An MCP server for managing RosettaHUB user AWS cloud accounts
RosettaHUB is a platform used by educators to provision and manage user AWS cloud environments. This MCP server wraps the RosettaHUB SOAP API into 16 tools and 2 resources, letting AI assistants like Claude manage user accounts through natural language.
Example: "Show me which users have used over 80% of their budget" or "Run
aws ec2 describe-instancesacross all user accounts"
pip install rosettahub-mcp-serverexport RH_API_KEY="your-rosettahub-api-key"
export RH_ORG="Your-Org-Name"Add to claude_desktop_config.json:
{
"mcpServers": {
"rosettahub": {
"command": "uvx",
"args": ["rosettahub-mcp-server"],
"env": {
"RH_API_KEY": "your-api-key",
"RH_ORG": "Your-Org-Name"
}
}
}
}claude mcp add rosettahub -e RH_API_KEY=your-key -e RH_ORG=Your-Org -- rosettahub-mcp-server| Tool | Description |
|---|---|
test_connection |
Test the API connection and return authenticated user info |
list_accounts |
List your own RosettaHUB cloud accounts |
list_user_accounts |
List all user accounts with budget details |
list_users |
List all federated users in the organization |
list_api_methods |
List all available RosettaHUB SOAP API methods |
| Tool | Description |
|---|---|
aws_exec |
Run an AWS CLI command across all user accounts |
aws_exec_user |
Run an AWS CLI command on one user's account |
ec2_list |
List EC2 instances across all user accounts |
get_sts_credentials |
Get temporary AWS STS credentials for a user |
get_console_url |
Get a sign-in URL for a user's AWS Console |
| Tool | Description |
|---|---|
budget_status |
Show budget, spending, and remaining balance for all users |
budget_transfer |
Transfer budget to all user accounts |
budget_transfer_user |
Transfer budget to one user's account |
| Tool | Description |
|---|---|
quarantine_user |
Quarantine a user (restrict cloud access) |
unquarantine_user |
Unquarantine a user (restore cloud access) |
set_allowed_regions |
Set which AWS regions a user can use |
| URI | Description |
|---|---|
rosettahub://users |
JSON list of current user logins |
rosettahub://budget-summary |
JSON budget data for all users |
| Environment Variable | Required | Default | Description |
|---|---|---|---|
RH_API_KEY |
Yes | — | Your RosettaHUB API key |
RH_ORG |
Yes | — | Your RosettaHUB organization name |
RH_AWS_REGION |
No | eu-west-1 |
Default AWS region for commands |
RH_WSDL_URL |
No | RosettaHUB public API | Override WSDL endpoint URL |
-
Command validation — All AWS commands must start with
awsto prevent arbitrary execution - Region validation — Region parameters are validated against AWS format to prevent flag injection
-
No shell injection — Commands run with
shell=Falseusingshlex.split() - Subprocess timeout — AWS CLI calls are capped at 60 seconds to prevent hung processes
- Minimal subprocess environment — Only AWS credentials and PATH are passed to child processes
- Temporary credentials — AWS access uses short-lived STS sessions (1 hour default), never long-term keys
- Logging to stderr — stdout is reserved for MCP JSON-RPC transport
src/rosettahub_mcp_server/
├── server.py # FastMCP instance and entry point
├── config.py # Environment variable loading
├── client.py # Singleton SOAP client (zeep)
├── types.py # TypedDict return types
├── tools/
│ ├── account_tools.py # 5 account/API info tools
│ ├── aws_tools.py # 5 AWS execution tools
│ ├── budget_tools.py # 3 budget tools
│ └── user_mgmt_tools.py # 3 access control tools
└── resources/
└── user_resources.py # 2 MCP resources
git clone https://github.com/danielcregg/rosettahub-mcp-server.git
cd rosettahub-mcp-server
pip install -e ".[dev]"pytest -vAll tests use mocked SOAP responses — no API key needed.
ruff check src/ tests/
mypy src/ --ignore-missing-importsexport RH_API_KEY="your-key"
export RH_ORG="Your-Org"
rosettahub-mcp-serverThis is an unofficial, community-maintained integration. It is not affiliated with, endorsed by, or sponsored by RosettaHUB. "RosettaHUB" is a trademark of its respective owner.
MIT — see LICENSE for details.