Grok Bot + xCloud
Manage Your Hosting from Grok Bot with xCloud
Grok Bot is xAI's app for always-on AI teammates: named Bots that work on a persistent cloud computer with a browser, files and a terminal, and keep going while your laptop is closed. Connected to xCloud through the MCP server, a Bot deploys, backs up, updates and diagnoses your servers and sites on request or on a routine, and stops for your approval before it creates, deploys, updates, reboots or deletes anything.
- One Remote HTTPS plugin, no config file
- Routines that run while you are away
- Free with every xCloud account
You@xcloud Which of my sites are down, have a certificate about to expire or have WordPress updates waiting? Report only.
sites_indexread-only
sites_statusread-only
sites_sslread-only
sites_wordpress_updatesread-only
AgentAll 12 sites answer 200. The certificate on docs.example.com renews in 9 days. blog.example.com has 3 plugin updates waiting. Want me to back it up and apply them?
YouYes, go ahead.
sites_wordpress_updateneeds approval
AgentBackup finished and the 3 updates are applied. The homepage still answers 200.
. Keep a human in the loop: xCloud stops and asks before anything that creates, deploys, updates, reboots, deletes or buys.
Setup
How Do I Connect Grok Bot to xCloud?
Point Grok Bot at the xCloud MCP server, approve access in your browser, then ask. The whole thing takes a couple of minutes.
Ask a Bot to add xCloud as a Remote HTTPS MCP server
In the Grok Bot desktop app, open any Bot's chat and ask it to add a custom MCP server of the Remote HTTPS kind, named xcloud, with this URL. The Bot adds it as a personal plugin from your own chat; the Marketplace in the sidebar only lists catalog connectors. The owner of a Team Bot adds the same kind of server from the Plugins card in the Bot's Setup panel instead. When the browser opens, sign in with xCloud, tick the teams the Bot may act on and choose Read-only or Full access.
https://app.xcloud.host/mcpAttach it to a task and check it works
In a Bot chat, type @ and pick xcloud to attach the connector to the task, then ask. A plugin you added from your own chat is personal and account-wide, so every Bot on your account can use it; a plugin added from a Team Bot's Setup panel belongs to that Team Bot, so check it in that Bot's chat. Put a standing boundary in the description of each Bot that may touch hosting, for example: never change production without approval.
@xcloud Who am I on xCloud, and which servers and sites do I have?Team Bot without sign-ins? Use an API key
A Remote HTTPS server added from the Plugins card in a Team Bot's Setup panel can run on the Bot's own credential instead of each person's sign-in, which suits a Team Bot that answers hosting questions for everyone. Create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things in Settings, Developers, API Tokens, and give the plugin this header where its form asks for one. Everyone who talks to that Bot then acts with the token's access, so keep it read-only unless the team should change things.
Authorization: Bearer YOUR_TOKENCheck it worked
With OAuth each person signs in with xCloud once in the browser and approves the teams and the access level; the tokens stay on Cursor's connector backend and the Bot calls tools without seeing them. A Team Bot can instead carry an xCloud API key with the mcp:invoke scope and the abilities it needs as its own credential.
@xcloud Who am I on xCloud?
Three surfaces
Which Way Should I Connect Grok Bot to xCloud?
The MCP server exposes one tool per customer-facing xCloud operation and leaves out eleven internal ones that only the Public API carries; the skills add workflow know-how on top of an MCP connection and, on their own, only read access. All three are free with every account and differ in what you set up and what holds the credentials.
| xCloud MCP server | xCloud Agent Skills | Public API | |
|---|---|---|---|
| Terminal needed | No (recommended for Grok Bot) | Yes for the plugin or ClawHub install | Yes |
| Authentication | OAuth sign-in, or an API key with mcp:invoke plus read or write abilities (recommended for Grok Bot) | The MCP connection, or a read-scoped API token | API token with scoped abilities |
| What it adds | One tool per customer-facing xCloud operation (188 today) (recommended for Grok Bot) | Workflow know-how: routing, dry run, confirm, poll, diagnose | Raw REST for your own code |
| Changes to your infrastructure | Yes, after confirmation (recommended for Grok Bot) | Only through a connected MCP tool, after confirmation | Yes, with write scopes |
| Best for | Most people; every MCP client (recommended for Grok Bot) | Agents that run shell commands and read skills | CI jobs, dashboards and long-running loops |
Background
What Is Grok Bot?
Grok Bot is xAI's app for always-on AI teammates. You create named Bots, give each one a job and a description of how it should work, and message them from the desktop app on macOS, Windows or Linux, or from the mobile app. Each Bot works on a persistent cloud computer with a browser, a filesystem and a terminal, so tasks finish in real tools rather than as chat drafts, and work continues while your laptop is closed. Grok Bot is included with paid Cursor plans and Cursor Teams, or through a linked SuperGrok subscription, and the computers run in Cursor's cloud.
Bots reach outside services through connectors, which Grok Bot calls plugins. Catalog connectors come from the Marketplace in the sidebar; a custom Model Context Protocol server is added by asking a Bot in your own chat, or from the Plugins card in a Team Bot's Setup panel, as a Remote HTTPS server that each person signs in to or one that runs on the Bot's own credential. In chat you type @ to attach a connector to a task and / to reference a saved skill. Personal plugins are account-wide, and all of your Bots share one computer, so a connection you add from your own chat is available to your other Bots; a plugin added to a Team Bot is shared with that Team Bot's conversations instead.
Grok Bot also has routines: you ask the Bot that should own a recurring job when to run it and what to report, and it runs in the background on its schedule. That is what makes it a useful pairing with xCloud. One Bot can hold the hosting role, answer questions about servers and sites all day, run a morning check on its own, and stop at an approval card before it deploys, updates or deletes anything.
Why Grok Bot with xCloud?
A teammate that stays on
A Bot keeps its role, memory and connections across sessions. Make one Bot the hosting owner, tell it once which server is production and which sites are clients', and later requests lean on that context.
Checks that run while you sleep
Routines run on the Bot's cloud computer on a schedule, laptop open or not. Point one at xCloud for a daily look at downtime, expiring certificates, pending WordPress updates and new vulnerabilities, and read the report in the morning.
Approvals you can see
Grok Bot shows the proposed action and lets you Allow once, Always allow or Deny, and Auto Review rules can force a stop before production changes. xCloud adds its own rule: it refuses to create, deploy, update, reboot or delete without an explicit confirmation.
Guides
What Can Grok Bot Do on xCloud?
One guide per hosting job, each with the Grok Bot setup, the xCloud tools involved, a settings reference, example prompts and the limits that apply.
- Deploy from Git with Grok BotTurn a GitHub, GitLab or Bitbucket repository into a live site on a server you already have.
- Run Docker apps with Grok BotRun a Dockerfile or Docker Compose app on a Docker server, keep it backed up and recover it when a deploy fails.
- Install one-click apps with Grok BotPick an app from the xCloud catalogue, check it fits your server, install it and get the login details.
- Manage WordPress with Grok BotKeep WordPress sites updated, scanned and healthy, and create new ones, by asking in plain words.
- Back up and stage sites with Grok BotCheck that your sites are backed up, take a backup before a risky change, and open a staging copy to test it on.
- Manage SSL and domains with Grok BotCheck a site's certificate and DNS, install or renew HTTPS, and see which domains point at it.
- Manage servers with Grok BotSee how your servers are doing, change services and runtimes, tighten security and reboot with proof it worked.
- Troubleshoot a broken site with Grok BotFind out why a site returns a 500, 502 or 503, shows a critical error or has stopped answering.
- Speed up a slow site with Grok BotFind out why a site is slow, from real numbers, and learn which fix is a dashboard switch.
- Secure sites and servers with Grok BotFind vulnerable sites, manage server firewall rules and banned IPs, and see which protections are on.
Example prompts
What Can You Ask Grok Bot to Do on xCloud?
Type these as written and swap in your own site and server names. Reads and routine actions such as backups, cache purges, PageSpeed scans and vulnerability scans run straight away; creating, deploying, updating, rebooting, deleting, buying or starting a broken-link scan stops and asks first.
@xcloud Every weekday at 8:00 AM, check all my sites for downtime, expiring SSL certificates and pending WordPress updates, and post a short report here. Change nothing.@xcloud Deploy https://github.com/example/shop to my Frankfurt server on a staging hostname. Show me the dry run and wait for my approval before you create anything.@xcloud Back up every WordPress site that has pending updates, list what each update would change and wait for my go-ahead.@xcloud The API site returns a 502. Read the recent events and logs, find the cause and tell me what you would change before changing anything.Remember that my production server is the Frankfurt one and that client sites never get updated without my approval.Good to know
- Grok Bot works from a cloud computer in Cursor's cloud, so its calls to xCloud come from there, not from your laptop. The xCloud MCP URL is public and protected by OAuth, so that works; a server that only answers on a private network would not be reachable. Its traffic leaves through Cursor's shared static IP ranges; there is no dedicated per-customer egress IP, and an Enterprise team that needs its own source address routes the Bot through a member's desktop or its own network.
- Personal plugins are account-wide, so a connector you add from your own chat is available to all of your Bots, and your personal Bots all work on one computer in Cursor's cloud. A plugin on a Team Bot stays with that Team Bot, and a Team Bot's work runs on the computer of whoever is talking to it: the owner's in the owner's chat, each teammate's in their own chat or 1:1 Slack DM, and one shared computer, separate from everyone's, for Slack channels, group DMs and threads. Do not use separate Bots as a security boundary: put the boundary in each Bot's description and add an Ask first Auto-review rule for changes to production. Personal Auto-review rules are desktop-local and do not apply where nobody can answer a card, so for a Team Bot that works in Slack channels have your admin enforce the rule for the team or connect its xCloud plugin Read-only.
- Grok Bot inherits your team's Cursor connector policy. If the xcloud plugin shows Disabled by team admin, an admin enables it in the Teams Marketplace and, on Enterprise, adds https://app.xcloud.host/mcp to the MCP allowlist. Grok Bot itself needs a paid Cursor plan or a linked SuperGrok subscription.
- Grok Bot is not Grok chat and not Grok Build. The chat assistant on grok.com and the terminal coding agent have their own setups, and the Grok Build guide lives at /agents/grok/. This page is only for Bots in the Grok Bot app.
Run hosting checks on a schedule with routines
A routine tells one Bot when to run a workflow, on a schedule or, where supported, after an event. Ask the Bot that should own hosting checks in plain words: when to run, what to check, where to report and what it must not do. The Bot creates the routine and shows its next run. Use Test run before you rely on it, and open Routines under View conversation details to pause it, edit its schedule or read recent runs. Background routines run while your laptop is closed. Keep them to reads, PageSpeed and vulnerability scans and reports, and say so in the routine; start a backup only from a chat you are watching, because a Docker backup stops the app while it captures, and a broken-link scan, like any change, waits for your yes. xCloud refuses to create, deploy, update, reboot or delete without an explicit confirmation, so a routine that finds one of those jobs reports it and waits for you. Routine actions are different: a backup, a cache purge or a service restart runs without an xCloud prompt, and Test run performs real work, so a routine paired with an Always allow rule could carry them out unattended unless you write it to report only.
Every weekday at 8:00 AM, use @xcloud to check every site for downtime, expiring SSL certificates, pending WordPress updates and new vulnerabilities. Post a short report in this conversation. Report only and change nothing. If xCloud is unreachable, say so instead of reusing yesterday's data.More prompts, grouped by job: What you can ask xCloud MCP to do.
Grok Bot and xCloud: Frequently Asked Questions
Short answers about connecting Grok Bot, what it may change and what it costs.
How do I connect Grok Bot to xCloud?
Ask any Bot in the Grok Bot desktop app to add a custom MCP server of the Remote HTTPS kind, named xcloud, with the URL https://app.xcloud.host/mcp; it becomes a personal plugin from your own chat. The owner of a Team Bot adds it from the Plugins card in the Bot's Setup panel instead. Sign in with xCloud in the browser, tick your teams and choose Read-only or Full access. Then type @xcloud and ask who am I on xCloud to confirm: in any Bot chat for a personal plugin, or in that Team Bot's chat for a plugin added from its Setup panel.
Do I need an xCloud API key for Grok Bot?
Not for your own Bots. A Remote HTTPS server that uses OAuth asks you to sign in once, and xCloud supports dynamic client registration, so there is no client ID or token to paste. A Team Bot that should answer for everyone without sign-ins can carry an xCloud API key with the mcp:invoke scope as its own credential instead.
Can Grok Bot run xCloud checks on a schedule?
Yes. Ask the Bot that should own the job to create a routine, for example every weekday at 8:00 AM check my sites and post a report here. Routines run in the background on the Bot's cloud computer, a Bot can own up to 50 of them, and you manage them under Routines in the conversation details. Keep them to reads and reports and say so in the routine: xCloud stops for confirmation before it creates, deploys, updates, reboots or deletes, but routine actions such as a backup, a cache purge or a service restart run without that step, so an Always allow rule would let a routine carry them out unattended.
Can Grok Bot change my servers without asking?
Not for the operations xCloud gates. Grok Bot shows an approval card for consequential actions and lets you Allow once, Always allow or Deny, and you can add Ask first rules under Auto-review. xCloud refuses to create a site or server, deploy, update plugins, reboot, delete or buy without an explicit confirmation. Reads and routine actions such as a backup, a scan or a service restart run without an xCloud prompt, so for those your Grok Bot rule is the only gate, and an Always allow rule would let them run unattended, as would a Team Bot in a channel where nobody can answer a card, since personal Auto-review rules are desktop-local and only team-enforced rules apply there.
Is Grok Bot the same as Grok or Grok Build?
No. Grok is the chat assistant on grok.com and in the Grok apps, Grok Build is xAI's coding agent for the terminal, and Grok Bot is the app for always-on Bots with their own cloud computer. Each connects to xCloud differently; the Grok Build guide is at /agents/grok/ and this page covers Grok Bot.
Can my whole team use xCloud through one Team Bot?
Yes. Publish a Team Bot with the xcloud plugin. With OAuth, each teammate signs in with their own xCloud account the first time they need it, so the Bot acts as the person asking. With an API key as the Bot's own credential, everyone shares the token's access, so keep that token read-only unless the team should change things.
Why does my Bot say the xcloud plugin is disabled by team admin?
Your team's Cursor connector policy blocks that server. A team admin enables it in the Teams Marketplace on the Plugins and MCPs page and, on Enterprise, adds https://app.xcloud.host/mcp to the MCP allowlist. Restart the Grok Bot app afterwards.
Does Grok Bot connect to xCloud from my computer?
No. Bots work from a persistent cloud computer in Cursor's cloud, so requests to xCloud come from there. That works because the xCloud MCP URL is public and protected by OAuth. Your local computer is a separate capability that a Bot only uses when you allow it, and it is not involved in the xCloud connection.
Is it free to use Grok Bot with xCloud?
The xCloud side is free: the MCP server and the Public API are included with every xCloud account, including the free plan. Grok Bot itself comes with paid Cursor plans and Cursor Teams, or through a linked SuperGrok subscription, and its usage is billed by Cursor or xAI under that plan.
Other agents
Also Works With
The same xCloud account, the same operations, a guide for each client.
- Claude CodeAnthropic's terminal coding agent. One claude mcp add command, plus the xCloud skills plugin with nine skills on top.
- ClaudeAnthropic's chat assistant on the web and desktop. Add xCloud as a custom connector, no terminal needed.
- Claude CoworkAnthropic's desktop agent for delegated work. Add the xCloud connector, then hand off hosting jobs.
- CursorThe AI code editor. One mcp.json entry with the compact URL, because Cursor stops at 40 tools.
- CodexOpenAI's coding agent for the terminal. A codex mcp add command or a config.toml entry, then codex mcp login.
- OpenCodeThe open-source terminal coding agent. One remote MCP entry, then opencode mcp auth xcloud.
- Hermes AgentNous Research's agent with memory and a built-in scheduler. An mcp_servers entry in config.yaml and one login.
- OpenClawThe open-source agent runtime with chat apps and automations. ClawHub skill plus the MCP client.
- WindsurfThe Cognition editor, now Devin Desktop. devin mcp add for the Devin Local agent, a serverUrl entry for legacy Cascade.
- GitHub CopilotCopilot agent mode in VS Code. One .vscode/mcp.json entry, or the Agent Plugins package.
- Gemini CLIGoogle's terminal agent. One gemini mcp add command, OAuth found automatically.
- ChatGPTOpenAI's chat assistant. A developer-mode app with the xCloud MCP URL and OAuth.
- ChatGPT dotsOpenAI's always-on agent in ChatGPT. Uses the xCloud MCP plugin you add in ChatGPT, with custom rules and scheduled tasks.
- GrokxAI's terminal agent, Grok Build. One grok mcp add command or a config.toml entry.
- KiroAWS's agentic IDE. One url entry in .kiro/settings/mcp.json, plus the portable xCloud Agent Plugins package.
- AntigravityGoogle's agentic IDE. One serverUrl entry in mcp_config.json and a browser sign-in.
- ZedThe Zed editor's Agent Panel. One context_servers entry in settings.json and a browser sign-in.
Run Your Hosting from Grok Bot
xCloud MCP, the Agent Skills and the Public API are free with every account. Connect once and ask.