Codex + xCloud

Deploy from Git with Codex on xCloud

Deploying from Git with Codex means telling OpenAI's terminal coding agent to ship a repository, and letting xCloud detect the app, preview the site, create it once you approve and verify that the live URL answers.

  • Skill: xcloud:deploy
  • Toolsets: sites, servers, integrations
  • Free with every xCloud account

YouDeploy this repo to Frankfurt on a staging hostname. Dry run first.

git_detectread-only

AgentLaravel app on main. xCloud would use PHP 8.3, web root public, and a free staging hostname. Warning: no .env in the repo, so I will pass the values through the environment field. Create it?

YouYes.

servers_sites_git_autoneeds approval

AgentDeployed. SSL issued, the site answers 200, and failed steps are empty.

. Keep a human in the loop: xCloud stops and asks before anything that creates, deploys, updates, reboots, deletes or buys.

Setup

How Do You Set Up Codex to Deploy from Git on xCloud?

Connect Codex once; every job on this account uses the same connection. Then ask in plain words.

  1. Add the xCloud MCP server

    Run this in your terminal. This form comes from xCloud's connect guide; OpenAI's Codex page documents codex mcp add for local commands, so if your version rejects --url, use the config.toml step below.

    Terminal
    codex mcp add xcloud --url https://app.xcloud.host/mcp
  2. Or write it in config.toml

    Codex reads ~/.codex/config.toml. Add a table for the server with its url. A Streamable HTTP server needs only the url, and the same file is where you set a bearer_token_env_var if you use an API key instead of OAuth.

    TOML
    [mcp_servers.xcloud]
    url = "https://app.xcloud.host/mcp"
  3. Sign in and check

    Run the login command, approve the teams and choose Read-only or Full access in the browser, then type /mcp in Codex to see xcloud and its tools. Optional: Codex is also listed for the xCloud Agent Plugins package, which adds the xCloud skills.

    Terminal
    codex mcp login xcloud
  4. Check it worked

    Then ask Codex for the job itself, for example:

    Prompt
    Deploy this repo to my Frankfurt server on a staging hostname. Dry run first, then wait for me.

In practice

How Does Deploy from Git Work from Codex?

You run Codex in a terminal, usually in the repository you are working on, so it can read the remote, the branch and the scripts without being told. Typing deploy this to my Frankfurt server is enough for it to call git_detect through the xCloud MCP server and report the app type, the suggested install, build and start commands and any warning. If you would rather deploy a repository you are not standing in, give it the URL. Either way, the first thing Codex does is detection, which creates nothing, and the reply is a few lines you can read at a glance in the terminal.

Before the first deploy, run /mcp in Codex and check that xcloud is listed with its tools. If it is not, you skipped codex mcp login xcloud. After that the flow is the same four beats every time. Codex asks xCloud for a staging hostname unless you named a domain, sends the create request as a dry run, and prints the would-create summary. You answer yes once. It sends the confirmed request with an idempotency key, follows the site status with one line per real step change, and fetches the address before saying the site is live. Codex also asks for its own approval before it runs tools, depending on how you configured it, so you may see its prompt and xCloud's confirmation as two separate checkpoints.

Codex can edit files and run commands, which is what makes a failed deploy short. It reads the deployment diagnosis, which names the failing step and quotes the log, and compares it with the repository. A wrong build command is corrected on the same site through a retry. A code problem it can fix in the working tree, but xCloud deploys from the remote, so the change has to be committed and pushed before the retry picks it up. Ask for that explicitly: fix it, commit, push and then retry.

Codex specific: Codex only has xCloud's tools after codex mcp login xcloud has run, and /mcp is the quick check. The deploy reads the Git remote, so a fix Codex makes in the working tree reaches xCloud only after it is committed and pushed. If your version rejects the codex mcp add form with --url, write the [mcp_servers.xcloud] table in ~/.codex/config.toml instead, which OpenAI's page documents.

What xCloud does for deploy from git

xCloud detects the app in the repository, previews the site it would create with a dry run, creates it once you approve, polls the deployment to a terminal state and checks the live URL. A failed deploy gets a diagnosis and a corrected retry on the same site, never a delete and recreate.

  1. Pick the team and server. The agent uses the server you name. If you name none it lists provisioned servers and asks; it never picks one silently. Node.js, PHP and static builds need an Nginx or OpenLiteSpeed server; anything else needs a Docker server.
  2. Detect the repository. git_detect reads the default branch, the app type (WordPress, Laravel, custom PHP, Node.js or Lovable), the web root, suggested install, build and start commands, repository access and server compatibility. Detection creates nothing.
  3. Choose the address. With no domain the agent asks xCloud for a free staging hostname. With a live domain it checks whether the zone is on a connected Cloudflare account, in which case xCloud writes the DNS record and certificate itself.
  4. Dry run, then one approval. The agent sends the create request with dry_run set to true and shows you the resolved configuration: app type, URL, branch, commands, runtime version and every warning. Then it asks once, naming the server and the URL, before sending the same body with confirm set to true and an idempotency key.
  5. Poll and verify. A 202 means queued, not deployed. The agent polls the site status until it is terminal, reports each real step change, reads failed_steps and the SSL block, and fetches the URL before it calls the site live.
  6. Recover if it fails. On a failed deploy the agent reads the deployment diagnosis, proposes a fix from the correctable fields, and retries on the same site with your approval. Two failed retries with the same classification stop the loop and hand you the dashboard link.

Reference

Deploy from Git Settings and Limits on xCloud

The facts Codex works within when it deploys from Git. Where a row names the dashboard, that step stays yours to take there.

Setting or limitWhat applies
Supported app typesWordPress, Laravel, custom PHP, Node.js and Lovable on native servers; Dockerfile and Compose apps, including Python, Go and Rust, on Docker servers
Repository sourcesPublic HTTPS URLs, repositories on a connected GitHub, GitLab or Bitbucket provider, and private SSH repositories with a read-only deploy key
Private repositoriesThe agent prepares a deploy key on the server, you add the public key to the repository, xCloud verifies it. A private key or personal token never goes in the request
Previewdry_run: true returns the would_create block and consumes no idempotency key
IdempotencyThe create call carries an Idempotency-Key, so a retried request cannot create a duplicate site. A new deployment needs a new key
Deployment statesdeployed, failed or cancelled once terminal is true; failed_steps can be non-empty on a deployed site and must be read
Node.js versionsThe Node version is server-wide, not per site; changing it can affect other apps on the server
RedeploysA redeploy runs git reset --hard and git clean -df in the site directory, so uncommitted server-side changes are lost. Supply environment values through env_file_content, not files in the checkout
Staging environmentsAvailable for Git sites on paid plans through the API; WordPress staging stays a dashboard step
Agentic serversAn OpenClaw, Hermes, Paperclip or DeepSeek Harness server hosts only the site created at provisioning; a second site is refused

Rules Codex has to follow

  • Creating a site is billable and stops for your approval; detection and the dry run never create anything.
  • The agent explains every detection warning before asking, and a repository access problem is never worked around by naming an app type by hand.
  • A deployed state is not proof the application works: the agent fetches the URL and reads failed_steps first.
  • A failed site is retried in place with corrections; it is never deleted and recreated to retry.
  • Changing a live site's domain after creation, databases and server resizing are dashboard steps; the agent gives you the path and the dashboard link xCloud returned.

Example prompts

What Can You Ask Codex to Do for Deploy from Git?

Type these as written and swap in your own repository, site and server names. Reads and routine actions such as backups, cache purges, PageSpeed scans and vulnerability scans run straight away; creating, deploying, updating, rebooting, deleting, buying or starting a broken-link scan stops and asks first.

Prompt
Deploy this repo to my Frankfurt server on a staging hostname. Dry run first, then wait for me.
Prompt
Diagnose the failed deploy of the shop site, fix the cause in the repo, commit and push, then retry on the same site.
Prompt
Detect github.com/acme/api and tell me whether it needs a Docker server. Create nothing.
Prompt
Deploy https://github.com/acme/shop to my Frankfurt server and show me the dry run before creating anything.
Prompt
Deploy the private GitLab repository connected to my team on a staging hostname.
Prompt
Scan the docker-compose.yml in github.com/acme/api and tell me which services and ports xCloud would use.
Prompt
Create a staging environment from the feature/checkout branch of the API site.
Prompt
Deploy the latest commit of the shop site after showing me what will change.
Prompt
The last deploy of the API site failed. Diagnose it, fix the build command and retry on the same site.

Codex and Deploy from Git: Frequently Asked Questions

What people ask before they let Codex deploy from Git through xCloud.

Do I need codex mcp login before Codex can deploy?

Yes. Adding the server only registers it, and the xCloud tools stay unavailable until codex mcp login xcloud completes the OAuth sign-in in your browser. Type /mcp in Codex afterwards to confirm xcloud and its tools are listed.

Will Codex deploy my uncommitted changes?

No. xCloud clones the Git remote, so only pushed commits are deployed. If Codex fixes a build error in your working tree, ask it to commit and push before it retries the deployment.

Does the agent create the site as soon as I give it a repository URL?

No. It detects the repository and runs a dry run first, shows you the resolved configuration, and asks once. Only after you approve does it send the create call with an explicit confirmation and an idempotency key.

Can an agent deploy a private repository through xCloud?

Yes. Either the repository is on a Git provider connected to your xCloud team, or the agent prepares an SSH deploy key on the server for you to add to the repository. A private key or a personal access token is never sent in the request.

What does a 202 response mean during a deploy?

That xCloud queued the deployment. The agent polls the site status until it is terminal and reports deployed, failed or cancelled, then checks failed_steps and fetches the URL before calling the site live.

What happens when a deploy fails?

The agent reads the deployment diagnosis, which classifies the failing step and quotes the relevant log lines, proposes a fix from the fields xCloud lets it correct, and retries on the same site after your approval. It never deletes and recreates the site to retry.

Which servers can take a Git deploy?

Node.js, PHP and static builds deploy to Nginx or OpenLiteSpeed servers. Dockerfile and Compose apps, and other language stacks, need a Docker server. Agentic servers running OpenClaw, Hermes, Paperclip or DeepSeek Harness take no additional sites.

Other agents

Deploy from Git with Other Agents

The same job, the same xCloud tools, a guide for each client.

Run Your Hosting from Codex

xCloud MCP, the Agent Skills and the Public API are free with every account. Connect once and ask.