Home / Token cost / Appaloft

The Appaloft MCP server costs 59,762 tokens before the first call.

Every request your agent makes carries every tool definition this server exposes — context your code, documents and conversation can't use, mostly for tools the agent never calls. You don't need them all in the window, and you don't have to pay for them.

QUICK ANSWER The Appaloft MCP server's 358 tool definitions consume 59,762 tokens — 30% of a 200k context window, and 28× the median MCP server (2,143 tokens). A scoped grant exposing only the tools you use cuts that roughly in proportion.

MEASURED FROM SCHEMAS tiktoken o200k_base · rank #17 of 5,416 measured servers · refreshed every build Method →

What that costs before your agent starts working.

Tool definitions are overhead: they occupy context on every request and compete with your code, documents and conversation history for the same window.

200K WINDOW 30%
1M WINDOW 6.0%

Corpus context: Appaloft ranks #17 of 5,416 measured MCP servers by definition cost. The median is 2,143 tokens, p90 is 11,749, and the heaviest (Ainumbers Mcp Apps) is 170,419 — 85% of a 200k window on its own. New to this? See MCP token cost and context window in the glossary.

Where the 59,762 tokens go.

Each row is one tool definition as a tools/list entry — name, description and input schema — counted with o200k_base. Average: 167 tokens per tool.

ToolCategoryTokens% of server
runtime_monitoring_rollup Read 3,242 5.4%
runtime_monitoring_samples_list Read 2,870 4.8%
runtime_monitoring_thresholds_show Read 2,776 4.6%
runtime_usage_inspect Read 1,475 2.5%
resources_create Write 1,249 2.1%
resources_health_history Read 883 1.5%
sandboxes_create Write 734 1.2%
dependency_resources_provisioning_plan Write 673 1.1%
audit_events_export_global Write 655 1.1%
resources_configure_runtime Write 617 1.0%
resources_configure_source Write 613 1.0%
storage_volumes_backup_policies_configure Write 592 1.0%
blueprints_install Write 495 0.8%
sandbox_templates_create Write 485 0.8%
audit_events_archives_create Write 482 0.8%
audit_events_legal_holds_configure Write 468 0.8%
audit_events_archives_list Read 465 0.8%
storage_volumes_create_backup Write 455 0.8%
audit_events_export Write 450 0.8%
runtime_monitoring_thresholds_configure Write 440 0.7%
storage_volumes_backup_plan Write 439 0.7%
blueprints_plan_install Write 375 0.6%
servers_capacity_prune Execute 342 0.6%
resources_configure_health Write 334 0.6%
dependency_resources_import Write 328 0.5%
source_events_ingest Execute 324 0.5%
dependency_resources_provision Execute 315 0.5%
environments_duplicate_profile Execute 313 0.5%
connections_capability_accept Execute 312 0.5%
servers_test_draft_connectivity Read 310 0.5%
source_events_prune Execute 309 0.5%
servers_test_connectivity Read 308 0.5%
domain_events_prune Execute 305 0.5%
entitlements_query Read 304 0.5%
connections_connect_start Write 304 0.5%
domain_bindings_create Write 304 0.5%
domain_bindings_dns_readiness_inspect Read 298 0.5%
storage_volumes_cleanup_runtime Execute 297 0.5%
resources_runtime_log_archives_prune Execute 295 0.5%
preview_policies_configure Write 295 0.5%
resources_configure_auto_deploy Write 295 0.5%
provider_job_logs_prune Execute 292 0.5%
sandbox_ports_expose Execute 291 0.5%
resources_runtime_control_attempts_prune Execute 284 0.5%
terminal_sessions_expire Execute 280 0.5%
deployments_prune Execute 276 0.5%
sandbox_snapshots_create Write 273 0.5%
operator_work_prune Execute 271 0.5%
audit_events_archives_prune Execute 269 0.5%
terminal_sessions_open Write 268 0.4%
audit_events_prune Execute 265 0.4%
sandboxes_network_policy_configure Write 264 0.4%
deploy_tokens_create Execute 249 0.4%
deployments_timeline_stream Read 246 0.4%
sandboxes_promotions_plan Write 236 0.4%
scheduled_runtime_prune_policies_configure Write 233 0.4%
resources_diagnostic_summary Read 226 0.4%
sandboxes_agents_runs_create Write 222 0.4%
servers_configure_credential Write 222 0.4%
capabilities_query Read 217 0.4%
deployments_show Read 204 0.3%
operator_work_stream_events Read 197 0.3%
static_artifacts_publish_payload Write 194 0.3%
dependency_resources_backup_policies_configure Write 193 0.3%
deployments_count Read 191 0.3%
retention_defaults_configure Write 191 0.3%
connections_connect_callback Write 190 0.3%
scheduled_tasks_create Write 187 0.3%
auth_bootstrap_first_admin Execute 185 0.3%
deployments_cleanup_preview Execute 185 0.3%
source_links_relink Execute 181 0.3%
connections_capability_apply Write 181 0.3%
scheduled_tasks_configure Write 181 0.3%
sandbox_credentials_request Execute 180 0.3%
resources_configure_network Write 179 0.3%
deployments_plan Write 178 0.3%
default_access_domain_policies_configure Write 177 0.3%
domain_bindings_dns_plan Write 174 0.3%
operator_work_list Read 172 0.3%
preview_environments_list Read 171 0.3%
organizations_invite_member Write 171 0.3%
credentials_rotate_ssh Execute 170 0.3%
sandbox_credentials_grant Execute 170 0.3%
resources_health Read 170 0.3%
storage_volumes_create Write 162 0.3%
resources_runtime_logs Read 159 0.3%
deployments_timeline Read 158 0.3%
environments_set_variable Write 155 0.3%
sandboxes_exec Execute 153 0.3%
servers_register Write 152 0.3%
connections_list Read 148 0.2%
certificates_issue_or_renew Write 148 0.2%
resources_attach_storage Write 147 0.2%
sandboxes_agents_runtimes_create Write 146 0.2%
organizations_profile_change Execute 145 0.2%
resources_show Read 145 0.2%
preview_policies_show Read 144 0.2%
static_artifacts_publish_archive Write 142 0.2%
deployments_force_redeploy Destructive 140 0.2%
deployments_create Write 139 0.2%
deployments_redeploy Execute 138 0.2%
resources_bind_dependency Execute 137 0.2%
resources_runtime_logs_archive Write 137 0.2%
deployments_recovery_readiness Read 134 0.2%
static_artifacts_publish Write 134 0.2%
source_events_list Read 133 0.2%
resources_import_variables Write 133 0.2%
resources_set_variable Write 133 0.2%
connections_capability_plan Write 132 0.2%
domain_bindings_confirm_ownership Execute 131 0.2%
dependency_resources_restore_backup Write 131 0.2%
domain_bindings_configure_route Write 131 0.2%
deploy_tokens_revoke Execute 129 0.2%
deployments_reconcile_stale Execute 129 0.2%
deployments_list Read 128 0.2%
certificates_import Write 128 0.2%
scheduled_task_runs_list Read 127 0.2%
retention_defaults_list Read 125 0.2%
resources_proxy_configuration_preview Read 124 0.2%
resources_rotate_dependency_binding_secret Execute 123 0.2%
resources_runtime_log_archives_list Read 123 0.2%
storage_volumes_restore_backup Write 123 0.2%
sandboxes_promotions_accept Execute 122 0.2%
terminal_sessions_list Read 122 0.2%
resources_list Read 121 0.2%
control_plane_portability_import Write 118 0.2%
retention_defaults_show Read 117 0.2%
deploy_tokens_rotate Execute 116 0.2%
environments_unset_variable Execute 116 0.2%
audit_events_legal_holds_list Read 115 0.2%
scheduled_tasks_list Read 115 0.2%
deploy_tokens_list Execute 113 0.2%
resources_runtime_restart Execute 113 0.2%
resources_runtime_start Execute 113 0.2%
dependency_resources_query Read 113 0.2%
deployments_stale_attempts Read 111 0.2%
resources_configure_access Write 111 0.2%
organizations_change_member_role Execute 110 0.2%
servers_bootstrap_proxy Execute 110 0.2%
credentials_create_ssh Write 110 0.2%
sandboxes_agents_runs_events_stream Read 109 0.2%
scheduled_task_runs_logs Read 109 0.2%
storage_volumes_restore_plan Write 108 0.2%
deployments_rollback Execute 107 0.2%
sandboxes_agents_runs_events Read 107 0.2%
control_plane_portability_import_plan Write 107 0.2%
domain_bindings_delete Destructive 106 0.2%
organizations_list_invitations Read 106 0.2%
sandboxes_events_stream Read 106 0.2%
resources_secrets_rotate Execute 105 0.2%
organizations_transfer_owner Financial 105 0.2%
dependency_resources_list Read 105 0.2%
environments_diff_profile Read 105 0.2%
resources_secrets_create Write 105 0.2%
sandbox_files_write Write 105 0.2%
environments_create Write 104 0.2%
tunnels_start Execute 103 0.2%
credentials_delete_ssh Destructive 102 0.2%
environments_promote Write 102 0.2%
environments_sync_profile Execute 101 0.2%
resources_runtime_stop Execute 101 0.2%
scheduled_tasks_run_now Execute 101 0.2%
scheduled_runtime_prune_policies_list Read 100 0.2%
environments_plan_duplicate Write 100 0.2%
source_events_replay Execute 99 0.2%
sandbox_credentials_list Read 99 0.2%
projects_delete Destructive 98 0.2%
resources_delete Destructive 98 0.2%
servers_delete Destructive 98 0.2%
resources_access_failure_evidence_lookup Read 98 0.2%
sandboxes_agents_runtimes_terminate Write 98 0.2%
environments_clone Execute 97 0.2%
organizations_delete Destructive 96 0.2%
sandboxes_agents_runtimes_show Read 96 0.2%
servers_configure_edge_proxy Write 96 0.2%
certificates_delete Destructive 95 0.2%
sandboxes_promotions_retry Execute 95 0.2%
source_links_list Read 94 0.2%
sandboxes_source_artifacts_create Write 94 0.2%
sandbox_files_remove Destructive 93 0.2%
sandboxes_agents_runs_cancel Destructive 93 0.2%
projects_reorder Execute 93 0.2%
servers_reorder Execute 93 0.2%
projects_list Read 93 0.2%
sandboxes_agents_runs_show Read 93 0.2%
sandboxes_agents_approvals_resolve Write 93 0.2%
resources_secrets_delete Destructive 92 0.2%
sandbox_ports_revoke Destructive 92 0.2%
account_profile_change Execute 92 0.2%
audit_events_legal_holds_release Execute 92 0.2%
resources_secrets_show Read 92 0.2%
servers_list Read 92 0.2%
resources_unset_variable Execute 91 0.2%
sandbox_processes_terminate Write 91 0.2%
dependency_resources_count Read 90 0.2%
system_control_plane_secret_rotation_apply Write 90 0.2%
audit_events_list Read 89 0.1%
dependency_resources_backup_policies_list Read 89 0.1%
sandbox_processes_show Read 89 0.1%
sandbox_credentials_revoke Destructive 88 0.1%
organizations_reactivate_member Execute 88 0.1%
scheduled_tasks_delete Destructive 87 0.1%
deployments_retry Execute 87 0.1%
static_artifacts_publications_list Read 87 0.1%
deployments_cancel Destructive 86 0.1%
organizations_remove_member Destructive 86 0.1%
sandbox_files_list Read 86 0.1%
sandbox_files_read Read 86 0.1%
dependency_resources_create_backup Write 86 0.1%
preview_environments_show Read 85 0.1%
servers_show Read 85 0.1%
resources_archive Write 85 0.1%
certificates_revoke Destructive 84 0.1%
credentials_show Read 84 0.1%
scheduled_task_runs_show Read 84 0.1%
storage_volumes_list_backups Read 84 0.1%
organizations_list_members Read 83 0.1%
source_events_show Read 83 0.1%
servers_rename Write 83 0.1%
dependency_resources_provisioning_accept Execute 82 0.1%
servers_deactivate Execute 82 0.1%
account_delete Destructive 81 0.1%
deployments_archive Write 81 0.1%
dependency_resources_list_backups Read 80 0.1%
sandbox_snapshots_list Read 80 0.1%
domain_bindings_retry_verification Execute 79 0.1%
domain_bindings_list Read 79 0.1%
resources_secrets_list Read 79 0.1%
dependency_resources_rotate_connection Execute 78 0.1%
sandbox_templates_list Read 78 0.1%
servers_prepare_runtime Execute 77 0.1%
sandboxes_list Read 77 0.1%
preview_environments_delete Destructive 76 0.1%
default_access_domain_policies_show Read 76 0.1%
sandboxes_agents_approvals_list Read 76 0.1%
sandboxes_agents_approvals_show Read 76 0.1%
sandboxes_agents_runtimes_list Read 76 0.1%
certificates_retry Execute 75 0.1%
resources_unbind_dependency Execute 75 0.1%
resources_show_dependency_binding Read 75 0.1%
storage_volumes_rename Write 75 0.1%
sandboxes_candidate_previews_delete Destructive 74 0.1%
connections_catalog_list Read 74 0.1%
sandboxes_candidate_previews_show Read 74 0.1%
dependency_resources_rename Write 74 0.1%
sandboxes_candidate_previews_create Write 74 0.1%
dependency_resources_delete Destructive 73 0.1%
sandboxes_source_artifacts_delete Destructive 73 0.1%
deploy_tokens_show Execute 73 0.1%
resources_detach_storage Execute 73 0.1%
environments_diff Read 73 0.1%
sandboxes_agents_runs_list Read 73 0.1%
sandboxes_source_artifacts_list Read 73 0.1%
sandboxes_source_artifacts_show Read 73 0.1%
operator_work_dead_letter Execute 72 0.1%
environments_archive Write 72 0.1%
environments_lock Write 72 0.1%
operator_work_mark_recovered Write 72 0.1%
projects_create Write 72 0.1%
account_sessions_revoke Destructive 71 0.1%
audit_events_show Read 71 0.1%
sandboxes_promotions_list Read 71 0.1%
sandboxes_promotions_show Read 71 0.1%
organizations_switch_current Write 71 0.1%
projects_archive Write 71 0.1%
operator_work_cancel Destructive 70 0.1%
sandbox_snapshots_delete Destructive 70 0.1%
deployments_proof Read 70 0.1%
sandbox_snapshots_show Read 70 0.1%
scheduled_tasks_show Read 70 0.1%
environments_rename Write 70 0.1%
sandbox_processes_list Read 69 0.1%
projects_rename Write 69 0.1%
sandboxes_terminate Write 69 0.1%
sandbox_templates_delete Destructive 68 0.1%
source_links_delete Destructive 68 0.1%
operator_work_retry Execute 68 0.1%
sandbox_ports_list Read 68 0.1%
sandbox_templates_show Read 68 0.1%
sandboxes_pause Execute 67 0.1%
sandboxes_show Read 67 0.1%
control_plane_portability_export Write 67 0.1%
sandboxes_resume Write 67 0.1%
blueprints_installation_show Read 66 0.1%
resources_effective_config Read 66 0.1%
storage_volumes_backup_policies_show Read 66 0.1%
system_instance_upgrade_apply Write 66 0.1%
control_plane_portability_artifacts_delete Destructive 65 0.1%
storage_volumes_prune_backups Execute 65 0.1%
audit_events_legal_holds_show Read 65 0.1%
control_plane_portability_artifacts_show Read 65 0.1%
dependency_resources_backup_policies_show Read 65 0.1%
scheduled_runtime_prune_policies_show Read 65 0.1%
storage_volumes_list Read 65 0.1%
dependency_resources_provisioning_status Read 64 0.1%
domain_bindings_delete_check Destructive 63 0.1%
resources_runtime_log_archives_show Read 63 0.1%
projects_set_description Write 63 0.1%
connections_revoke Destructive 62 0.1%
connections_status_show Read 62 0.1%
environments_effective_precedence Read 62 0.1%
resources_list_dependency_bindings Read 62 0.1%
storage_volumes_show_backup Read 62 0.1%
storage_volumes_delete Destructive 61 0.1%
audit_events_archives_show Read 61 0.1%
certificates_list Read 61 0.1%
dependency_resources_inspect Read 61 0.1%
dependency_resources_show_backup Read 61 0.1%
domain_bindings_show Read 61 0.1%
resources_count Read 61 0.1%
storage_volumes_backup_policies_list Read 61 0.1%
storage_volumes_show Read 61 0.1%
connections_show Read 60 0.1%
dependency_resources_show Read 60 0.1%
environments_list Read 60 0.1%
tunnels_revoke Destructive 58 0.1%
servers_capacity_inspect Read 58 0.1%
terminal_sessions_show Read 58 0.1%
tunnels_list Read 58 0.1%
terminal_sessions_close Write 58 0.1%
projects_delete_check Destructive 57 0.1%
resources_delete_check Destructive 57 0.1%
resources_reset_health Destructive 57 0.1%
servers_delete_check Destructive 57 0.1%
operator_work_show Read 57 0.1%
source_links_show Read 57 0.1%
certificates_show Read 56 0.1%
credentials_list_ssh Read 56 0.1%
environments_show Read 56 0.1%
tunnels_show Read 56 0.1%
environments_unlock Write 56 0.1%
blueprints_show Read 55 0.1%
organizations_profile_show Read 55 0.1%
projects_show Read 55 0.1%
projects_restore Write 55 0.1%
resources_restore Write 55 0.1%
system_instance_upgrade_check Read 54 0.1%
system_github_app_connection_show Read 51 0.1%
system_github_repositories_list Read 50 0.1%
control_plane_portability_artifacts_list Read 49 0.1%
system_control_plane_secret_rotation_plan Write 49 0.1%
default_access_domain_policies_list Read 47 0.1%
control_plane_portability_export_plan Write 47 0.1%
system_providers_list Read 46 0.1%
connections_categories_list Read 45 0.1%
environments_count Read 45 0.1%
system_doctor Read 45 0.1%
system_integrations_list Read 45 0.1%
system_plugins_list Read 45 0.1%
system_db_migrate Write 44 0.1%
auth_bootstrap_status Read 42 0.1%
system_db_status Read 42 0.1%
blueprints_list Read 41 0.1%
organizations_current_context Read 41 0.1%
account_profile_show Read 39 0.1%
account_sessions_list Read 39 0.1%
projects_count Read 39 0.1%
servers_count Read 39 0.1%

Your agent uses a handful of these tools. It pays for all 358.

You don't need all 358 of those definitions in the window. PolicyLayer is an MCP gateway that sits in front of Appaloft: only the tools you grant are exposed to the agent, the rest never load. A smaller window means a sharper agent — less noise when it picks a tool — and every request costs less:

Grant scopeDefinition costReduction
All 358 tools (no gateway) 59,762 tokens
3 granted tools ~501 tokens −99%
5 granted tools ~835 tokens −99%
10 granted tools ~1,669 tokens −97%

The risk dividend: 37 of these 358 tools are critical-risk (destructive or financial) and cost 3,000 tokens (5% of the definition load). Block them — the recommended starter policy — and you reclaim that context before tuning anything else.

  1. Create a free account and register Appaloft — nothing to install.
  2. Grant only the tools you use — ungranted definitions never enter the context window.
  3. Point your MCP client (Claude, Cursor, anything) at your gateway URL.
CUT APPALOFT TOKEN COST →

Instant setup, no code required.

Appaloft token-cost questions.

How many tokens does the Appaloft MCP server use?+

Its 358 tool definitions total 59,762 tokens — 30% of a 200k context window — measured with tiktoken o200k_base over the serialised tools/list payload. Exact counts vary slightly by client and model.

Why does Appaloft consume tokens before I send a message?+

MCP clients load every connected server's tool definitions — name, description, and input schema — into the model's context so it knows what it can call. That payload is charged against your context window on every request, whether or not a tool is used.

How do I reduce Appaloft's token usage?+

Expose fewer tools. A PolicyLayer grant scopes Appaloft to only the tools you allow — ungranted definitions are filtered out of the tool list, so they never enter the context window. A grant of 3 typical tools costs roughly 501 tokens, a 99% reduction.

Does deferred tool loading fix this?+

Partially, in some clients. Claude Code defers MCP tool schemas behind a tool-search step by default, and VS Code has experimental grouping — but you still pay tokens per search and reload, and Cursor, Windsurf and Gemini CLI load definitions upfront. Reducing the exposed tool set cuts the cost in every client.

How these numbers were measured.

01
Serialisation

Each tool is serialised as a tools/list entry — name, description, input schema — from the schemas in the PolicyLayer scan database. Clients differ slightly in framing, so treat counts as close estimates.

02
Tokeniser

tiktoken o200k_base (GPT-4o/o-series). Anthropic's current tokeniser isn't published, so Claude's exact counts will differ; for English text and JSON schemas the totals are close enough to treat these as estimates.

03
Deferred loading

Some clients now defer schema loading (Claude Code's tool search; VS Code experimental grouping). You still pay per search and reload — and Cursor, Windsurf and Gemini CLI load everything upfront.

Computed 24-07-2026 from the PolicyLayer scan database over all 358 catalogued Appaloft tools. Counts refresh with every site build.

Expose only the tools you use — the rest never enter your context.

A PolicyLayer grant scopes Appaloft to the tools you actually allow. Ungranted definitions never load, and every call that does run is checked against policy first.

Instant setup, no code required.

46,500+ MCP servers and 515,000+ tools scanned and risk-classified.

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.