Claude Cowork + xCloud

Install one-click apps with Claude Cowork on xCloud

Delegating one-click app installs to Claude Cowork means describing the outcome you want, such as a monitoring app running on the best-fitting server, and letting Cowork do the checking across your xCloud servers before it stops for your approval.

  • Skill: xcloud:deploy
  • Toolsets: oneclick-apps, catalog, servers
  • Free with every xCloud account

YouWhich of my servers can run Uptime Kuma? Check all of them and report. Install nothing.

servers_indexread-only

oneclickApps_compatibilityread-only

AgentFive servers checked. Frankfurt and Amsterdam fit. Singapore is too small for the app's minimum size. Paris is on a different stack. Dublin has no monitoring snapshot, so its resource check is inconclusive.

YouInstall it on Amsterdam, staging hostname.

oneclickApps_installneeds approval

. Keep a human in the loop: xCloud stops and asks before anything that creates, deploys, updates, reboots, deletes or buys.

Setup

How Do You Set Up Claude Cowork to Install one-click apps on xCloud?

Connect Claude Cowork once; every job on this account uses the same connection. Then ask in plain words.

  1. Add xCloud as a custom connector

    In Cowork, open Customize, then Connectors, and choose Add custom connector. If you already added xCloud to your Claude account, look for it in that list first. Name it xcloud, use this URL and sign in when the xCloud approval page opens.

    URL
    https://app.xcloud.host/mcp
  2. Check the connection

    Start a task and ask this first. Claude Cowork calls xCloud and names your account and the teams you approved, so you know the connector works before you delegate real work.

    Prompt
    Who am I on xCloud?
  3. Match the access level to the job

    Optional. On the xCloud approval screen, Full access lets a delegated job deploy, update plugins and renew certificates; Read-only is enough for audits and reports. To change the level later, reconnect the connector and approve again. A Team or Enterprise owner adds the same URL under Organization settings, then Connectors.

    URL
    https://app.xcloud.host/mcp
  4. Check it worked

    Then ask Claude Cowork for the job itself, for example:

    Prompt
    Find out which of my xCloud servers can run Uptime Kuma. Check them all, write a short report with the reasons, and do not install anything yet.

In practice

How Does One-click apps Work from Claude Cowork?

Cowork is for work you would rather hand off than steer turn by turn, and choosing where an app should live is exactly that kind of task. You write the outcome, for example: I want Uptime Kuma on whichever of my servers fits it best, and give me a short report before you install anything. Cowork reads your servers with servers_index, runs oneclickApps_compatibility against each one and compiles the answer into a single report: which servers fit, which do not and why, and where the resource check was skipped because a server had no monitoring snapshot. Nothing in that stage changes your hosting.

The report is the useful part. A server that is too small stays too small, so Cowork lists a larger server as the suggestion instead of retrying, and an app that needs a different stack is marked as a mismatch before you waste an install. Servers that run an OpenClaw, Hermes, Paperclip or DeepSeek Harness never take a one-click app, and Cowork leaves those out of the table. You read the result when you return, pick a server, and tell Cowork to proceed. It then restates the app, the server and the address and asks for your approval, because the install is the step that creates something.

That ordering suits the connection. A Read-only approval on the xCloud screen is enough for the whole survey, so you can delegate the checking with no risk of a change, and move to Full access only when you want Cowork to run oneclickApps_install. After the install, Cowork polls oneclickApps_status, then hands you the URL. Login details come only when you ask for them, once, in the reply. You can then give it the follow-on task of writing the install notes for your team, without the credentials in them.

Claude Cowork specific: Do not leave an install running unattended on a hope. The install stops for your approval by design, so a delegated task that reaches that step waits until you answer, and a Read-only connection cannot run it at all. Choose the access level to match the task: Read-only for surveys, Full access when you are present to approve. To change the level later, reconnect the xCloud connector and approve again.

What xCloud does for one-click apps

xCloud lists the one-click catalogue, checks whether an app fits a given server, installs it once you approve and reports each install phase until it finishes. Afterwards the agent can fetch the login details and stop, start or redeploy the app. A few apps install only from the dashboard, and the agent tells you where to click.

  1. Find the app. The agent searches the catalogue by name or purpose and shows what it found. An empty catalogue means the list has not synced on that environment, so the agent never answers that an app does not exist from an empty list.
  2. Read the install form. The agent reads the app's fields. Fields xCloud generates for you can be left out. For the address you choose a free xCloud staging hostname or your own domain, and a live domain needs the full site name.
  3. Check the server fits. You name the server, or the agent lists yours and asks. The compatibility check covers the server stack, runtime, state, billing and RAM, CPU and disk against the latest monitoring snapshot. If monitoring data is missing the resource check was skipped, and the agent says the result is inconclusive.
  4. Approve and install. The agent restates the app, the server and the address, and asks once. On your yes it sends the install with an explicit confirmation and an idempotency key, so a retried request cannot create a second copy.
  5. Poll the install. The agent polls the install status every five to ten seconds until it is terminal. A failure names its phase: pre_install, install, post_install or provisioning, so you know where it stopped.
  6. Hand over and manage. The agent gives you the URL. It fetches the login details only when you ask, shows them once in the reply and tells you to store them in a password manager. Later it can stop, start, restart or redeploy the app after your approval.

Reference

One-click apps Settings and Limits on xCloud

The facts Claude Cowork works within when it installs one-click apps. Where a row names the dashboard, that step stays yours to take there.

Setting or limitWhat applies
CatalogueSearchable by name. It holds hundreds of apps, and most run on a Docker server. Public facts such as supported stacks and minimum size come from the catalogue listing
Compatibility checkPer server: stack, runtime, server state, billing and RAM, CPU and disk. monitor_available set to false means the resource check was skipped, not passed
Too-small serversA server that is too small stays too small. The agent suggests a larger server instead of retrying the install
Stack requirementsAn app that needs another stack is refused with a 422 that reads "This app requires a ... server. This server is on the ... stack."
Dashboard-only installsn8n, Supabase, Nextcloud, Mautic, LibreChat, Open WebUI, Ollama, Umami, WireGuard, phpMyAdmin and Site.pro. The API answers 404 for these eleven; install them from Add site, One-Click Apps in the dashboard
AddressStaging hostname for a free xCloud address, or go live with your own domain. A demo site promoted to a live domain cannot return to the demo address
IdempotencyThe install carries an Idempotency-Key, so a retried request cannot create a duplicate site
Install phasespre_install, install, post_install and provisioning. is_terminal marks the end, and failed_phase says where a failure happened
CredentialsRead on request and shown once in the reply. Some apps have none to read because you create the first admin inside the app
LifecycleStop, start, restart and redeploy run synchronously. Stop takes the app offline and redeploy recreates its containers. Both answer 422 while an install is running or after a failed install
Agentic serversAn OpenClaw, Hermes, Paperclip or DeepSeek Harness server never takes a one-click app

Rules Claude Cowork has to follow

  • Installing, stopping and redeploying an app stop for your approval; browsing the catalogue and the compatibility check never change anything.
  • A missing resource reading is reported as inconclusive, never as a pass.
  • Login details are shown once, only when you ask, and never repeated in a summary or a later message.
  • For the eleven dashboard-only apps the agent checks that the server fits, then gives you the dashboard path instead of trying the install.
  • A failed install is not retried blindly: the agent names the failed phase and reads the site's recent events first.

Example prompts

What Can You Ask Claude Cowork to Do for One-click apps?

Type these as written and swap in your own repository, site and server names. Reads and routine actions such as backups, cache purges, PageSpeed scans and vulnerability scans run straight away; creating, deploying, updating, rebooting, deleting, buying or starting a broken-link scan stops and asks first.

Prompt
Find out which of my xCloud servers can run Uptime Kuma. Check them all, write a short report with the reasons, and do not install anything yet.
Prompt
Pick the server from your report with the most headroom, then install Uptime Kuma there on a staging hostname once I approve.
Prompt
Write install notes for the Uptime Kuma app for my team: the URL, the server and how to ask for a restart. Leave the login details out.
Prompt
Which one-click apps are compatible with my Frankfurt server?
Prompt
Search the one-click catalogue for a self-hosted blog and tell me what each result needs from a server.
Prompt
Install Uptime Kuma on the Frankfurt server on a staging hostname, wait until it is ready, then give me the login details.
Prompt
Check whether Immich fits my Amsterdam server before I install it, and tell me if the resource check was inconclusive.
Prompt
I want n8n on my Frankfurt server. Check that the server fits, then tell me where to click to install it.
Prompt
The Uptime Kuma install on the Frankfurt server failed. Which phase failed, and what do the recent events say?
Prompt
Redeploy the Ghost app on blog.example.com, but tell me what a redeploy does before you run it.

Claude Cowork and One-click apps: Frequently Asked Questions

What people ask before they let Claude Cowork install one-click apps through xCloud.

Can Claude Cowork check all my servers for one app in a single task?

Yes. Cowork lists your servers, runs the compatibility check on each and returns one report showing which fit, which do not and why. Servers without monitoring data are marked inconclusive, not passed, so you know which ones to look at yourself.

Will Cowork install an app while I am away?

Not without you. An install stops for your explicit approval, and a connector approved as Read-only cannot install at all. Cowork can finish the survey on its own, then wait with a ready recommendation until you come back and say yes.

Can an agent install any app in the one-click catalogue?

Most of them. Eleven apps install only from the dashboard: n8n, Supabase, Nextcloud, Mautic, LibreChat, Open WebUI, Ollama, Umami, WireGuard, phpMyAdmin and Site.pro. For those the agent checks that your server fits and points you to Add site, One-Click Apps.

How does the agent know an app will fit my server?

It runs the compatibility check for that server, which covers the stack, runtime, server state, billing and the RAM, CPU and disk readings from the latest monitoring snapshot. If monitoring data is missing, the agent tells you the resource check was inconclusive.

What does a 422 during an app install mean?

Usually that the app needs a different server stack than the one you picked, and the message names both. Pick a server on the required stack. A 422 on stop, start or redeploy means an install is still running or the last install failed.

Where do the login details for a one-click app come from?

The agent can read them from xCloud when you ask and shows them once in the reply. Store them in a password manager. Some apps have no generated login because you create the first administrator inside the app.

Can an agent stop or restart a one-click app?

Yes. Stop, start, restart and redeploy are available, and they run straight away once you approve. Stop takes the app offline and redeploy recreates its containers, so the agent asks before either.

Other agents

One-click apps with Other Agents

The same job, the same xCloud tools, a guide for each client.

Run Your Hosting from Claude Cowork

xCloud MCP, the Agent Skills and the Public API are free with every account. Connect once and ask.