Gemini CLI + xCloud

Back up and stage sites with Gemini CLI on xCloud

Backing up and staging sites with Gemini CLI means typing a request into Google's terminal agent so it checks your xCloud backups, takes one before a change and creates a staging copy of your branch through the xcloud MCP server.

  • Skill: xcloud:sites
  • Toolsets: sites
  • Free with every xCloud account

YouBackup status for shop.example.com, then take a new backup.

mcp_xcloud_sites_backupStatusread-only

AgentNative site. Daily schedule, last backup 21 hours ago, completed, local storage. Allow me to start a new backup?

YouAllow once.

mcp_xcloud_sites_backup

AgentBackup completed. Staging and restores are separate: restore is in the dashboard under Site > Site Backup > Previous Backups.

. Keep a human in the loop: xCloud stops and asks before anything that creates, deploys, updates, reboots, deletes or buys.

Setup

How Do You Set Up Gemini CLI to Back up and stage sites on xCloud?

Connect Gemini CLI once; every job on this account uses the same connection. Then ask in plain words.

  1. Add the xCloud MCP server

    Run this in your terminal, then start gemini. The --scope user flag writes the server to ~/.gemini/settings.json so it is available in every project; without it, gemini mcp add writes to the current project's .gemini/settings.json and refuses to run from your home directory. The first time it calls xCloud it finds the OAuth endpoints, opens your browser on the xCloud approval screen and asks you to tick the teams and choose Read-only or Full access.

    Terminal
    gemini mcp add --scope user --transport http xcloud https://app.xcloud.host/mcp
  2. Or edit settings.json

    Add this to ~/.gemini/settings.json for every project, or to .gemini/settings.json in one project. This is the entry gemini mcp add writes: url plus type set to http. The older httpUrl key still works, but a url without a type is treated as an SSE server and will not connect. If the browser sign-in does not start, type /mcp auth xcloud inside Gemini CLI.

    JSON
    {
      "mcpServers": {
        "xcloud": {
          "url": "https://app.xcloud.host/mcp",
          "type": "http"
        }
      }
    }
  3. No browser? Use an API key

    For a headless machine, create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things in Settings, Developers, API Tokens and send it in the headers field. Keep the token out of version control, and keep the quotes: xCloud tokens contain a pipe character.

    JSON
    {
      "mcpServers": {
        "xcloud": {
          "url": "https://app.xcloud.host/mcp",
          "type": "http",
          "headers": {
            "Authorization": "Bearer YOUR_TOKEN"
          }
        }
      }
    }
  4. Check it worked

    Then ask Gemini CLI for the job itself, for example:

    Prompt
    Show the backup status for shop.example.com: last run, result, storage.

In practice

How Does Backups and staging Work from Gemini CLI?

Gemini CLI shows exactly what it is about to do, which suits a job where the order of operations matters. You start gemini in the project, ask whether the production site is backed up, and it calls the xCloud read tools. Gemini CLI names them mcp_xcloud_ followed by the operation, so you see mcp_xcloud_sites_backupSettings and mcp_xcloud_sites_backupStatus for a native site, or the sites_docker_backup read operations for a Docker app. Each call is listed in the terminal with its result, and the agent then summarises the schedule, the last backup time, the outcome and the storage location in a few lines.

Gemini CLI's confirmation dialog is the interesting part of the backup step. xCloud runs a backup without an approval prompt, so when you ask Gemini CLI to take one, the only thing that can stop mcp_xcloud_sites_backup is Gemini CLI itself, which asks you to allow the tool call unless you have marked the server as trusted. That is a good reason to keep the default. You approve the call once, Gemini CLI follows the backup until it reads completed or failed, and for a Docker app it tells you beforehand that the app is stopped briefly while its volumes are captured. If you want the agent to carry out a risky edit afterwards, put it in the same instruction so it only runs after a completed backup.

Staging works from the branch in your working directory, which Gemini CLI reads with git. For a Laravel, Node.js, custom PHP or Lovable site it proposes a staging environment, restates the site and branch, and waits for your yes before it calls the staging operation. Creating one needs a paid plan, and Gemini CLI relays xCloud's plan-limit answer on the free plan. If your tool list feels long, includeTools on the xcloud entry in settings.json can narrow it to the backup and staging operations you use for this job. WordPress staging, restores, native schedules and storage providers are dashboard steps, and the agent hands you the path, for example Site > Site Backup > Previous Backups > Restore.

Gemini CLI specific: Do not set trust to true on the xcloud entry for this job. xCloud starts a backup without any confirmation, so Gemini CLI's own tool dialog is the only prompt left, and trusting the server removes it. Streamable HTTP in settings.json is url plus type set to http, the form gemini mcp add writes, and the browser sign-in needs a browser on the same machine, so use an API key on a remote host.

What xCloud does for backups and staging

xCloud lets the agent read every site's backup state, start a backup on demand for native and Docker sites, and create a staging environment for Git sites. Restores, storage providers and WordPress staging stay in the dashboard, and the agent tells you the exact path when you ask for one.

  1. Find the site. The agent resolves the site by name or domain, restates which one it is about to act on, and reads whether it is a native site or a Docker app, because the two use different backup operations.
  2. Read the protection state. It reads the backup settings, status, count and recent backups. That answers whether the site has a schedule, when the last backup ran, whether it succeeded and where it is stored, before anything is changed.
  3. Back up now. A backup starts without an approval prompt. A native site takes a local backup by default or a remote one when a storage provider is connected. A Docker app is stopped briefly while its volumes are captured, so the agent says so before it backs up a production app.
  4. Wait for the result. xCloud queues the backup and returns straight away. The agent follows the backup task or row until it is terminal, then reports completed or failed instead of treating the queued response as done.
  5. Stage the change. For a Git site such as Laravel, Node.js, custom PHP or Lovable, the agent creates a staging environment from the branch you name, after you approve, and gives you its URL. A WordPress staging site is a dashboard step, and the agent gives you the path.
  6. Hand off restores and settings. If you ask to restore a backup, change a native site's schedule or add a storage provider, the agent explains that these are dashboard-only and gives the path and the site's dashboard link. It never improvises a workaround.

Reference

Backups and staging Settings and Limits on xCloud

The facts Gemini CLI works within when it backs up and stage sites. Where a row names the dashboard, that step stays yours to take there.

Setting or limitWhat applies
Native site backupOn demand through the API; the type is local (the default) or remote. A remote backup needs a storage provider with a working connection, otherwise xCloud refuses it with a 422 before anything is queued
Docker app backupOn demand through the API for Compose deploys and most one-click apps. The app is cold-stopped for a moment while volumes are captured. A remote copy goes to an S3-compatible or SFTP provider; Google Drive and pCloud are not supported for Docker apps
Reading backupsBackup list, count, status and settings are readable for every site. Docker apps also expose one backup's detail
Docker backup housekeepingThe agent can label a Docker backup with a note and delete one. Deleting is irreversible, so it names the exact backup by date and note first
Native schedule and retentionRead-only through the API. Change them in the dashboard under Site > Site Backup > Backup Settings
Docker backup settingsWritable through the API: automatic backup on or off, daily, weekly or monthly frequency, and the number of days to keep backups
RestoresDashboard-only for every site type: Site > Site Backup > Previous Backups > Restore. A backup can also be restored to another site from the same page
Storage providersDashboard-only, under Integrations > Storage Provider. Backup settings return a provider's identifier and status, never its credentials
Team-wide backup policyApplying one backup policy to many sites is dashboard-only, under Global Settings > Site Backup
Git stagingCreated through the API for Git sites on paid plans. On the free plan xCloud answers 403 because it is a plan limit, not a permission
WordPress stagingDashboard-only: xCloud answers 422 when the API is asked for it. Push and pull between staging and production also happen in the dashboard
SnapshotsSnapshots are listed per site. The server-wide snapshot list holds site snapshots, not a server image. Taking or restoring a snapshot, and a whole-server provider backup, stay in the dashboard

Rules Gemini CLI has to follow

  • A backup runs without an approval prompt, but the agent says when it briefly stops a Docker app and does not trigger one on a busy production app without telling you.
  • A queued backup is not a finished backup: the agent reports completed or failed only after it has read the result.
  • Restoring a backup, changing a native site's schedule, adding a storage provider and creating WordPress staging are dashboard steps; the agent gives you the path instead of guessing an operation.
  • Creating a staging environment stops for your approval, and deleting a backup names the exact backup first.
  • Before you push staging data to production in the dashboard, take a backup of the production site so you can recover if the push goes wrong.

Example prompts

What Can You Ask Gemini CLI to Do for Backups and staging?

Type these as written and swap in your own repository, site and server names. Reads and routine actions such as backups, cache purges, PageSpeed scans and vulnerability scans run straight away; creating, deploying, updating, rebooting, deleting, buying or starting a broken-link scan stops and asks first.

Prompt
Show the backup status for shop.example.com: last run, result, storage.
Prompt
Take a backup of shop.example.com, wait until it is completed, then run the database migration in this repo.
Prompt
Create a staging environment for the API site from the branch I am on and print the URL.
Prompt
When was the last backup of the shop site, did it succeed, and where is it stored?
Prompt
Check the backup settings on every site and list the ones with no schedule.
Prompt
Take a backup of the n8n Docker app now, before I upgrade it, and tell me when it is done.
Prompt
Switch the n8n Docker app to a daily backup and keep backups for 14 days. Show me the change before you apply it.
Prompt
Create a staging environment for the API site from the feature/checkout branch and give me its URL.
Prompt
List the snapshots of the shop site and tell me which is newest.
Prompt
I need to restore the shop site to last night's backup. Tell me where to click.

Gemini CLI and Backups and staging: Frequently Asked Questions

What people ask before they let Gemini CLI back up and stage sites through xCloud.

Why does Gemini CLI ask before a backup that xCloud does not ask about?

xCloud treats a backup as a routine action and runs it without a prompt. The confirmation you see comes from Gemini CLI, which asks before it runs an MCP tool unless the server is marked as trusted. Keeping that prompt is worth it, because it is the only one left for a backup.

What are the backup tools called in Gemini CLI?

Gemini CLI prefixes xCloud operations with mcp_xcloud_, so a native site backup appears as mcp_xcloud_sites_backup and a Docker app backup as mcp_xcloud_sites_docker_backup. You do not need to type those names. Ask for the backup in plain words and the agent picks the tool.

Can an AI agent restore a backup for me?

No. Restoring a native or Docker backup is a dashboard step, under Site > Site Backup > Previous Backups > Restore. The agent can list the backups, tell you which one is newest and completed, and give you the site's dashboard link so you can start the restore yourself.

Does the agent ask before it takes a backup?

No. A backup is a routine action, so xCloud runs it without a confirmation prompt. For a Docker app the agent tells you first that the app stops briefly while its data is captured, and it reports the result only after the backup has finished.

Can the agent change my backup schedule?

For Docker apps, yes: it can turn automatic backups on or off, set daily, weekly or monthly, and set how many days backups are kept. For native sites the schedule, retention and destination are read-only through the API, so you change them in the dashboard under Site > Site Backup > Backup Settings.

Can the agent connect my S3 bucket or other storage?

No. Storage providers are added in the dashboard, under Integrations > Storage Provider, so credentials never pass through a chat. Once a provider exists, the agent can read which one a site's backup settings point at and use it for a remote backup.

Can the agent create a staging site for WordPress?

Not through the API. xCloud answers 422 for WordPress staging, so you create it in the dashboard from the site overview. For Laravel, Node.js, custom PHP and Lovable sites the agent can create a staging environment, which needs a paid plan.

Other agents

Backups and staging with Other Agents

The same job, the same xCloud tools, a guide for each client.

Run Your Hosting from Gemini CLI

xCloud MCP, the Agent Skills and the Public API are free with every account. Connect once and ask.