Codex + xCloud
Back up and stage sites with Codex on xCloud
Backing up and staging sites with Codex means telling OpenAI's terminal agent to check the state of your xCloud backups, take one before a change and create a staging copy of the current branch, using the xcloud server you registered.
- Skill: xcloud:sites
- Toolsets: sites
- Free with every xCloud account
YouBackup status for shop.example.com, then back it up.
sites_backupStatusread-only
AgentNative site. Daily schedule, last backup 20 hours ago, completed, local storage. Starting a fresh backup.
sites_backup
AgentBackup completed. Ready to apply the schema change when you say so.
. Keep a human in the loop: xCloud stops and asks before anything that creates, deploys, updates, reboots, deletes or buys.
Setup
How Do You Set Up Codex to Back up and stage sites on xCloud?
Connect Codex once; every job on this account uses the same connection. Then ask in plain words.
Add the xCloud MCP server
Run this in your terminal. This form comes from xCloud's connect guide; OpenAI's Codex page documents codex mcp add for local commands, so if your version rejects --url, use the config.toml step below.
codex mcp add xcloud --url https://app.xcloud.host/mcpOr write it in config.toml
Codex reads ~/.codex/config.toml. Add a table for the server with its url. A Streamable HTTP server needs only the url, and the same file is where you set a bearer_token_env_var if you use an API key instead of OAuth.
[mcp_servers.xcloud] url = "https://app.xcloud.host/mcp"Sign in and check
Run the login command, approve the teams and choose Read-only or Full access in the browser, then type /mcp in Codex to see xcloud and its tools. Optional: Codex is also listed for the xCloud Agent Plugins package, which adds the xCloud skills.
codex mcp login xcloudCheck it worked
Then ask Codex for the job itself, for example:
Read the backup status of shop.example.com. Last run, result, storage location.
In practice
How Does Backups and staging Work from Codex?
With Codex you work from a repository checkout, so the backup request usually comes attached to a task: change the schema, upgrade a framework, rewrite the checkout flow. Before it touches anything, you ask Codex to look at the site's backup state. After codex mcp login xcloud and a quick /mcp to confirm the server is listed, Codex calls the xCloud read tools, sites_backupSettings, sites_backupStatus and sites_backups for a native site or the Docker equivalents for a Docker app, and prints a short answer. It tells you whether a schedule is on, when the last backup ran and whether it completed. If the last backup is a day older than the work you are about to do, you ask it to take another one.
There are two layers of approval in this flow and it helps to keep them apart. Codex has its own approval policy for commands and tool calls, which you set when you start it. xCloud has its own confirmation rule, and a backup is on the side that needs none, so sites_backup or sites_docker_backup starts as soon as Codex calls it. If your Codex policy is strict, you may still be asked to allow the tool call, and if it is relaxed, nothing at all will stop a backup. For a Docker app, ask Codex to say first that the app is stopped briefly while its volumes are captured. It then follows the backup and reports completed or failed, and only then moves on to the edit.
Staging fits the repository workflow. Codex can read the current branch, so it proposes a staging environment from that branch for a Laravel, Node.js, custom PHP or Lovable site, restates the site and branch, and calls sites_stagingSites_create only after you approve. Creating one needs a paid plan, and Codex relays xCloud's plan-limit answer if you are on the free plan. For scripted use, codex exec with a bearer_token_env_var token can run a read-only backup coverage check in a scheduled job. WordPress staging, restores, native schedules and storage providers stay in the dashboard, and Codex gives you the path rather than a workaround.
Codex specific: Codex keeps xCloud's confirmation rule and its own approval policy separate, and a backup needs no xCloud confirmation. A relaxed Codex policy therefore lets a backup start with no prompt at all, so name the site in your request and check the answer. Also run codex mcp login xcloud after adding the server, or the backup tools stay unavailable, and confirm xcloud appears under /mcp.
What xCloud does for backups and staging
xCloud lets the agent read every site's backup state, start a backup on demand for native and Docker sites, and create a staging environment for Git sites. Restores, storage providers and WordPress staging stay in the dashboard, and the agent tells you the exact path when you ask for one.
- Find the site. The agent resolves the site by name or domain, restates which one it is about to act on, and reads whether it is a native site or a Docker app, because the two use different backup operations.
- Read the protection state. It reads the backup settings, status, count and recent backups. That answers whether the site has a schedule, when the last backup ran, whether it succeeded and where it is stored, before anything is changed.
- Back up now. A backup starts without an approval prompt. A native site takes a local backup by default or a remote one when a storage provider is connected. A Docker app is stopped briefly while its volumes are captured, so the agent says so before it backs up a production app.
- Wait for the result. xCloud queues the backup and returns straight away. The agent follows the backup task or row until it is terminal, then reports completed or failed instead of treating the queued response as done.
- Stage the change. For a Git site such as Laravel, Node.js, custom PHP or Lovable, the agent creates a staging environment from the branch you name, after you approve, and gives you its URL. A WordPress staging site is a dashboard step, and the agent gives you the path.
- Hand off restores and settings. If you ask to restore a backup, change a native site's schedule or add a storage provider, the agent explains that these are dashboard-only and gives the path and the site's dashboard link. It never improvises a workaround.
Reference
Backups and staging Settings and Limits on xCloud
The facts Codex works within when it backs up and stage sites. Where a row names the dashboard, that step stays yours to take there.
| Setting or limit | What applies |
|---|---|
| Native site backup | On demand through the API; the type is local (the default) or remote. A remote backup needs a storage provider with a working connection, otherwise xCloud refuses it with a 422 before anything is queued |
| Docker app backup | On demand through the API for Compose deploys and most one-click apps. The app is cold-stopped for a moment while volumes are captured. A remote copy goes to an S3-compatible or SFTP provider; Google Drive and pCloud are not supported for Docker apps |
| Reading backups | Backup list, count, status and settings are readable for every site. Docker apps also expose one backup's detail |
| Docker backup housekeeping | The agent can label a Docker backup with a note and delete one. Deleting is irreversible, so it names the exact backup by date and note first |
| Native schedule and retention | Read-only through the API. Change them in the dashboard under Site > Site Backup > Backup Settings |
| Docker backup settings | Writable through the API: automatic backup on or off, daily, weekly or monthly frequency, and the number of days to keep backups |
| Restores | Dashboard-only for every site type: Site > Site Backup > Previous Backups > Restore. A backup can also be restored to another site from the same page |
| Storage providers | Dashboard-only, under Integrations > Storage Provider. Backup settings return a provider's identifier and status, never its credentials |
| Team-wide backup policy | Applying one backup policy to many sites is dashboard-only, under Global Settings > Site Backup |
| Git staging | Created through the API for Git sites on paid plans. On the free plan xCloud answers 403 because it is a plan limit, not a permission |
| WordPress staging | Dashboard-only: xCloud answers 422 when the API is asked for it. Push and pull between staging and production also happen in the dashboard |
| Snapshots | Snapshots are listed per site. The server-wide snapshot list holds site snapshots, not a server image. Taking or restoring a snapshot, and a whole-server provider backup, stay in the dashboard |
Rules Codex has to follow
- A backup runs without an approval prompt, but the agent says when it briefly stops a Docker app and does not trigger one on a busy production app without telling you.
- A queued backup is not a finished backup: the agent reports completed or failed only after it has read the result.
- Restoring a backup, changing a native site's schedule, adding a storage provider and creating WordPress staging are dashboard steps; the agent gives you the path instead of guessing an operation.
- Creating a staging environment stops for your approval, and deleting a backup names the exact backup first.
- Before you push staging data to production in the dashboard, take a backup of the production site so you can recover if the push goes wrong.
Example prompts
What Can You Ask Codex to Do for Backups and staging?
Type these as written and swap in your own repository, site and server names. Reads and routine actions such as backups, cache purges, PageSpeed scans and vulnerability scans run straight away; creating, deploying, updating, rebooting, deleting, buying or starting a broken-link scan stops and asks first.
Read the backup status of shop.example.com. Last run, result, storage location.Take a backup of the shop site and wait for completed. Then apply the schema change in this repo.Create a staging environment for the API site from the current branch. Print the URL. Ask before you create it.When was the last backup of the shop site, did it succeed, and where is it stored?Check the backup settings on every site and list the ones with no schedule.Take a backup of the n8n Docker app now, before I upgrade it, and tell me when it is done.Switch the n8n Docker app to a daily backup and keep backups for 14 days. Show me the change before you apply it.Create a staging environment for the API site from the feature/checkout branch and give me its URL.List the snapshots of the shop site and tell me which is newest.I need to restore the shop site to last night's backup. Tell me where to click.Codex and Backups and staging: Frequently Asked Questions
What people ask before they let Codex back up and stage sites through xCloud.
Will Codex ask me before it takes a backup on xCloud?
xCloud does not ask, because a backup is a routine action. Codex may still ask you to allow the tool call, depending on the approval policy you started it with. Creating a staging environment always stops for an explicit confirmation.
Can Codex check backups from a script?
Yes, for reads. Run codex exec with a token that carries the mcp:invoke scope plus read:sites, held in the environment variable named by bearer_token_env_var, and ask for the backup state of your sites. Keep the token out of config.toml and out of any prompt.
Can an AI agent restore a backup for me?
No. Restoring a native or Docker backup is a dashboard step, under Site > Site Backup > Previous Backups > Restore. The agent can list the backups, tell you which one is newest and completed, and give you the site's dashboard link so you can start the restore yourself.
Does the agent ask before it takes a backup?
No. A backup is a routine action, so xCloud runs it without a confirmation prompt. For a Docker app the agent tells you first that the app stops briefly while its data is captured, and it reports the result only after the backup has finished.
Can the agent change my backup schedule?
For Docker apps, yes: it can turn automatic backups on or off, set daily, weekly or monthly, and set how many days backups are kept. For native sites the schedule, retention and destination are read-only through the API, so you change them in the dashboard under Site > Site Backup > Backup Settings.
Can the agent connect my S3 bucket or other storage?
No. Storage providers are added in the dashboard, under Integrations > Storage Provider, so credentials never pass through a chat. Once a provider exists, the agent can read which one a site's backup settings point at and use it for a remote backup.
Can the agent create a staging site for WordPress?
Not through the API. xCloud answers 422 for WordPress staging, so you create it in the dashboard from the site overview. For Laravel, Node.js, custom PHP and Lovable sites the agent can create a staging environment, which needs a paid plan.
Other agents
Backups and staging with Other Agents
The same job, the same xCloud tools, a guide for each client.
- Back up and stage sites with Claude CodeAnthropic's terminal coding agent. One claude mcp add command, plus the xCloud skills plugin with nine skills on top.
- Back up and stage sites with ClaudeAnthropic's chat assistant on the web and desktop. Add xCloud as a custom connector, no terminal needed.
- Back up and stage sites with Claude CoworkAnthropic's desktop agent for delegated work. Add the xCloud connector, then hand off hosting jobs.
- Back up and stage sites with CursorThe AI code editor. One mcp.json entry with the compact URL, because Cursor stops at 40 tools.
- Back up and stage sites with OpenCodeThe open-source terminal coding agent. One remote MCP entry, then opencode mcp auth xcloud.
- Back up and stage sites with Hermes AgentNous Research's agent with memory and a built-in scheduler. An mcp_servers entry in config.yaml and one login.
- Back up and stage sites with OpenClawThe open-source agent runtime with chat apps and automations. ClawHub skill plus the MCP client.
- Back up and stage sites with WindsurfThe Cognition editor, now Devin Desktop. devin mcp add for the Devin Local agent, a serverUrl entry for legacy Cascade.
- Back up and stage sites with GitHub CopilotCopilot agent mode in VS Code. One .vscode/mcp.json entry, or the Agent Plugins package.
- Back up and stage sites with Gemini CLIGoogle's terminal agent. One gemini mcp add command, OAuth found automatically.
- Back up and stage sites with ChatGPTOpenAI's chat assistant. A developer-mode app with the xCloud MCP URL and OAuth.
- Back up and stage sites with ChatGPT dotsOpenAI's always-on agent in ChatGPT. Uses the xCloud MCP plugin you add in ChatGPT, with custom rules and scheduled tasks.
- Back up and stage sites with GrokxAI's terminal agent, Grok Build. One grok mcp add command or a config.toml entry.
- Back up and stage sites with Grok BotxAI's always-on Bots on a cloud computer. One Remote HTTPS MCP plugin, OAuth sign-in, routines on a schedule.
- Back up and stage sites with KiroAWS's agentic IDE. One url entry in .kiro/settings/mcp.json, plus the portable xCloud Agent Plugins package.
- Back up and stage sites with AntigravityGoogle's agentic IDE. One serverUrl entry in mcp_config.json and a browser sign-in.
- Back up and stage sites with ZedThe Zed editor's Agent Panel. One context_servers entry in settings.json and a browser sign-in.
More Codex guides
Run Your Hosting from Codex
xCloud MCP, the Agent Skills and the Public API are free with every account. Connect once and ask.