# Stacklet > Stacklet is a cloud governance company founded by the creators of Cloud Custodian, the > open-source rules engine it stewards. Its Governance-as-Code platform runs Cloud Custodian > policies as a managed service across AWS, Azure and GCP, and adds AssetDB (a SQL-queryable > warehouse of cloud resources, costs, tags and relationships), IaC governance, and the Jun0 > agentic layer. The marketing surface is stacklet.ai; stacklet.io redirects to it. Generated by API Evangelist on 2026-08-29 from this repository's artifacts. Stacklet does not publish an llms.txt of its own — https://stacklet.ai/llms.txt returns 404 — so this file is generated, not harvested. ## How to reach the API - Platform API: GraphQL, served per customer deployment at https://api..stacklet.io/ There is no shared multi-tenant endpoint and no publicly resolvable instance host, so the schema cannot be introspected anonymously. - Authentication: SSO through AWS Cognito (`stacklet-admin login`), a username/password grant, or an API key in `STACKLET_API_KEY`. All three end in a Bearer token on the Authorization header. See authentication/stacklet-authentication.yml - Documentation is served from the customer's own deployment at https://docs..stacklet.io/ and is not public. There is no public developer portal, API reference, status page or OpenAPI. ## Agent surface - MCP server: `stacklet-mcp` on PyPI, source at https://github.com/stacklet/mcp-server Local stdio only — there is no hosted or remote MCP endpoint. 16 tools across three toolsets: AssetDB SQL, Platform GraphQL, and documentation. Writes (saving and archiving AssetDB queries, executing GraphQL mutations) are OFF by default and each is gated behind its own environment variable. See mcp/stacklet-mcp.yml - No A2A agent card is served (/.well-known/agent-card.json and /.well-known/agent.json both 404 on stacklet.ai and stacklet.io). - Read the server's own warning before pointing an agent at a deployment: most Stacklet installations contain confidential cloud inventory, and this server exists to hand it to a model. ## Contract status - No OpenAPI, Swagger, AsyncAPI, WSDL or .proto is published anywhere on Stacklet's public surface. Probes of /openapi.json, /swagger.json and /api-docs on both hosts returned 404. - The GraphQL SDL exists but is auth-gated behind a customer deployment. - The public projection of the schema is the official Terraform provider (25 resources, 24 data sources) and the official CLI's GraphQL snippets, which is what this profile's data model is derived from. ## Core entities Account, AccountDiscovery, AccountGroup, Policy, PolicyCollection, Binding, Repository, User, SSOGroup, Role, RoleAssignment, ReportGroup, NotificationTemplate, ConfigurationProfile (email/Slack/Teams/Jira/ServiceNow/Symphony/account-owner/resource-owner), GCPIntegration. A Binding joins a PolicyCollection to an AccountGroup; deploying and running a binding is what executes policy against real cloud accounts. A binding carries `dry_run`, which is the documented way to rehearse an action without taking it. ## Conventions - Relay cursor connections: edges[].node plus pageInfo (startCursor, endCursor, hasNextPage, hasPreviousPage); --first/--last/--after/--before on the CLI. - Errors arrive in the GraphQL errors array; HTTP 400 carries the GraphQL message. No RFC 9457. - No idempotency key and no documented rate limit. Every add- verb has a matching remove- verb, but no retention or undo window is stated — see the reversibility block in conventions/stacklet-conventions.yml before letting an agent write. ## Packages - stacklet-mcp (PyPI) 2026.4.0, 2026-04-02 — MCP server - stacklet.client.platform (PyPI) 2026.8.10, 2026-08-11 — stacklet-admin CLI + Python client - stacklet.client.sinistral (PyPI) 0.5.37, 2026-07-24 — Sinistral IaC governance CLI - stacklet/stacklet (Terraform Registry) 0.8.2, 2026-06-29 — Terraform provider Cloud Custodian (c7n, c7n-org, c7n-mailer) is stewarded by Stacklet but published by the upstream open-source project — https://cloudcustodian.io/docs ## Commercial - No published pricing and no self-service sign-up. Get a demo: https://stacklet.ai/get-a-demo/ - AWS Marketplace listing (private offer): https://aws.amazon.com/marketplace/pp/prodview-za7x2tiyughvm - Terms: https://stacklet.ai/terms-of-service/ · Privacy: https://stacklet.ai/privacy-policy/ ## Links - Website: https://stacklet.ai/ - Platform overview: https://stacklet.ai/platform-overview/ - Blog: https://stacklet.ai/blog/ (RSS https://stacklet.ai/feed/) - GitHub: https://github.com/stacklet - Contact: https://stacklet.ai/contact/ - Cloud Custodian: https://cloudcustodian.io/