Read-only MCP server for MuleSoft Anypoint: app logs, archive search, Runtime Manager, Exchange.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Read-only observability for MuleSoft Anypoint Platform, over MCP.
Application logs, historical archive search, Runtime Manager, API Manager and Exchange β for any Anypoint customer, using their own credentials.
mulewatch bridges an MCP client β Claude Desktop, Claude Code, Cursor, OpenClaw β to MuleSoft Anypoint Platform, so you can ask about a Mule estate in plain language and get real answers from the platform APIs. It is aimed at the person holding the pager, not the person writing the flow: no local Mule project is required, and every tool is read-only.
Nothing is hardcoded to one customer: business groups, environments and credentials all come from your own connected app.
MuleSoft publishes its own MCP server (mulesoft-mcp-server, docs). It is a development tool β it scaffolds Mule projects, generates flows and API specs, and deploys applications, largely from a local project in an IDE.
mulewatch is an operations tool. It never writes to your estate, it assumes no local project, and it covers the one area the official server does not address at all: retrieving and searching application logs, including historical logs from the Monitoring Archive. The two run happily side by side, and if you want deployment or scaffolding tools, use the official one.
Grant the scopes for the surfaces you intend to use, on the business groups and environments you care about. Anypoint returns a bare 403 Forbidden when a scope is missing; mulewatch catches that and names the scope you probably need.
| Surface | Scope |
|---|---|
| Environments, business groups | View Environments, View Organization |
| Runtime Manager apps and logs | Read Applications |
| Historical archive search | Anypoint Monitoring Viewer |
| API Manager instances | View APIs Configuration |
| Exchange assets | Exchange viewer access |
Create a connected app in Anypoint Platform β Access Management β Connected Apps, choose "App acts on its own behalf (client credentials)", grant the scopes above, and copy the client id and secret.
Configuration is environment variables only β there is no config file and no organization default.
| Variable | Required | Purpose |
|---|---|---|
ANYPOINT_CLIENT_ID / ANYPOINT_CLIENT_SECRET | one auth method | Connected app client credentials, preferred for automation |
ANYPOINT_USERNAME / ANYPOINT_PASSWORD | one auth method | Platform login |
ANYPOINT_ACCESS_TOKEN | one auth method | Pre-generated bearer token; takes precedence over the other two |
ANYPOINT_ORG_ID | no | Business group id. Unset means "the organization the credentials belong to" |
ANYPOINT_ALLOWED_ENVIRONMENTS | no | Comma-separated environment names or ids; when set, every tool refuses anything outside the list |
ANYPOINT_BASE_URL | no | Control plane host, defaults to https://anypoint.mulesoft.com |
ANYPOINT_MONITORING_BASE_URL | no | Monitoring host, defaults to https://monitoring.anypoint.mulesoft.com |
Environments live on business groups, not on the root organization. If anypoint_list_environments comes back empty, your credentials resolved to the root org β call anypoint_list_business_groups to list the ids, then pass one as orgId or pin it with ANYPOINT_ORG_ID.
ANYPOINT_ALLOWED_ENVIRONMENTS scopes the whole server, not one tool. With
every tool refuses an environment outside the list and says why, whichever business group is targeted. Combine it with a connected app that only has access to those environments for defence in depth.
Nothing to install β point your MCP client at npx:
That block works as-is in Claude Desktop (claude_desktop_config.json), Cursor (.cursor/mcp.json) and OpenClaw. For Claude Code:
From a clone instead:
The server speaks stdio, which is what MCP clients expect. Start with anypoint_whoami to confirm credentials, business group and scope before anything else.
Every tool is read-only. All of them accept orgId to override the configured business group.
anypoint_whoamiConfirms which credentials, business group, hosts and environment allowlist the server is running with. No arguments. Call this first when anything fails.
anypoint_list_business_groupsLists the business groups beneath the credentials' organization, with ids and nesting depth.
anypoint_list_environmentsLists environments for a business group, filtered by ANYPOINT_ALLOWED_ENVIRONMENTS when set.
anypoint_list_deployed_appsLists deployed Mule applications for an environment, by environmentId or environmentName.
| Option | Purpose |
|---|---|
target | application_manager (default), cloudhub, hybrid, or all |
limit | Maximum records to return, default 100 |
includeRaw | Include raw API objects in the response |
includeErrors | Include per-target errors when a target endpoint is unavailable or not permitted |
application_manager covers CloudHub 2.0 and Runtime Fabric deployments, cloudhub legacy CloudHub, hybrid on-prem Runtime Manager. all queries every target and reports per-target failures instead of aborting.
anypoint_list_app_logsLists the latest Runtime Manager logs for an application.
| Option | Purpose |
|---|---|
environmentId | Use instead of environmentName |
deploymentId | Use when the app name is ambiguous or already known |
specId | A specific Application Manager deployment spec/config id |
target | auto (default), application_manager, or cloudhub |
limit | Maximum log entries, default 100, max 500 |
offset | Application Manager log offset, default 0 |
descending | Latest first, default true |
startTime / endTime | Application Manager time filter, ISO 8601 |
includeRaw | Include the raw API response |
includeErrors | Include failed target errors when target is auto |
For CloudHub 2.0 and Runtime Fabric the tool resolves appName to a deployment, resolves the current spec, then reads that spec's logs. For legacy CloudHub it calls the CloudHub logs endpoint directly.
anypoint_get_app_logs_for_analysisSame sources as above, but returns an analysis-ready payload rather than a raw list. Prefer it when diagnosing something.
Takes every option of anypoint_list_app_logs, plus:
| Option | Purpose |
|---|---|
searchTerms | Case-insensitive filters matched against timestamp, priority, message, logger, thread or instance |
errorOnly | Only return ERROR and FATAL lines |
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/mulewatch)<a href="https://allmcps.com/mcp/mulewatch"><img src="https://allmcps.com/api/badge/mulewatch?style=directory" alt="Mulewatch on AllMCPs" /></a>