in every category

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.