Services → Coolify
Connect Coolify
Inventory, status and logs from a Coolify instance. Coolify's own token abilities do the enforcing, which is what makes this the cleanest Tier 1.
Setting this up with your own agent? Give it these instructions.
Why this one is the clean example
Coolify tokens carry granular abilities — read, write, deploy, root — plus a
separate read-sensitive flag. A token created with read only, and read-sensitive
off, *physically cannot* write and cannot return environment values. Prodpeek's
allowlist and the credential refuse the same things independently, without either
knowing about the other. That is what Tier 1 means here.
Steps
- In Coolify: Keys & Tokens → API tokens → Create new token.
- Name it
prodpeek. - Tick read. Leave write, deploy and root unticked.
- Leave read-sensitive off. This is the field that matters most.
- Copy the token — Coolify shows it once.
- Enable the MCP endpoint if you have not: Settings → Advanced → MCP. The URL is your instance plus
/mcp. - In Prodpeek: Services → Add a service → Coolify, paste the token, then Test connection.
What Test connection should show
Your Coolify version decides the tool names, and they have moved between releases.
Anything advertised that the profile does not name lands in not in the policy
and is denied by default. That is safe, but it also means a read you wanted might be
missing — send the list along and the profile can be corrected.
Screenshots
Screenshot pending — the steps above stand on their own.
Screenshot pending — the steps above stand on their own.