Connect Claude to leancosts
leancosts runs an MCP server, so an AI client can read your workspace and help you connect a cloud account without you filling in forms. Add it once as a custom connector and approve the request: there is no token to copy.
1. Add the connector
Section titled “1. Add the connector”In Claude (Desktop, claude.ai, Cowork or mobile): Settings → Connectors → Add custom connector, and paste:
https://api.leancosts.com/api/mcpThe leancosts app shows the same URL, ready to copy, at the bottom of the Copilot page: along with the Claude Code command below.
Claude discovers the rest on its own and opens a leancosts page in your browser.
2. Approve the request
Section titled “2. Approve the request”Sign in if you are not already, then check what the page tells you:
- which client is asking (its name comes from the client itself),
- which workspace the connection will be pinned to: pick one if you belong to more than one,
- what it will be able to do.
Click Approve. Claude returns to the conversation, connected.
3. Use it
Section titled “3. Use it”Ask in plain language:
- “Using leancosts, what’s connected and what’s still missing?”
- “Help me connect our AWS account.”
- “How much did we spend last month, by service?”
- “Why did the bill move between June and July?”
- “Which reservations are underutilised?”
For connecting a cloud, Claude can fetch the exact read-only role or policy definition with your account’s values already filled in, and run it with your credentials on your machine. leancosts never writes to your cloud; that posture is unchanged here.
For questions about your spend, Claude turns what you asked into a structured query, and leancosts answers it with the rows and the audit trace, the filters applied and the query that produced them, in US dollars. Figures come out of your ingested billing data or not at all: there is no path for Claude to pass free text into the query layer, so it cannot round a number up or fill a gap with a plausible one. Ask it to show you the trace whenever a figure matters.
Claude can also run a check leancosts does not ship a detector for (your own rule, across your estate) and file what it finds as a change request your team approves and the ledger measures. See Detect your own patterns.
What the connection can and can’t do
Section titled “What the connection can and can’t do”- It acts as you, with your own permissions. It cannot do anything you cannot already do in the app.
- It reaches the leancosts MCP endpoint and nothing else: approving a connector does not hand over your API access.
- It stops working the moment you lose access to that workspace, or your account is deactivated.
- Nothing is stored that could be replayed: only a hash of the credential is kept.
Disconnect
Section titled “Disconnect”User menu → Settings → Tokens → Connected apps → Disconnect. It takes effect on the client’s next request.
Removing the connector in Claude also works: the client hands the grant back itself, so nothing is left live on our side. Deactivating the account, or removing it from the workspace, revokes every grant it approved without anyone clicking anything.
Troubleshooting
Section titled “Troubleshooting”“You can’t approve this.” The request asked for global-admin access and your account is not a leancosts global admin, or your account does not belong to a workspace yet. Ask an admin in your workspace to activate you.
“This connection request is no longer valid.” Approval requests are short- lived. Start again from the connector in Claude.
The connector never opens a browser page. Custom connectors are brokered
from Anthropic’s cloud, so the URL must be reachable from the public internet.
https://api.leancosts.com/api/mcp is, but a corporate proxy that rewrites the
URL will break discovery. Paste it exactly as shown.
Using Claude Code instead
Section titled “Using Claude Code instead”Claude Code can send a header, so it can use a Personal Access Token directly: see Use the API with a token. The token screen prints this command with your new token already in it, so copying it there beats retyping it here:
claude mcp add --transport http leancosts \ https://api.leancosts.com/api/mcp \ --header "Authorization: Bearer <your PAT>"