Skip to main content
Connect your Pulumi account to let Alex (Cloud Engineer) inspect stacks, search the resources Pulumi manages, review policy violations, and look up Registry schemas through Pulumi’s hosted MCP server. Pulumi uses OAuth, so you never paste a Pulumi access token into CloudThinker.

Prerequisites

  • A Pulumi Cloud account that belongs to the organization you want CloudThinker to inspect.
  • Permission to authorize CloudThinker through Pulumi’s OAuth flow.
The tools read the organization your Pulumi account defaults to. Authorize with the account that belongs to the organization holding the stacks you care about, or the agent reports an empty inventory.

Setup

1

Open CloudThinker

Go to Connections → Pulumi in your workspace.
2

Start the OAuth flow

Click Connect to open Pulumi’s authorization page.
3

Authorize CloudThinker

Sign in to the Pulumi account that can see the stacks you want, then approve access.
4

Return to CloudThinker

CloudThinker stores the OAuth tokens and the connection shows a Connected status.

Connection details

Pulumi uses OAuth, so there are no fields to fill in. CloudThinker stores the tokens automatically once the authorization completes.

Required permissions

CloudThinker inherits the Pulumi access granted during OAuth.
  • Read operations cover stacks, managed resources, policy violations, organization members, Neo task history, and Registry schemas.
  • Deployments and Pulumi Neo need matching Pulumi access and explicit approval in CloudThinker, because both change cloud resources.
Authorize with an account that reads the organization rather than one that administers it. Read access covers every capability below except the two that already ask you first.

Agent capabilities

Once connected, Alex can:

Verify the connection

Example prompts

Approval-gated tools

Four Pulumi tools change real state, so CloudThinker asks before each call: deploy to AWS, and the three tools that drive Pulumi Neo (bridge, continue a task, reset a conversation). The agent names the stack and the effect, then waits for your answer. Everything else on this connection reads. Reading a stack never triggers a prompt, so an inventory or policy question completes in one turn.
Approve a deployment only when you recognize the stack in the prompt. A Pulumi deployment provisions real cloud resources and bills your cloud account.

Troubleshooting

Your browser may be signed in to a different Pulumi account. Sign in to the intended account at app.pulumi.com, then retry Connect in CloudThinker.
Pulumi answers for the organization your account defaults to. Confirm that account is a member of the organization holding the stacks, then reconnect with the right account.
The token reaches only the organizations your Pulumi user belongs to. Add the user to the organization in Pulumi, or reconnect with an account that already belongs to it.
That is the approval gate, and it is per call. Answer the prompt in the conversation. See Approval for how CloudThinker handles gated tools.
CloudThinker exposes a reviewed list of Pulumi tools. A tool Pulumi releases later stays hidden until CloudThinker reviews it and decides whether it needs approval.

Security

  • Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
  • Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
  • Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
  • Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
  • Keep the gate on — leave deployment and Pulumi Neo approval-gated; they are the only tools here that can change your cloud.
  • Reconnect deliberately — the connection reaches whatever the authorizing account reaches, so switch accounts by removing the connection and authorizing again.

Alex Agent

Cloud infrastructure and cost analysis

Approval

How CloudThinker gates tools that change state