Gemini CLI + xCloud

Manage Your Hosting from Gemini CLI with xCloud

Gemini CLI is Google's command-line AI agent. Connected to xCloud through the MCP server, it deploys repositories, takes backups, updates WordPress, renews SSL and diagnoses failures from the terminal you already work in.

  • One command: gemini mcp add
  • OAuth discovered automatically
  • Free with every xCloud account

YouIs SSL healthy on shop.example.com? Renew it if it is close to expiring.

sites_sslread-only

AgentThe certificate expires in nine days. I can renew it now. Go ahead?

YouYes.

sites_ssl_renewneeds approval

AgentRenewed. The site answers 200 over https with the new certificate.

. Keep a human in the loop: xCloud stops and asks before anything that creates, deploys, updates, reboots, deletes or buys.

Setup

How Do I Connect Gemini CLI to xCloud?

Point Gemini CLI at the xCloud MCP server, approve access in your browser, then ask. The whole thing takes a couple of minutes.

  1. Add the xCloud MCP server

    Run this in your terminal, then start gemini. The --scope user flag writes the server to ~/.gemini/settings.json so it is available in every project; without it, gemini mcp add writes to the current project's .gemini/settings.json and refuses to run from your home directory. The first time it calls xCloud it finds the OAuth endpoints, opens your browser on the xCloud approval screen and asks you to tick the teams and choose Read-only or Full access.

    Terminal
    gemini mcp add --scope user --transport http xcloud https://app.xcloud.host/mcp
  2. Or edit settings.json

    Add this to ~/.gemini/settings.json for every project, or to .gemini/settings.json in one project. This is the entry gemini mcp add writes: url plus type set to http. The older httpUrl key still works, but a url without a type is treated as an SSE server and will not connect. If the browser sign-in does not start, type /mcp auth xcloud inside Gemini CLI.

    JSON
    {
      "mcpServers": {
        "xcloud": {
          "url": "https://app.xcloud.host/mcp",
          "type": "http"
        }
      }
    }
  3. No browser? Use an API key

    For a headless machine, create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things in Settings, Developers, API Tokens and send it in the headers field. Keep the token out of version control, and keep the quotes: xCloud tokens contain a pipe character.

    JSON
    {
      "mcpServers": {
        "xcloud": {
          "url": "https://app.xcloud.host/mcp",
          "type": "http",
          "headers": {
            "Authorization": "Bearer YOUR_TOKEN"
          }
        }
      }
    }
  4. Check it worked

    Gemini CLI detects the 401 from xCloud and runs the OAuth flow in your browser, so there is no token to paste into settings.json; Gemini CLI keeps the OAuth tokens it receives in its own credential store. A headless machine sends an API key with the mcp:invoke scope and the abilities it needs in the headers field.

    Prompt
    Who am I on xCloud?

Three surfaces

Which Way Should I Connect Gemini CLI to xCloud?

The MCP server exposes one tool per customer-facing xCloud operation and leaves out eleven internal ones that only the Public API carries; the skills add workflow know-how on top of an MCP connection and, on their own, only read access. All three are free with every account and differ in what you set up and what holds the credentials.

xCloud MCP serverxCloud Agent SkillsPublic API
Terminal neededNo (recommended for Gemini CLI)Yes for the plugin or ClawHub installYes
AuthenticationOAuth sign-in, or an API key with mcp:invoke plus read or write abilities (recommended for Gemini CLI)The MCP connection, or a read-scoped API tokenAPI token with scoped abilities
What it addsOne tool per customer-facing xCloud operation (188 today) (recommended for Gemini CLI)Workflow know-how: routing, dry run, confirm, poll, diagnoseRaw REST for your own code
Changes to your infrastructureYes, after confirmation (recommended for Gemini CLI)Only through a connected MCP tool, after confirmationYes, with write scopes
Best forMost people; every MCP client (recommended for Gemini CLI)Agents that run shell commands and read skillsCI jobs, dashboards and long-running loops

Background

What Is Gemini CLI?

Gemini CLI is Google's command-line AI agent. It runs in your terminal, reads the files in your project, runs commands and works through multi-step tasks, asking for confirmation before it uses a tool that changes something.

It is a Model Context Protocol client. You register servers with gemini mcp add or in the mcpServers section of settings.json, and Gemini CLI discovers each server's tools and names them mcp_ followed by the server name and the tool name, so tools from different servers never collide.

xCloud's MCP server is a remote server of that kind. Once it is registered, Gemini CLI gets one tool per customer-facing xCloud operation, and a deploy, a backup or an SSL renewal becomes a sentence in the terminal instead of a trip to the dashboard.

Why Gemini CLI with xCloud?

One command, no config file

gemini mcp add writes the settings entry for you, and OAuth is found automatically when xCloud answers with a 401. There is no client ID to create and no token to paste.

User or project scope

Put the entry in ~/.gemini/settings.json to use xCloud everywhere, or in a project's .gemini/settings.json to keep it with that repository.

Confirmations stay on

Gemini CLI asks before it runs a tool, and xCloud adds its own confirmation rule for anything that creates, deploys, updates, reboots, deletes or buys. Two checks sit between a request and a change.

Guides

What Can Gemini CLI Do on xCloud?

One guide per hosting job, each with the Gemini CLI setup, the xCloud tools involved, a settings reference, example prompts and the limits that apply.

Example prompts

What Can You Ask Gemini CLI to Do on xCloud?

Type these as written and swap in your own site and server names. Reads and routine actions such as backups, cache purges, PageSpeed scans and vulnerability scans run straight away; creating, deploying, updating, rebooting, deleting, buying or starting a broken-link scan stops and asks first.

Prompt
Deploy https://github.com/acme/shop to my Frankfurt server and show me the dry run before you create anything.
Prompt
Update all plugins on example.com, but take a backup first and confirm the homepage still loads afterwards.
Prompt
The last deploy of the API site failed. Diagnose it, fix the build command and retry on the same site.
Prompt
Renew the SSL certificate for shop.example.com and tell me when it expires now.
Prompt
Audit example.com: is it up, is SSL healthy, any vulnerabilities, and how is performance?

Good to know

  • In settings.json a streamable HTTP server is url plus type set to http, which is what gemini mcp add writes; the older httpUrl key still works. A url without a type is treated as an SSE server and will not connect.
  • Do not set trust to true on the xcloud entry. It makes Gemini CLI skip its own tool confirmation dialogs.
  • The browser sign-in redirects to a localhost port, so it needs a browser on the same machine. On a remote or headless host, use the API-key form.
  • Gemini CLI names tools mcp_xcloud_ followed by the operation name. Use includeTools or excludeTools on the entry if you want a smaller tool list.

More prompts, grouped by job: What you can ask xCloud MCP to do.

Gemini CLI and xCloud: Frequently Asked Questions

Short answers about connecting Gemini CLI, what it may change and what it costs.

How do I connect Gemini CLI to xCloud?

Run gemini mcp add --scope user --transport http xcloud https://app.xcloud.host/mcp in your terminal, then start gemini and ask who you are on xCloud. The --scope user flag registers the server for every project instead of only the current one. Approve the access level in the browser tab that opens the first time.

What is the settings.json form for xCloud?

Under mcpServers add an xcloud entry with url set to https://app.xcloud.host/mcp and type set to http, which is what gemini mcp add writes. Use ~/.gemini/settings.json for every project or .gemini/settings.json for one. The older httpUrl key still works; a url without a type means SSE.

Do I need an xCloud API key for Gemini CLI?

Not when you sign in with OAuth. Gemini CLI finds the authorization endpoints itself and opens your browser. An API key is only for machines without a browser: create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things and send it in the headers field as an Authorization Bearer value.

What if the sign-in does not start?

Type /mcp auth xcloud inside Gemini CLI to start the OAuth flow by hand. The redirect goes to a localhost port, so run it on a machine that has a browser. Run gemini mcp list to check that the xcloud server is registered.

Can Gemini CLI change my servers without asking?

Not for the operations xCloud gates. Reads run straight away, and routine actions such as cache purges, backups, PageSpeed and vulnerability scans run without a prompt. Creating a site or server, deploying, updating plugins, rebooting, deleting or buying needs an explicit confirmation, and xCloud refuses the call without one.

How do I remove or reconnect the xCloud server?

Run gemini mcp remove xcloud to take it out, then add it again with gemini mcp add. Run gemini mcp list at any time to see which servers are configured and their status.

Can Gemini CLI work across several xCloud teams?

Yes. On the approval screen you tick every team the connection may act on, and you name the team in your request. A site on a team you did not tick comes back as not found; reconnect and tick that team.

Is it free to use Gemini CLI with xCloud?

The xCloud side is free: the MCP server, the skills and the Public API are included with every xCloud account, including the free plan. Gemini CLI itself follows Google's own terms and pricing.

Other agents

Also Works With

The same xCloud account, the same operations, a guide for each client.

Run Your Hosting from Gemini CLI

xCloud MCP, the Agent Skills and the Public API are free with every account. Connect once and ask.