MCP tools
Updated 6 October 2026 · applies to 1.0.1 · Commercial
Every tool the BROKA MCP server offers — 136 in all — by area, with what each does and what kind it is. How the server is turned on, who may use it and how its calls are recorded are on MCP server.
Kinds
| Kind | What it means |
|---|---|
| read | Changes nothing |
| write | Changes something. Takes a reason, which a guarded environment requires |
| destructive | Removes or changes something for good, or cannot be undone. Requires a reason in every environment, and is marked for the client as destructive |
| preview | Changes nothing. Returns what a change would do and a plan id for its apply tool, good for ten minutes |
| apply | Takes the plan id of a preview and applies exactly what was previewed, once. apply · destructive marks one whose change is destructive: it requires a reason too |
A token sees only the tools it can use. In Read only mode the write, destructive and apply tools are not listed. A tool needing a permission the token cannot use is not listed, nor is a tool for a platform the installation does not serve; the Kafka Connect tools appear only where a Connect cluster is registered. Every list is paged — at most 100 rows a page — and hands back a cursor while there is more.
Estate
| Tool | Kind | What it does |
|---|---|---|
estate_list_environments |
read | The environments, with each one's write policy and default classification |
estate_list_connections |
read | The connections the token's owner can see, with their environment and last known health; by platform or environment |
estate_get_connection |
read | One connection: its platform, environment, health and the features it supports — never a secret |
estate_test_connection |
read | Connects with the stored settings and reports whether the server answered, how fast, and what it is |
estate_search |
read | The console's global search: topics, queues, keys, consumer groups, connections and applications by name |
Kafka
| Tool | Kind | What it does |
|---|---|---|
kafka_get_cluster |
read | Status, version and nodes; the KRaft metadata quorum with its voters and observers; every feature with its finalized and supported levels |
kafka_list_brokers |
read | Brokers and controllers: rack, controller role, partitions, leaders, under-replicated partitions and log-directory size |
kafka_get_broker |
read | One broker, with its configuration and where each value comes from, its log directories and its loggers |
kafka_get_metrics |
read | The cluster's metrics, read live and never stored — from JMX too where it is set up — and, for a named topic, its byte and message rates |
kafka_list_topics |
read | Topics with partitions, replication factor, size, retention, produce rate and last activity, from the cluster snapshot |
kafka_get_topic |
read | One topic: partitions and replicas, configuration with each value's source, the ACLs that apply to it, and its producers |
kafka_read_messages |
read | A bounded read of a topic's records — from the latest, the earliest, an offset or a time, optionally filtered by value or key — up to 100 |
kafka_list_consumer_groups |
read | Consumer groups with state, lag, time lag and an INACTIVE or STALLED signal; name a topic to find who reads it |
kafka_get_consumer_group |
read | One group, read live: members and assignments, each partition's offsets and lag, and lag by topic, broker and host |
kafka_list_share_groups |
read | Share groups (Kafka 4.0 and later) with state, members, topics and lag |
kafka_get_share_group |
read | One share group: members and assignments, each partition's start offset and lag, and its configuration |
kafka_list_streams_groups |
read | Kafka Streams groups (Kafka 4.1 and later) with state, members and subtopologies |
kafka_get_streams_group |
read | One Streams group: its subtopologies, and the active, standby and warm-up tasks each member holds |
kafka_list_acls |
read | ACL bindings, by principal or resource, or every binding that applies to a topic. ACLs are changed only in the console |
kafka_list_quotas |
read | Client quotas for each user, client id, IP or default |
kafka_list_client_metrics |
read | Client-metrics subscriptions: the metrics they ask for, the push interval and the clients they match |
kafka_list_scram_users |
read | The users with SCRAM credentials, with mechanism and iterations — never a password, salt or hash |
kafka_list_delegation_tokens |
read | Delegation tokens with owner, renewers and dates — never the token's secret |
kafka_list_transactions |
read | Transactional ids with their state; filters find the ones running longer than their timeout |
kafka_get_transaction |
read | One transactional id: state, timeout, partitions, and whether the transaction in progress has run past its timeout |
kafka_list_reassignments |
read | Partition reassignments in progress, with the replicas each is adding and removing |
kafka_create_topic |
write | Creates a topic with its partitions, replication factor and configuration overrides |
kafka_delete_topic |
destructive | Deletes a topic and every record in it |
kafka_preview_topic_config |
preview | Checks a configuration change with the brokers: each property before and after, and any the brokers refuse |
kafka_apply_topic_config |
apply | Applies the previewed configuration change |
kafka_add_partitions |
destructive | Raises a topic's partition count. Cannot be undone, and moves which partition a key lands on |
kafka_produce |
write | Writes 1 to 100 records, as text or encoded through the Schema Registry, and says where each landed |
kafka_preview_offset_reset |
preview | Computes where a consumer group's committed offsets would move, partition by partition |
kafka_apply_offset_reset |
apply · destructive | Moves the group's offsets as previewed; the group must have no active members |
kafka_delete_consumer_group |
destructive | Deletes a consumer group and its committed offsets; the group must have no active members |
Schema Registry and Kafka Connect
| Tool | Kind | What it does |
|---|---|---|
kafka_get_schema_registry |
read | The registry on a Kafka connection: active and soft-deleted subjects, global compatibility and mode, contexts and schema types |
kafka_list_subjects |
read | Subjects with their schema type, latest version and how many versions each has; soft-deleted ones on request |
kafka_get_schema |
read | One version of a subject — schema text, id, references and metadata — with the subject's versions, compatibility and settings |
kafka_diff_schemas |
read | Two versions of one subject, and the lines removed and added between them |
kafka_check_schema_compatibility |
read | Checks a candidate schema against a subject without registering it, with the registry's reasons if it fails |
kafka_preview_schema |
preview | Checks a schema against its subject's compatibility; a compatible one gets a plan |
kafka_register_schema |
apply | Registers the previewed schema as its subject's next version |
kafka_set_subject_compatibility |
write | Sets the compatibility level a subject sets itself |
kafka_soft_delete_subject |
destructive | Soft-deletes a subject; its versions can still be read. Permanent deletion stays in the console |
kafka_list_connect_clusters |
read | The Kafka Connect clusters registered on a Kafka connection — never a secret |
kafka_list_connectors |
read | Connectors with their type, class, state, and how many tasks run and how many failed |
kafka_get_connector |
read | One connector: state, worker, configuration with secret values masked, each task with a failed one's stack trace, and its offsets |
kafka_list_connect_plugins |
read | The connector plugins installed on the cluster's workers |
kafka_pause_connector |
write | Pauses a connector and its tasks |
kafka_resume_connector |
write | Resumes a paused or stopped connector and its tasks |
kafka_stop_connector |
destructive | Stops a connector: its tasks shut down and release their resources until it is resumed |
kafka_restart_connector |
write | Restarts a connector, optionally with its tasks, or only the instances that failed |
kafka_restart_task |
write | Restarts one task of a connector |
kafka_preview_connector_config |
preview | Validates a connector's new configuration and lists the properties it adds, removes and changes |
kafka_apply_connector_config |
apply | Replaces the connector's configuration with the previewed one |
Redis
| Tool | Kind | What it does |
|---|---|---|
redis_get_instance |
read | The server's health from INFO, its databases, replication links, cluster slots and the Sentinel groups watching it |
redis_scan_keys |
read | One page of a database's keys, walked with SCAN — never KEYS — by pattern and type |
redis_get_key |
read | One key: its type, expiry, size, and its value or the first page of its elements |
redis_analyze_keys |
read | A sampled analysis of the keyspace: memory and counts by type, the largest prefixes and keys, expiry coverage |
redis_get_diagnostics |
read | The memory and latency reports, the slow log, the connected clients and the runtime configuration |
redis_list_streams |
read | The streams in a database with their length, memory and expiry — never an entry |
redis_get_stream |
read | One stream: its entries, its consumer groups with their lag, and a named group's consumers and pending entries |
redis_list_pubsub |
read | Pub/Sub channels with their subscribers, pattern subscriptions and shard channels |
redis_list_acl_users |
read | ACL users and their rules — never a password or hash. They are changed only in the console |
redis_list_indexes |
read | Search indexes with their progress and failures, or one index described in full |
redis_query_index |
read | One page of the documents a search-index query matches |
redis_set_key |
write | Writes into a key the way its type writes: a string, a hash field, a JSON document or path, a list item, a sorted-set member, set members |
redis_expire_key |
write | Gives a key an expiry, or removes the one it has |
redis_delete_keys |
destructive | Deletes up to 100 keys named exactly |
redis_preview_bulk_delete |
preview | Counts the keys a pattern delete would remove, deleting nothing |
redis_apply_bulk_delete |
apply · destructive | Deletes the keys matching the previewed pattern |
redis_add_stream_entry |
write | Appends an entry to a stream, optionally trimming the stream as it does |
redis_ack_pending |
write | Acknowledges a consumer group's pending entries |
redis_claim_pending |
write | Moves a consumer group's pending entries to another consumer, by id or by idle time |
RabbitMQ
| Tool | Kind | What it does |
|---|---|---|
rabbitmq_get_cluster |
read | Version, nodes with their memory and disk, resource alarms, totals and rates, and the broker's health checks |
rabbitmq_list_queues |
read | Queues with their type, state, depth, consumers, rates and effective policy |
rabbitmq_get_queue |
read | One queue with its arguments and bindings and, for a quorum queue, each replica's state |
rabbitmq_peek_messages |
destructive | Reads up to 100 messages from the head of a queue and puts them back; they return marked redelivered and count against a quorum queue's delivery limit |
rabbitmq_read_stream |
read | Reads up to 100 messages of a stream from a chosen start; takes nothing away |
rabbitmq_list_exchanges |
read | Exchanges with their type, durability, arguments and effective policy |
rabbitmq_get_exchange |
read | One exchange, with the bindings it routes through and the bindings that feed it |
rabbitmq_trace_routing |
read | Which queues a message with a given routing key and headers would reach; publishes nothing |
rabbitmq_list_connections |
read | Live client connections |
rabbitmq_list_channels |
read | Live channels, with their unacknowledged messages and prefetch |
rabbitmq_list_consumers |
read | Consumers with the queue each reads, prefetch, ack mode and whether it is active |
rabbitmq_list_shovels |
read | Shovels with their live state and their definitions |
rabbitmq_list_federation |
read | Federation links with their status, and the upstreams they can pull from |
rabbitmq_list_policies |
read | User and operator policies; name a queue or exchange to see which policy governs it |
rabbitmq_list_vhosts |
read | Virtual hosts with their default queue type, tracing, deletion protection and depth |
rabbitmq_list_users |
read | Users with their tags and limits — never a password or hash. They are changed only in the console |
rabbitmq_list_permissions |
read | Permissions and topic permissions in each virtual host. They are changed only in the console |
rabbitmq_export_definitions |
read | The topology as a definitions document, with every password hash and credential removed |
rabbitmq_publish |
write | Publishes one message with publisher confirms, and says whether the broker confirmed it, returned it or refused it |
rabbitmq_purge_queue |
destructive | Discards every ready message of a queue |
rabbitmq_create_queue |
write | Declares a classic, quorum or stream queue |
rabbitmq_delete_queue |
destructive | Deletes a queue or stream with any messages it still holds |
rabbitmq_create_exchange |
write | Declares an exchange |
rabbitmq_delete_exchange |
destructive | Deletes an exchange and every binding from or to it |
rabbitmq_create_binding |
write | Binds a queue or an exchange to an exchange |
rabbitmq_delete_binding |
destructive | Removes one binding |
rabbitmq_restart_shovel |
write | Restarts a shovel from its definition, which stays unchanged |
Apache Artemis
| Tool | Kind | What it does |
|---|---|---|
artemis_get_broker |
read | The broker's overview, its mirroring and HA health, every broker attribute, and its acceptors |
artemis_list_addresses |
read | Addresses with their routing types, queue counts and sizes |
artemis_get_address |
read | One address, and the address settings that apply to it |
artemis_list_queues |
read | Queues with their address, routing type, filter, depth, consumers and whether each is paused |
artemis_get_queue |
read | One queue and its message counter; on request, the message groups pinned to a consumer |
artemis_browse_messages |
read | One page of a queue's messages — queued, scheduled or being delivered — consuming nothing |
artemis_list_clients |
read | The broker's connections, sessions, consumers or producers |
artemis_list_routing |
read | Diverts, bridges, broker connections and cluster connections |
artemis_list_transactions |
read | In-doubt transactions with the messages each holds. Resolving one stays in the console |
artemis_list_security |
read | Users with their roles, and the roles that apply to an address match. They are changed only in the console |
artemis_send |
write | Sends one text message to an address, with String properties |
artemis_purge_queue |
destructive | Removes every message of a queue |
artemis_pause_queue |
write | Pauses delivery from a queue to its consumers; the pause survives a restart |
artemis_resume_queue |
write | Resumes delivery from a paused queue |
Memcached
| Tool | Kind | What it does |
|---|---|---|
memcached_list_nodes |
read | Every node with its version, counters and effective settings, and the totals across them |
memcached_get_memory |
read | Each node's slab classes and its item-size histogram |
memcached_list_keys |
read | The keys one node holds, from a live walk of the node — approximate, and cut at the limit rather than paged |
memcached_get_key |
read | One item's value exactly as stored, with its size, flags, time to live and cas version |
memcached_set_key |
write | Stores one item — set, add, replace, append or prepend — optionally as a compare-and-swap |
memcached_delete_key |
destructive | Deletes one item from one node |
Operations
| Tool | Kind | What it does |
|---|---|---|
audit_query |
read | The audit trail, newest first, by time, actor, event, resource, connection, platform, result and channel. Alert events are left out, and the answer says how many |
access_review_roster |
read | Every account, with what makes one worth a second look |
access_review_user |
read | What one account can do, scope by scope, and what conferred each permission |
access_review_permission |
read | Everyone who holds one permission, where, and what conferred it |
applications_list |
read | The application catalogue |
applications_get |
read | One application, with the resources bound to it, its health and its dependencies |
metadata_lookup |
read | The metadata recorded for one resource: description, owning team, labels and classification |
saved_views_list |
read | The saved views the token's owner can see, without their definitions |
templates_list |
read | The message templates the token's owner can see, without their payloads |
monitoring_get_series |
read | One metric's current reading on a connection and the short window of readings behind it; nothing is stored |
Insights
| Tool | Kind | What it does |
|---|---|---|
insights_kafka_topics |
read | Topics that are empty, stale, at replication factor 1 or without an owner, and brokers whose partition share is skewed |
insights_kafka_groups |
read | Consumer groups that are idle, lag past a given figure, or read topics that no longer exist |
insights_rabbitmq_queues |
read | Queues with messages and no consumer, or with unacknowledged messages building up |
insights_redis_keys |
read | From a sample of the keyspace: the largest keys, and keys with no expiry |
insights_estate |
read | Connections whose last known health is not healthy |

