Available tools
|
The AIC Remote MCP Server is currently available in Rapid (Sandbox) environments only. Support for Development, UAT, Staging, and Production environments is rolling out over the coming weeks. |
The AIC Remote MCP Server exposes tools for administering your PingOne Advanced Identity Cloud environment through an AI client. You don’t need to know the individual tool names. Describe what you want in natural language and your AI agent selects the right tool automatically.
Every request must include the mandatory aic:mcp:access scope. Each category table below groups its tools by the additional scope required. For the full scope reference and per-tier request lists, refer to Scopes. Available tools also depend on your environment tier. Refer to Environments and access.
| Category | What you can do |
|---|---|
Create, query, update, and delete managed objects, object types, and custom relationships. |
|
List, create, update, delete, and set default themes. |
|
List log sources and query authentication and activity logs. |
|
Query, create, update, and delete environment variables and secrets. |
|
Inspect and install optional IDM and platform features. |
|
List, retrieve, create, update, and delete OIDC applications. |
|
Manage authentication journeys, node types, and Scripted Decision Node scripts. |
|
Inspect and configure AM services and social identity providers. |
|
Manage cross-origin resource sharing policies. |
|
Manage email templates, outbound email, password policies, and terms and conditions. |
|
Query, run, and author reports. |
Managed objects
Generic CRUD operations for any managed object type in your environment, plus administrative tools for managing object type definitions and custom relationship properties.
| Scope | Tool | Description |
|---|---|---|
|
|
Discover all managed object types in your environment. |
|
Get the schema definition for an object type. |
|
|
Query objects with filters, pagination, and sorting. |
|
|
Retrieve an object’s complete profile. |
|
|
|
Create a new managed object. |
|
Update object fields. |
|
|
Delete an object. |
|
|
Create a new managed object type definition. |
|
|
Modify an existing managed object type definition. |
|
|
Delete a managed object type definition. |
|
|
Add, update, or remove a custom relationship property. Custom relationships must use the |
Themes
Customize login and account page appearance.
| Scope | Tool | Description |
|---|---|---|
|
|
Get complete theme schema documentation. |
|
List all themes in a realm. |
|
|
Get a theme’s complete configuration. |
|
|
|
Create a new theme. |
|
Update theme properties. |
|
|
Delete a theme. |
|
|
Set a theme as the realm default. |
Logging
Query and analyze authentication and activity logs.
| Scope | Tool | Description |
|---|---|---|
|
|
List available log sources. |
|
Query logs with time range, source, and content filters. |
ESVs (Environment Secrets and Variables)
Manage environment variables used for configuration across your tenant.
| Scope | Tool | Description |
|---|---|---|
|
|
Query variables or secrets by ID pattern. |
|
Retrieve a variable with its decoded value. |
|
|
|
Create or update a variable. |
|
Delete a variable. |
Feature management
Inspect and enable optional IDM and platform features.
| Scope | Tool | Description |
|---|---|---|
|
|
List all features (IDM + AIC platform) and their install status. |
|
Check whether an IDM feature can be installed without making any changes. |
|
|
|
Install an IDM feature. Run |
|
|
Enable AI Agents on the tenant. Re-running is safe. |
Applications
Manage OIDC applications, plus cross-type lookups for any application (OIDC, SAML, PingOne, and others).
| Scope | Tool | Description |
|---|---|---|
|
|
List all applications in a realm regardless of type, with summary fields only. |
|
Retrieve a single application by name or ID, regardless of type. |
|
|
Get the OIDC application schema. |
|
|
List OIDC applications in a realm with summary fields. |
|
|
Retrieve a complete OIDC application configuration. |
|
|
|
Create a new OIDC application. |
|
Update an OIDC application. Partial updates. Send only changed fields. |
|
|
Delete an OIDC application. |
AM journeys, nodes, and scripts
Manage authentication journeys, node types, and Scripted Decision Node scripts.
| Scope | Tool | Description |
|---|---|---|
|
|
List all authentication journeys in a realm. |
|
Get a journey with node schemas and configs automatically included. |
|
|
Generate a preview URL to test a journey in a browser. |
|
|
Export a journey with its nodes, inner trees, SAML entities, circles of trust, and themes. |
|
|
Discover all available authentication node types. |
|
|
Get the schema, template, and outcomes for a node type. |
|
|
Calculate outcomes for a node based on its configuration. |
|
|
List Scripted Decision Node scripts in a realm. |
|
|
Get an AM script with automatic base64 decoding. |
|
|
Get available bindings and allowed imports for scripting. |
|
|
|
Create or replace an authentication journey atomically. |
|
Update an existing journey’s metadata and node graph. |
|
|
Delete a journey and its associated nodes. |
|
|
Set the default authentication journey for a realm. |
|
|
Update a single node’s configuration. |
|
|
Batch delete orphaned node instances. |
|
|
Create a new Scripted Decision Node script. |
|
|
Update an existing script’s name, description, or content. |
|
|
Delete an AM script. |
AM services and identity providers
Manage AM services and social/third-party identity providers.
| Scope | Tool | Description |
|---|---|---|
|
|
List AM services (configured or all/creatable types) in a realm. |
|
Retrieve the full configuration of a single AM service. |
|
|
Return the JSON Schema for a configurable AM service type. |
|
|
List configured social/third-party identity providers, or discover IdP sub-types. |
|
|
Retrieve the full configuration of a single social/third-party identity provider. |
|
|
|
Create or update an AM service configuration (upsert, partial payloads). |
|
Permanently delete an AM service configuration. |
|
|
Create or update a social/third-party OIDC identity provider. |
|
|
Permanently remove a social/third-party identity provider. |
CORS policies
Manage cross-origin resource sharing policies for AM.
| Scope | Tool | Description |
|---|---|---|
|
|
List all CORS policies configured in PingOne Advanced Identity Cloud. |
|
Retrieve a single CORS policy by ID. |
|
|
|
Create a new CORS policy. |
|
Update an existing CORS policy (full replacement). |
|
|
Permanently delete a CORS policy. |
Policy and notifications
Manage email templates, outbound email provider config, password policy, and terms and conditions.
| Scope | Tool | Description |
|---|---|---|
|
|
List all end-user email templates. |
|
Read the current terms and conditions configuration. |
|
|
|
Create a new end-user email template. |
|
Update an existing email template (full replacement). |
|
|
Create or update the tenant outbound email provider (SMTP config, singleton). |
|
|
Add and activate a new terms and conditions version. |
|
|
|
Retrieve the password policy for a managed object type. |
|
|
Update the password policy for a managed object type. |
Reporting
Query, run, and author PingOne Advanced Identity Cloud reports. Includes out-of-the-box (OOTB) reports every tenant has, plus custom reports built through the Advanced Reporting add-on.
|
Reporting tools are available in all environment tiers, including UAT, Staging, and Production. This lets administrators author and run reports in upper environments even when write tools are otherwise restricted. |
| Scope | Tool | Description |
|---|---|---|
|
|
List available OOTB and custom report templates. |
|
Get a single report’s parameters and fields by name. |
|
|
Run a published report with parameters, polling briefly for completion. |
|
|
Fetch paginated results for a report run by jobId. |
|
|
Export a completed report run’s results as CSV or JSON Lines. |
|
|
Export a custom report template definition as JSON. |
|
|
|
Copy an existing report (OOTB or custom) into a new draft. |
|
Author and auto-publish a custom report. Requires the Advanced Reporting add-on. |
|
|
Import a previously exported custom report template. |