Grok Bot + xCloud

Install one-click apps with Grok Bot on xCloud

Installing one-click apps with Grok Bot means asking one of your Bots to search the xCloud catalogue, check an app against a server, install it once you approve and hand you the URL, while telling you which apps only the dashboard can install.

  • Skill: xcloud:deploy
  • Toolsets: oneclick-apps, catalog, servers
  • Free with every xCloud account

You@xcloud Install Uptime Kuma on the Frankfurt server on a staging hostname.

oneclickApps_compatibilityread-only

AgentUptime Kuma fits the Frankfurt Docker server. The stack and runtime match, and the latest monitoring snapshot shows enough RAM and disk. Install it on a free staging hostname?

YouYes.

oneclickApps_installneeds approval

oneclickApps_statusread-only

AgentI polled the install until every phase finished. It is live at https://status-test.example.xcloud.site. Want the login details? I will show them once.

. Keep a human in the loop: xCloud stops and asks before anything that creates, deploys, updates, reboots, deletes or buys.

Setup

How Do You Set Up Grok Bot to Install one-click apps on xCloud?

Connect Grok Bot once; every job on this account uses the same connection. Then ask in plain words.

  1. Ask a Bot to add xCloud as a Remote HTTPS MCP server

    In the Grok Bot desktop app, open any Bot's chat and ask it to add a custom MCP server of the Remote HTTPS kind, named xcloud, with this URL. The Bot adds it as a personal plugin from your own chat; the Marketplace in the sidebar only lists catalog connectors. The owner of a Team Bot adds the same kind of server from the Plugins card in the Bot's Setup panel instead. When the browser opens, sign in with xCloud, tick the teams the Bot may act on and choose Read-only or Full access.

    URL
    https://app.xcloud.host/mcp
  2. Attach it to a task and check it works

    In a Bot chat, type @ and pick xcloud to attach the connector to the task, then ask. A plugin you added from your own chat is personal and account-wide, so every Bot on your account can use it; a plugin added from a Team Bot's Setup panel belongs to that Team Bot, so check it in that Bot's chat. Put a standing boundary in the description of each Bot that may touch hosting, for example: never change production without approval.

    Prompt
    @xcloud Who am I on xCloud, and which servers and sites do I have?
  3. Team Bot without sign-ins? Use an API key

    A Remote HTTPS server added from the Plugins card in a Team Bot's Setup panel can run on the Bot's own credential instead of each person's sign-in, which suits a Team Bot that answers hosting questions for everyone. Create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things in Settings, Developers, API Tokens, and give the plugin this header where its form asks for one. Everyone who talks to that Bot then acts with the token's access, so keep it read-only unless the team should change things.

    Code
    Authorization: Bearer YOUR_TOKEN
  4. Check it worked

    Then ask Grok Bot for the job itself, for example:

    Prompt
    @xcloud I want a self-hosted uptime monitor. Search the one-click catalogue and tell me what each result needs from a server.

In practice

How Does One-click apps Work from Grok Bot?

Most people arrive at this job with a purpose, not an app name: a self-hosted uptime monitor, a blog, a note-taking tool. That suits a Bot, which you can brief in a sentence and leave to work. Type @xcloud, describe what you want, and the Bot calls oneclickApps_index to search the catalogue, then shows what it found and what each result needs from a server. Next it names the app and the server and calls oneclickApps_compatibility, which checks the stack, the runtime, the server state and the RAM, CPU and disk readings from the latest monitoring snapshot. If monitoring data is missing, the resource check was skipped, and a good Bot says the result is inconclusive instead of calling it a pass.

Eleven apps are the exception to all of that: n8n, Supabase, Nextcloud, Mautic, LibreChat, Open WebUI, Ollama, Umami, WireGuard, phpMyAdmin and Site.pro install only from the dashboard, under Add site, One-Click Apps, and the API answers 404 for them. Ask a Grok Bot for one of those and it should check that your server fits and then give you the dashboard path. The installs it can do go through oneclickApps_install after the explicit confirmation xCloud requires, and Grok Bot shows its own card as well, so you approve at two points. The Bot polls oneclickApps_status and tells you when each phase finishes. A failure names its phase, pre_install, install, post_install or provisioning, and the Bot reads the site's recent events before it suggests anything, instead of retrying.

The login details deserve a note that is specific to a Bot. When you ask, the Bot reads them with oneclickApps_credentials and shows them once in the reply. A Bot, though, is a teammate with a persistent conversation and a memory, so that reply stays in the conversation history. Copy the login into a password manager straight away and tell the Bot not to repeat it or keep it in a summary. Some apps have no generated login at all, because you create the first administrator inside the app, and the Bot should say so rather than invent one.

Grok Bot specific: Check the server before you ask a Grok Bot to install anything, because an agentic server never takes a one-click app: an OpenClaw, Hermes, Paperclip or DeepSeek Harness server hosts only the site created at provisioning. Do not confuse the Bot's cloud computer with a place to install the app, either. Grok Bot's computer lives in Cursor's cloud and is shared by all of your Bots, while a one-click app is installed by xCloud on your own server and is unaffected when you rename or delete a Bot. A 422 that says the app requires a different stack is not a Bot error. Pick a server on the stack the message names, and if a server is too small, ask the Bot for a larger one to compare instead of retrying.

What xCloud does for one-click apps

xCloud lists the one-click catalogue, checks whether an app fits a given server, installs it once you approve and reports each install phase until it finishes. Afterwards the agent can fetch the login details and stop, start or redeploy the app. A few apps install only from the dashboard, and the agent tells you where to click.

  1. Find the app. The agent searches the catalogue by name or purpose and shows what it found. An empty catalogue means the list has not synced on that environment, so the agent never answers that an app does not exist from an empty list.
  2. Read the install form. The agent reads the app's fields. Fields xCloud generates for you can be left out. For the address you choose a free xCloud staging hostname or your own domain, and a live domain needs the full site name.
  3. Check the server fits. You name the server, or the agent lists yours and asks. The compatibility check covers the server stack, runtime, state, billing and RAM, CPU and disk against the latest monitoring snapshot. If monitoring data is missing the resource check was skipped, and the agent says the result is inconclusive.
  4. Approve and install. The agent restates the app, the server and the address, and asks once. On your yes it sends the install with an explicit confirmation and an idempotency key, so a retried request cannot create a second copy.
  5. Poll the install. The agent polls the install status every five to ten seconds until it is terminal. A failure names its phase: pre_install, install, post_install or provisioning, so you know where it stopped.
  6. Hand over and manage. The agent gives you the URL. It fetches the login details only when you ask, shows them once in the reply and tells you to store them in a password manager. Later it can stop, start, restart or redeploy the app after your approval.

Reference

One-click apps Settings and Limits on xCloud

The facts Grok Bot works within when it installs one-click apps. Where a row names the dashboard, that step stays yours to take there.

Setting or limitWhat applies
CatalogueSearchable by name. It holds hundreds of apps, and most run on a Docker server. Public facts such as supported stacks and minimum size come from the catalogue listing
Compatibility checkPer server: stack, runtime, server state, billing and RAM, CPU and disk. monitor_available set to false means the resource check was skipped, not passed
Too-small serversA server that is too small stays too small. The agent suggests a larger server instead of retrying the install
Stack requirementsAn app that needs another stack is refused with a 422 that reads "This app requires a ... server. This server is on the ... stack."
Dashboard-only installsn8n, Supabase, Nextcloud, Mautic, LibreChat, Open WebUI, Ollama, Umami, WireGuard, phpMyAdmin and Site.pro. The API answers 404 for these eleven; install them from Add site, One-Click Apps in the dashboard
AddressStaging hostname for a free xCloud address, or go live with your own domain. A demo site promoted to a live domain cannot return to the demo address
IdempotencyThe install carries an Idempotency-Key, so a retried request cannot create a duplicate site
Install phasespre_install, install, post_install and provisioning. is_terminal marks the end, and failed_phase says where a failure happened
CredentialsRead on request and shown once in the reply. Some apps have none to read because you create the first admin inside the app
LifecycleStop, start, restart and redeploy run synchronously. Stop takes the app offline and redeploy recreates its containers. Both answer 422 while an install is running or after a failed install
Agentic serversAn OpenClaw, Hermes, Paperclip or DeepSeek Harness server never takes a one-click app

Rules Grok Bot has to follow

  • Installing, stopping and redeploying an app stop for your approval; browsing the catalogue and the compatibility check never change anything.
  • A missing resource reading is reported as inconclusive, never as a pass.
  • Login details are shown once, only when you ask, and never repeated in a summary or a later message.
  • For the eleven dashboard-only apps the agent checks that the server fits, then gives you the dashboard path instead of trying the install.
  • A failed install is not retried blindly: the agent names the failed phase and reads the site's recent events first.

Example prompts

What Can You Ask Grok Bot to Do for One-click apps?

Type these as written and swap in your own repository, site and server names. Reads and routine actions such as backups, cache purges, PageSpeed scans and vulnerability scans run straight away; creating, deploying, updating, rebooting, deleting, buying or starting a broken-link scan stops and asks first.

Prompt
@xcloud I want a self-hosted uptime monitor. Search the one-click catalogue and tell me what each result needs from a server.
Prompt
@xcloud Check whether Immich fits my Amsterdam server. If the resource check is inconclusive, say so instead of guessing.
Prompt
@xcloud Install Uptime Kuma on the Frankfurt server on a staging hostname. Wait until it is ready, then show me the login once and do not repeat it later.
Prompt
Which one-click apps are compatible with my Frankfurt server?
Prompt
Search the one-click catalogue for a self-hosted blog and tell me what each result needs from a server.
Prompt
Install Uptime Kuma on the Frankfurt server on a staging hostname, wait until it is ready, then give me the login details.
Prompt
Check whether Immich fits my Amsterdam server before I install it, and tell me if the resource check was inconclusive.
Prompt
I want n8n on my Frankfurt server. Check that the server fits, then tell me where to click to install it.
Prompt
The Uptime Kuma install on the Frankfurt server failed. Which phase failed, and what do the recent events say?
Prompt
Redeploy the Ghost app on blog.example.com, but tell me what a redeploy does before you run it.

Grok Bot and One-click apps: Frequently Asked Questions

What people ask before they let Grok Bot install one-click apps through xCloud.

Can a Grok Bot install n8n for me on xCloud?

Not by itself. n8n is one of eleven apps that install only from the dashboard, under Add site, One-Click Apps, because the API answers 404 for them. The Bot can check that your server fits and give you that path, and it can manage the rest of the catalogue.

Is it safe to have a Grok Bot read the login details of an app?

The Bot shows them once in the reply and only when you ask. Because a Bot keeps its conversations and summaries, copy them into a password manager and tell it not to repeat or remember them. Some apps have no generated login because you create the first administrator inside the app.

Can an agent install any app in the one-click catalogue?

Most of them. Eleven apps install only from the dashboard: n8n, Supabase, Nextcloud, Mautic, LibreChat, Open WebUI, Ollama, Umami, WireGuard, phpMyAdmin and Site.pro. For those the agent checks that your server fits and points you to Add site, One-Click Apps.

How does the agent know an app will fit my server?

It runs the compatibility check for that server, which covers the stack, runtime, server state, billing and the RAM, CPU and disk readings from the latest monitoring snapshot. If monitoring data is missing, the agent tells you the resource check was inconclusive.

What does a 422 during an app install mean?

Usually that the app needs a different server stack than the one you picked, and the message names both. Pick a server on the required stack. A 422 on stop, start or redeploy means an install is still running or the last install failed.

Where do the login details for a one-click app come from?

The agent can read them from xCloud when you ask and shows them once in the reply. Store them in a password manager. Some apps have no generated login because you create the first administrator inside the app.

Can an agent stop or restart a one-click app?

Yes. Stop, start, restart and redeploy are available, and they run straight away once you approve. Stop takes the app offline and redeploy recreates its containers, so the agent asks before either.

Other agents

One-click apps with Other Agents

The same job, the same xCloud tools, a guide for each client.

Run Your Hosting from Grok Bot

xCloud MCP, the Agent Skills and the Public API are free with every account. Connect once and ask.