Gemini CLI + xCloud
Install one-click apps with Gemini CLI on xCloud
Installing one-click apps with Gemini CLI means asking Google's terminal agent to check a catalogue app against your xCloud server and install it, or, for the few apps that install only from the dashboard, to tell you where to click.
- Skill: xcloud:deploy
- Toolsets: oneclick-apps, catalog, servers
- Free with every xCloud account
YouI want n8n on my Frankfurt server. Can you install it?
oneclickApps_compatibilityread-only
AgentFrankfurt fits n8n: right stack, enough RAM, CPU and disk. n8n installs only from the dashboard, though, so I cannot do it from here.
AgentIn the dashboard, open Add site, then One-Click Apps, pick n8n and choose Frankfurt. Want me to look up xCloud's setup guide for it?
. Keep a human in the loop: xCloud stops and asks before anything that creates, deploys, updates, reboots, deletes or buys.
Setup
How Do You Set Up Gemini CLI to Install one-click apps on xCloud?
Connect Gemini CLI once; every job on this account uses the same connection. Then ask in plain words.
Add the xCloud MCP server
Run this in your terminal, then start gemini. The --scope user flag writes the server to ~/.gemini/settings.json so it is available in every project; without it, gemini mcp add writes to the current project's .gemini/settings.json and refuses to run from your home directory. The first time it calls xCloud it finds the OAuth endpoints, opens your browser on the xCloud approval screen and asks you to tick the teams and choose Read-only or Full access.
gemini mcp add --scope user --transport http xcloud https://app.xcloud.host/mcpOr edit settings.json
Add this to ~/.gemini/settings.json for every project, or to .gemini/settings.json in one project. This is the entry gemini mcp add writes: url plus type set to http. The older httpUrl key still works, but a url without a type is treated as an SSE server and will not connect. If the browser sign-in does not start, type /mcp auth xcloud inside Gemini CLI.
{ "mcpServers": { "xcloud": { "url": "https://app.xcloud.host/mcp", "type": "http" } } }No browser? Use an API key
For a headless machine, create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things in Settings, Developers, API Tokens and send it in the headers field. Keep the token out of version control, and keep the quotes: xCloud tokens contain a pipe character.
{ "mcpServers": { "xcloud": { "url": "https://app.xcloud.host/mcp", "type": "http", "headers": { "Authorization": "Bearer YOUR_TOKEN" } } } }Check it worked
Then ask Gemini CLI for the job itself, for example:
I want n8n on my Frankfurt server. Check that it fits, then tell me where to click to install it.
In practice
How Does One-click apps Work from Gemini CLI?
Most requests in this job end with an install, but some end with a pointer, and Gemini CLI handles both in one session. Suppose you type that you want n8n on your Frankfurt server. Gemini CLI calls the catalogue search and then the compatibility check for the server, and reports whether it fits. n8n is one of eleven apps that xCloud installs only from the dashboard, so the agent does not try the install; it says the server fits and tells you to open Add site, then One-Click Apps, in the dashboard. The check is still worth having, because you learn about a size or stack problem before you click.
For an app the API can install, the terminal flow is brief. You ask for Uptime Kuma, Gemini CLI reads the install form, checks the server, restates the app, the server and the address, and waits for your yes. Then it installs and polls. Gemini CLI names MCP tools with an mcp_ prefix followed by the server name, so what you see in its tool list reads like mcp_xcloud_oneclickApps_install, and a lookup of what the agent called is a matter of scanning for that prefix. That makes it easy to confirm that the install call was the only write in the session.
Gemini CLI asks for confirmation before it runs a tool that changes something, which is a second line of defence behind xCloud's own approval for an install. The settings.json entry for a streamable HTTP server is url plus type set to http, the form gemini mcp add writes, and the first call finds the OAuth endpoints and opens your browser, so there is no token to paste. Because the agent works from the terminal you started it in, you can ask it to write the install summary, minus any login details, into a file in the directory you are in.
Gemini CLI specific: The compatibility check can pass for an app that still cannot be installed from the CLI, because eleven apps install only from the dashboard: n8n, Supabase, Nextcloud, Mautic, LibreChat, Open WebUI, Ollama, Umami, WireGuard, phpMyAdmin and Site.pro. A fit result is not an install result, so read the agent's next sentence. If the browser sign-in does not start on the first call, type /mcp auth xcloud inside Gemini CLI to start it.
What xCloud does for one-click apps
xCloud lists the one-click catalogue, checks whether an app fits a given server, installs it once you approve and reports each install phase until it finishes. Afterwards the agent can fetch the login details and stop, start or redeploy the app. A few apps install only from the dashboard, and the agent tells you where to click.
- Find the app. The agent searches the catalogue by name or purpose and shows what it found. An empty catalogue means the list has not synced on that environment, so the agent never answers that an app does not exist from an empty list.
- Read the install form. The agent reads the app's fields. Fields xCloud generates for you can be left out. For the address you choose a free xCloud staging hostname or your own domain, and a live domain needs the full site name.
- Check the server fits. You name the server, or the agent lists yours and asks. The compatibility check covers the server stack, runtime, state, billing and RAM, CPU and disk against the latest monitoring snapshot. If monitoring data is missing the resource check was skipped, and the agent says the result is inconclusive.
- Approve and install. The agent restates the app, the server and the address, and asks once. On your yes it sends the install with an explicit confirmation and an idempotency key, so a retried request cannot create a second copy.
- Poll the install. The agent polls the install status every five to ten seconds until it is terminal. A failure names its phase: pre_install, install, post_install or provisioning, so you know where it stopped.
- Hand over and manage. The agent gives you the URL. It fetches the login details only when you ask, shows them once in the reply and tells you to store them in a password manager. Later it can stop, start, restart or redeploy the app after your approval.
Reference
One-click apps Settings and Limits on xCloud
The facts Gemini CLI works within when it installs one-click apps. Where a row names the dashboard, that step stays yours to take there.
| Setting or limit | What applies |
|---|---|
| Catalogue | Searchable by name. It holds hundreds of apps, and most run on a Docker server. Public facts such as supported stacks and minimum size come from the catalogue listing |
| Compatibility check | Per server: stack, runtime, server state, billing and RAM, CPU and disk. monitor_available set to false means the resource check was skipped, not passed |
| Too-small servers | A server that is too small stays too small. The agent suggests a larger server instead of retrying the install |
| Stack requirements | An app that needs another stack is refused with a 422 that reads "This app requires a ... server. This server is on the ... stack." |
| Dashboard-only installs | n8n, Supabase, Nextcloud, Mautic, LibreChat, Open WebUI, Ollama, Umami, WireGuard, phpMyAdmin and Site.pro. The API answers 404 for these eleven; install them from Add site, One-Click Apps in the dashboard |
| Address | Staging hostname for a free xCloud address, or go live with your own domain. A demo site promoted to a live domain cannot return to the demo address |
| Idempotency | The install carries an Idempotency-Key, so a retried request cannot create a duplicate site |
| Install phases | pre_install, install, post_install and provisioning. is_terminal marks the end, and failed_phase says where a failure happened |
| Credentials | Read on request and shown once in the reply. Some apps have none to read because you create the first admin inside the app |
| Lifecycle | Stop, start, restart and redeploy run synchronously. Stop takes the app offline and redeploy recreates its containers. Both answer 422 while an install is running or after a failed install |
| Agentic servers | An OpenClaw, Hermes, Paperclip or DeepSeek Harness server never takes a one-click app |
Rules Gemini CLI has to follow
- Installing, stopping and redeploying an app stop for your approval; browsing the catalogue and the compatibility check never change anything.
- A missing resource reading is reported as inconclusive, never as a pass.
- Login details are shown once, only when you ask, and never repeated in a summary or a later message.
- For the eleven dashboard-only apps the agent checks that the server fits, then gives you the dashboard path instead of trying the install.
- A failed install is not retried blindly: the agent names the failed phase and reads the site's recent events first.
Example prompts
What Can You Ask Gemini CLI to Do for One-click apps?
Type these as written and swap in your own repository, site and server names. Reads and routine actions such as backups, cache purges, PageSpeed scans and vulnerability scans run straight away; creating, deploying, updating, rebooting, deleting, buying or starting a broken-link scan stops and asks first.
I want n8n on my Frankfurt server. Check that it fits, then tell me where to click to install it.Search the one-click catalogue for an uptime monitor and show what it needs from a server.Install Uptime Kuma on Frankfurt on a staging hostname once the compatibility check passes, and tell me when it is ready.Which one-click apps are compatible with my Frankfurt server?Search the one-click catalogue for a self-hosted blog and tell me what each result needs from a server.Install Uptime Kuma on the Frankfurt server on a staging hostname, wait until it is ready, then give me the login details.Check whether Immich fits my Amsterdam server before I install it, and tell me if the resource check was inconclusive.I want n8n on my Frankfurt server. Check that the server fits, then tell me where to click to install it.The Uptime Kuma install on the Frankfurt server failed. Which phase failed, and what do the recent events say?Redeploy the Ghost app on blog.example.com, but tell me what a redeploy does before you run it.Gemini CLI and One-click apps: Frequently Asked Questions
What people ask before they let Gemini CLI install one-click apps through xCloud.
Why does Gemini CLI send me to the dashboard for some apps?
Eleven catalogue apps, including n8n, Supabase and Nextcloud, install only from the dashboard, and xCloud's API answers 404 for them. Gemini CLI still checks that your server fits, then gives you the path: Add site, then One-Click Apps.
How can I see what Gemini CLI called during an install?
Gemini CLI names MCP tools with an mcp_ prefix and the server name, so xCloud calls appear as mcp_xcloud_ followed by the operation. Look for the install call to confirm what changed. Reads such as the catalogue search and compatibility check do not alter anything.
Can an agent install any app in the one-click catalogue?
Most of them. Eleven apps install only from the dashboard: n8n, Supabase, Nextcloud, Mautic, LibreChat, Open WebUI, Ollama, Umami, WireGuard, phpMyAdmin and Site.pro. For those the agent checks that your server fits and points you to Add site, One-Click Apps.
How does the agent know an app will fit my server?
It runs the compatibility check for that server, which covers the stack, runtime, server state, billing and the RAM, CPU and disk readings from the latest monitoring snapshot. If monitoring data is missing, the agent tells you the resource check was inconclusive.
What does a 422 during an app install mean?
Usually that the app needs a different server stack than the one you picked, and the message names both. Pick a server on the required stack. A 422 on stop, start or redeploy means an install is still running or the last install failed.
Where do the login details for a one-click app come from?
The agent can read them from xCloud when you ask and shows them once in the reply. Store them in a password manager. Some apps have no generated login because you create the first administrator inside the app.
Can an agent stop or restart a one-click app?
Yes. Stop, start, restart and redeploy are available, and they run straight away once you approve. Stop takes the app offline and redeploy recreates its containers, so the agent asks before either.
Other agents
One-click apps with Other Agents
The same job, the same xCloud tools, a guide for each client.
- Install one-click apps with Claude CodeAnthropic's terminal coding agent. One claude mcp add command, plus the xCloud skills plugin with nine skills on top.
- Install one-click apps with ClaudeAnthropic's chat assistant on the web and desktop. Add xCloud as a custom connector, no terminal needed.
- Install one-click apps with Claude CoworkAnthropic's desktop agent for delegated work. Add the xCloud connector, then hand off hosting jobs.
- Install one-click apps with CursorThe AI code editor. One mcp.json entry with the compact URL, because Cursor stops at 40 tools.
- Install one-click apps with CodexOpenAI's coding agent for the terminal. A codex mcp add command or a config.toml entry, then codex mcp login.
- Install one-click apps with OpenCodeThe open-source terminal coding agent. One remote MCP entry, then opencode mcp auth xcloud.
- Install one-click apps with Hermes AgentNous Research's agent with memory and a built-in scheduler. An mcp_servers entry in config.yaml and one login.
- Install one-click apps with OpenClawThe open-source agent runtime with chat apps and automations. ClawHub skill plus the MCP client.
- Install one-click apps with WindsurfThe Cognition editor, now Devin Desktop. devin mcp add for the Devin Local agent, a serverUrl entry for legacy Cascade.
- Install one-click apps with GitHub CopilotCopilot agent mode in VS Code. One .vscode/mcp.json entry, or the Agent Plugins package.
- Install one-click apps with ChatGPTOpenAI's chat assistant. A developer-mode app with the xCloud MCP URL and OAuth.
- Install one-click apps with ChatGPT dotsOpenAI's always-on agent in ChatGPT. Uses the xCloud MCP plugin you add in ChatGPT, with custom rules and scheduled tasks.
- Install one-click apps with GrokxAI's terminal agent, Grok Build. One grok mcp add command or a config.toml entry.
- Install one-click apps with Grok BotxAI's always-on Bots on a cloud computer. One Remote HTTPS MCP plugin, OAuth sign-in, routines on a schedule.
- Install one-click apps with KiroAWS's agentic IDE. One url entry in .kiro/settings/mcp.json, plus the portable xCloud Agent Plugins package.
- Install one-click apps with AntigravityGoogle's agentic IDE. One serverUrl entry in mcp_config.json and a browser sign-in.
- Install one-click apps with ZedThe Zed editor's Agent Panel. One context_servers entry in settings.json and a browser sign-in.
More Gemini CLI guides
- Gemini CLI and xCloud overview
- Deploy from Git with Gemini CLI
- Run Docker apps with Gemini CLI
- Manage WordPress with Gemini CLI
- Back up and stage sites with Gemini CLI
- Manage SSL and domains with Gemini CLI
- Manage servers with Gemini CLI
- Troubleshoot a broken site with Gemini CLI
- Speed up a slow site with Gemini CLI
- Secure sites and servers with Gemini CLI
Run Your Hosting from Gemini CLI
xCloud MCP, the Agent Skills and the Public API are free with every account. Connect once and ask.