# Deloc MCP server

Agent View of the PolicyLayer registry record for Deloc: identity, probed posture, risk grade, and all 45 tools classified. HTML page: https://policylayer.com/tools/deloc-mcp

## Facts

- Server id: `delocdev/deloc-mcp`
- Homepage: https://github.com/delocdev/deloc-mcp
- Registry record: grade F, identity unverified
- Lifecycle: active
- Rate-limited: no
- Tools: 45
- Tool categories present: Destructive, Execute, Read, Write
- Tags: deloc mcp, admin, automation
- Record last modified: 2026-08-02T15:33:26.421Z

## Tools (45)

| Tool | Category | Risk | Record |
| --- | --- | --- | --- |
| `delete_action` | Destructive | Critical | https://policylayer.com/tools/deloc-mcp/delete-action.md |
| `delete_action_secret` | Destructive | Critical | https://policylayer.com/tools/deloc-mcp/delete-action-secret.md |
| `delete_app` | Destructive | Critical | https://policylayer.com/tools/deloc-mcp/delete-app.md |
| `delete_dashboard_query` | Destructive | Critical | https://policylayer.com/tools/deloc-mcp/delete-dashboard-query.md |
| `delete_data_connection` | Destructive | Critical | https://policylayer.com/tools/deloc-mcp/delete-data-connection.md |
| `delete_oauth_credential` | Destructive | Critical | https://policylayer.com/tools/deloc-mcp/delete-oauth-credential.md |
| `disable_app` | Destructive | Critical | https://policylayer.com/tools/deloc-mcp/disable-app.md |
| `logout` | Destructive | Critical | https://policylayer.com/tools/deloc-mcp/logout.md |
| `deploy` | Execute | High | https://policylayer.com/tools/deloc-mcp/deploy.md |
| `run_dashboard_query` | Execute | High | https://policylayer.com/tools/deloc-mcp/run-dashboard-query.md |
| `test_action` | Execute | High | https://policylayer.com/tools/deloc-mcp/test-action.md |
| `test_oauth_credential` | Execute | High | https://policylayer.com/tools/deloc-mcp/test-oauth-credential.md |
| `bigquery_get_table_schema` | Read | Low | https://policylayer.com/tools/deloc-mcp/bigquery-get-table-schema.md |
| `bigquery_list_datasets` | Read | Low | https://policylayer.com/tools/deloc-mcp/bigquery-list-datasets.md |
| `bigquery_list_projects` | Read | Low | https://policylayer.com/tools/deloc-mcp/bigquery-list-projects.md |
| `bigquery_list_tables` | Read | Low | https://policylayer.com/tools/deloc-mcp/bigquery-list-tables.md |
| `check_bigquery_connection` | Read | Low | https://policylayer.com/tools/deloc-mcp/check-bigquery-connection.md |
| `get_account` | Read | Low | https://policylayer.com/tools/deloc-mcp/get-account.md |
| `get_action_logs` | Read | Low | https://policylayer.com/tools/deloc-mcp/get-action-logs.md |
| `get_app` | Read | Low | https://policylayer.com/tools/deloc-mcp/get-app.md |
| `list_action_secrets` | Read | Low | https://policylayer.com/tools/deloc-mcp/list-action-secrets.md |
| `list_actions` | Read | Low | https://policylayer.com/tools/deloc-mcp/list-actions.md |
| `list_apps` | Read | Low | https://policylayer.com/tools/deloc-mcp/list-apps.md |
| `list_dashboard_queries` | Read | Low | https://policylayer.com/tools/deloc-mcp/list-dashboard-queries.md |
| `list_data_connections` | Read | Low | https://policylayer.com/tools/deloc-mcp/list-data-connections.md |
| `list_data_files` | Read | Low | https://policylayer.com/tools/deloc-mcp/list-data-files.md |
| `list_oauth_credentials` | Read | Low | https://policylayer.com/tools/deloc-mcp/list-oauth-credentials.md |
| `suggest_deploy_options` | Read | Low | https://policylayer.com/tools/deloc-mcp/suggest-deploy-options.md |
| `connect_bigquery` | Write | Medium | https://policylayer.com/tools/deloc-mcp/connect-bigquery.md |
| `create_action` | Write | Medium | https://policylayer.com/tools/deloc-mcp/create-action.md |
| `create_dashboard_query` | Write | Medium | https://policylayer.com/tools/deloc-mcp/create-dashboard-query.md |
| `create_oauth_credential` | Write | Medium | https://policylayer.com/tools/deloc-mcp/create-oauth-credential.md |
| `disable_action` | Write | Medium | https://policylayer.com/tools/deloc-mcp/disable-action.md |
| `enable_action` | Write | Medium | https://policylayer.com/tools/deloc-mcp/enable-action.md |
| `enable_app` | Write | Medium | https://policylayer.com/tools/deloc-mcp/enable-app.md |
| `renew_app` | Write | Medium | https://policylayer.com/tools/deloc-mcp/renew-app.md |
| `set_action_secret` | Write | Medium | https://policylayer.com/tools/deloc-mcp/set-action-secret.md |
| `set_og_image` | Write | Medium | https://policylayer.com/tools/deloc-mcp/set-og-image.md |
| `set_password` | Write | Medium | https://policylayer.com/tools/deloc-mcp/set-password.md |
| `setup_data_refresh` | Write | Medium | https://policylayer.com/tools/deloc-mcp/setup-data-refresh.md |
| `setup_deloc` | Write | Medium | https://policylayer.com/tools/deloc-mcp/setup-deloc.md |
| `update_action` | Write | Medium | https://policylayer.com/tools/deloc-mcp/update-action.md |
| `update_dashboard_query` | Write | Medium | https://policylayer.com/tools/deloc-mcp/update-dashboard-query.md |
| `update_oauth_credential` | Write | Medium | https://policylayer.com/tools/deloc-mcp/update-oauth-credential.md |
| `upload_data` | Write | Medium | https://policylayer.com/tools/deloc-mcp/upload-data.md |

## Tool descriptions

- `delete_action` — Permanently delete an Action. All secrets and invocation logs are cascaded. Irreversible.
- `delete_action_secret` — Delete a secret from an Action. Any template referencing ${NAME} will fail at invoke time with variable_missing until re-set.
- `delete_app` — Permanently delete a published app and its files
- `delete_dashboard_query` — Delete a scheduled dashboard query. The already-written {name}.json data file stays in the app; it just stops refreshing.
- `delete_data_connection` — Delete a data connection. Fails if any dashboard query still uses it — repoint or delete those queries first.
- `delete_oauth_credential` — Permanently delete an OAuth credential. Fails with a list of referencing actions if any still use it — reassign or remove those actions first.
- `disable_app` — Take a published app offline
- `logout` — Log out of Deloc and clear stored credentials. Use this to switch to a different account.
- `deploy` — Deploy or update a project on Deloc. If an app with the same name already exists, it will be updated in place — do NOT delete and recreate apps. Redeploying preserves the same URL and settings. Set password to a string to use that passwo…
- `run_dashboard_query` — Run a scheduled dashboard query immediately instead of waiting for the daily refresh. Writes the result to the app
- `test_action` — Run a single test invocation against a configured Action. Logged with errorType=
- `test_oauth_credential` — Exchange credentials for a fresh access token against the upstream. Bypasses the server-side cache so you always see the live behavior — useful for verifying a newly created or rotated credential. Returns a short preview of the token (fi…
- `bigquery_get_table_schema` — Get the column names and types of a BigQuery table. Use this to write correct SQL for create_dashboard_query.
- `bigquery_list_datasets` — List the datasets in a GCP project visible to a BigQuery connection.
- `bigquery_list_projects` — List the GCP projects a BigQuery connection can access. Use the project id as gcp_project_id when creating dashboard queries.
- `bigquery_list_tables` — List the tables in a BigQuery dataset.
- `check_bigquery_connection` — Check whether a pending BigQuery connect session (started with connect_bigquery) has been approved. Polls briefly and reports the result.
- `get_account` — Get current user info including tier, usage, and limits
- `get_action_logs` — Fetch recent invocation history for an app
- `get_app` — Get detailed info about a published app including bandwidth usage
- `list_action_secrets` — List secret NAMES configured for an Action. Values are never returned — secrets are write-only after set.
- `list_actions` — List Actions configured for a published app. Shows method, status, and recent invocation stats.
- `list_apps` — List published apps with their URLs and status
- `list_dashboard_queries` — List the scheduled dashboard queries on an app, with their output files and last-run results.
- `list_data_connections` — List the user
- `list_data_files` — List the refreshable data files (uploaded via upload_data) for a Deloc app, with sizes and last-updated time. Use this to check what data files exist and when they were last refreshed.
- `list_oauth_credentials` — List OAuth credentials the authenticated user can see. Org users see the team-shared credentials for their org; solo users see their personal credentials. Secret values (client_secret, password, private key) are NEVER returned.
- `suggest_deploy_options` — Analyze a project directory and suggest deployment options including framework detection, build needs, app name, and size estimate
- `connect_bigquery` — Connect the user
- `create_action` — Create a new server-side Action on a published app. Actions let browser code call external APIs without exposing keys — secrets live server-side and are templated in at invoke time. Template syntax (IMPORTANT, do not mix up): {name} for …
- `create_oauth_credential` — Create an OAuth credential that actions can reference by name to get a fresh access token at invoke time (injected as ${OAUTH_ACCESS_TOKEN}). Walk the user through: (1) which upstream API, (2) which grant type fits (client_credentials fo…
- `disable_action` — Disable an Action so invocations are rejected. Config and secrets are preserved.
- `enable_action` — Re-enable a disabled or auto-disabled Action. Idempotent.
- `enable_app` — Re-enable a disabled app so it is served again
- `renew_app` — Extend a free-tier app
- `set_action_secret` — Set or rotate a secret for an Action. Values are encrypted at rest (libsodium secretbox) and never returned by any endpoint. Used to fill ${UPPERCASE_NAME} placeholders in target_url, header_template, or body_template. Do NOT echo the va…
- `set_og_image` — Set a custom OG preview image for an app (shown in link previews on X, Slack, etc.). Accepts a local PNG file path.
- `set_password` — Set, change, or remove password protection on an app
- `setup_data_refresh` — Generate a complete backend script that queries a data warehouse and auto-refreshes a Deloc dashboard. Creates a ready-to-deploy Python project (main.py, requirements.txt, Dockerfile) with scheduling instructions. Supported data sources:…
- `setup_deloc` — Set up Deloc — sign in to start deploying. Ask the user which sign-in method they prefer: Google, Microsoft, or if they already have an API token. If they don
- `update_action` — Update an existing Action. Every field is optional — send only what
- `update_dashboard_query` — Update a scheduled dashboard query: change its SQL, repoint it to a different connection, adjust caps, or enable/disable the schedule. Omitted fields are unchanged.
- `update_oauth_credential` — Update an OAuth credential. Rotate the secret (client_secret/password/private key) by passing a new grant + secret field; this clears the cached token so the next invoke re-fetches. Leave grant fields out to edit only display_name/token_…
- `upload_data` — Upload or replace a data file (CSV, JSON, TSV, XML, TXT, max 10MB) inside an already-deployed Deloc app WITHOUT redeploying. Use this to refresh dashboard data from databases or APIs on a schedule. The file is served at the same URL as t…

## Related servers

- UnClick (1662 tools) — https://policylayer.com/tools/io-github-malamutemayhem-unclick-mcp-server.md
- Delx Mcp A2a (1076 tools) — https://policylayer.com/tools/io-github-davidmosiah-delx-mcp-a2a.md
- Delx Protocol — Agent Recovery & Continuity (1076 tools) — https://policylayer.com/tools/io-github-davidmosiah-delx-protocol.md
- Nodebench (824 tools) — https://policylayer.com/tools/io-github-homenshum-nodebench.md
- MCP Framework Personal (790 tools) — https://policylayer.com/tools/inggerman-mcps.md
- Delx MCP Server (740 tools) — https://policylayer.com/tools/io-github-davidmosiah-delx-mcp-server.md
- Binance MCP Server (734 tools) — https://policylayer.com/tools/nirholas-binance-mcp.md
- Eda Agent (726 tools) — https://policylayer.com/tools/eda-agent.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=deloc-mcp · API: https://policylayer.com/registry/api · Recommended policies for every tool: https://policylayer.com/policies/deloc-mcp
