Grok Bot + xCloud
Manage servers with Grok Bot on xCloud
Managing servers with Grok Bot means giving an always-on Bot the job of reading your xCloud servers, flagging disk and load problems on a routine, and changing runtimes and firewall rules or rebooting only after you approve; a service restart or enable has no xCloud prompt, so there your Ask first rule, or a Read-only connection, is the gate.
- Skill: xcloud:servers
- Toolsets: servers, alerts, user
- Free with every xCloud account
You@xcloud Reboot the staging server and tell me when it is back.
servers_showread-only
Agentstaging-1 reports reboot required and hosts no production sites. Reboot it now?
YouYes.
servers_reboots_storeneeds approval
servers_reboots_showread-only
servers_servicesread-only
AgentI polled the reboot until xCloud verified a new boot. staging-1 is back and its services are running.
. Keep a human in the loop: xCloud stops and asks before anything that creates, deploys, updates, reboots, deletes or buys.
Setup
How Do You Set Up Grok Bot to Manage servers on xCloud?
Connect Grok Bot once; every job on this account uses the same connection. Then ask in plain words.
Ask a Bot to add xCloud as a Remote HTTPS MCP server
In the Grok Bot desktop app, open any Bot's chat and ask it to add a custom MCP server of the Remote HTTPS kind, named xcloud, with this URL. The Bot adds it as a personal plugin from your own chat; the Marketplace in the sidebar only lists catalog connectors. The owner of a Team Bot adds the same kind of server from the Plugins card in the Bot's Setup panel instead. When the browser opens, sign in with xCloud, tick the teams the Bot may act on and choose Read-only or Full access.
https://app.xcloud.host/mcpAttach it to a task and check it works
In a Bot chat, type @ and pick xcloud to attach the connector to the task, then ask. A plugin you added from your own chat is personal and account-wide, so every Bot on your account can use it; a plugin added from a Team Bot's Setup panel belongs to that Team Bot, so check it in that Bot's chat. Put a standing boundary in the description of each Bot that may touch hosting, for example: never change production without approval.
@xcloud Who am I on xCloud, and which servers and sites do I have?Team Bot without sign-ins? Use an API key
A Remote HTTPS server added from the Plugins card in a Team Bot's Setup panel can run on the Bot's own credential instead of each person's sign-in, which suits a Team Bot that answers hosting questions for everyone. Create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things in Settings, Developers, API Tokens, and give the plugin this header where its form asks for one. Everyone who talks to that Bot then acts with the token's access, so keep it read-only unless the team should change things.
Authorization: Bearer YOUR_TOKENCheck it worked
Then ask Grok Bot for the job itself, for example:
@xcloud List all my xCloud servers with CPU, RAM and disk usage and flag any server above 80% disk. Change nothing.
In practice
How Does Server management Work from Grok Bot?
A server question rarely arrives at a convenient moment, and a Bot is the teammate that is already on. You message it from your phone: which of my servers is above 80% disk. The Bot attaches xcloud, calls servers_index and servers_monitoring and answers with CPU, RAM and disk in a short table, flagging statuses such as low disk space or reboot required. Monitoring history is a paid-plan feature, so on the free plan the answer says it is a plan limit, not a missing permission. Bots keep stable preferences in memory, so you can tell the hosting Bot once which server is production and which services must never be disabled, and later requests start from that.
Changes come in two kinds. Reads and routine actions run straight away: the Bot can restart a service with servers_services_restart without an xCloud prompt, and it should still name the server, the service and the impact first. Anything that can interrupt a server, such as a reboot, a runtime change, a firewall rule or a sudo user, stops for an explicit confirmation, and Grok Bot shows its own card as well. A reboot is tracked: the Bot calls servers_reboots_store, then reads servers_reboots_show until xCloud reports a verified new boot, and an unconfirmed result is investigated, never repeated. The Bot also reads servers_tasks until each accepted change settles, because xCloud returns before the work finishes.
A morning routine is where Grok Bot earns its place. Ask for one: every weekday at 8:00 AM, list my servers with CPU, RAM and disk, flag any above 80% disk or showing reboot required, and post here. It runs while your laptop is closed, you Test run it first, and recent runs sit under Routines in the conversation details. It reports. It never reboots or restarts on its own. Buying, resizing and deleting servers are different again: a purchase needs an approved plan, region and price, while resizing and deleting a server are dashboard-only.
Grok Bot specific: Set Ask first rules for server changes before you hand a Bot a server. Auto Review, under Settings, General, Auto-review, takes Ask first and Allow automatically rules, and Ask first wins, so a rule that names reboots, service changes and firewall rules keeps the card in front of you in your own chat even if you once chose Always allow. Personal rules are stored on your desktop, though, and in a Slack channel or group chat where nobody can answer a card a Team Bot runs without Auto-review and stays within the permissions it was set up with, unless your team admin enforces Auto-review. xCloud's own confirmation still stops a reboot, a runtime change, a firewall rule or a sudo user in any conversation, but restarting or enabling a service has no xCloud prompt, so for a Team Bot that works in channels either have the admin enforce a team Ask first rule for service changes or connect its xCloud plugin Read-only and keep service changes in a 1:1 chat. Disabling ssh, nginx or a database can lock you out or take sites offline, so ask the Bot to say what a change will do before you answer, and write the same boundary into the Bot's description so it applies in every chat.
What xCloud does for server management
xCloud lets the agent list your servers, read their monitoring, and manage services, Node.js and PHP versions, cron jobs, firewall rules, Fail2Ban and sudo users. Changes that can interrupt a server stop for your approval, and a reboot is only reported as done after xCloud verifies a new boot.
- Pick the team and the server. The agent works on one team at a time and uses the server you name. If a name is missing or matches several servers, it lists them and asks. It always restates which server it is about to change before it changes it.
- Read the state first. It reads the server's status, installed services, runtimes and monitoring figures. A status such as low disk space or reboot required is worth surfacing on its own. Monitoring history is a paid-plan feature, so a free plan answers 403.
- Say what will change, then ask. For a service, runtime, cron, firewall or sudo change, the agent names the server, the item and the impact, for example that a Node.js default affects every Node site on the server. It waits for your approval when the change could interrupt a service.
- Follow the task to the end. xCloud accepts server work and returns before it finishes. The agent reads the server's task list until the task settles and reports the real outcome, not the acceptance.
- Reboot with proof. A reboot starts a tracked operation. The agent reads that operation until xCloud reports a verified new boot. If the result is unconfirmed it investigates and never repeats the reboot just to check.
- Buy a server only after approval. A new server is billable. The agent checks what you already have, reads the plans and the card on file, shows the plan, region and price, and waits for a yes. It sends the purchase once with an idempotency key so a retry cannot buy a second server.
Reference
Server management Settings and Limits on xCloud
The facts Grok Bot works within when it manages servers. Where a row names the dashboard, that step stays yours to take there.
| Setting or limit | What applies |
|---|---|
| Inventory | Every server on the team with its status, stack and the sites it hosts, plus the tasks, supervisor processes and site snapshots on a server |
| Monitoring | Current CPU, memory and disk are readable. Monitoring history is a paid-plan feature: xCloud answers 403 on the free plan, which is a plan limit and not a permission |
| Services | Install, enable, restart and disable. A restart runs without a server-side prompt; the agent still confirms the exact server, service and impact before any service change, because disabling ssh, nginx or a database can lock you out or cause downtime |
| Node.js versions | Read the installed versions and set the default. The default is server-wide and affects every Node site on the server |
| PHP versions | Install, uninstall, set the default, patch and toggle OPcache. The server default changes only the command-line php and the version new sites get; it does not change existing sites, and a single site's PHP version is a dashboard setting under Site > Site Settings |
| Cron jobs | List, create, update, delete, run now and read the last output for server cron jobs. Site cron is a separate resource |
| Firewall rules | List, create, delete, enable and disable rules with a name, protocol, allow or deny, port and optional source IP |
| Fail2Ban and IP access | List, ban and unban IP addresses, read the SSH restriction status, and whitelist your current IP or xCloud's own IPs |
| Sudo users | List, create or update and delete sudo users. A password is a secret and private keys are never returned |
| Verified reboots | Start a tracked reboot and read its operation; only a verified new boot proves it worked. An unconfirmed reboot can be rechecked without rebooting again |
| Buying a server | Billable, so it needs an approved plan, region and price, a card on file and an idempotency key. It buys xCloud-managed servers only |
| Dashboard-only | Resizing or deleting a server, a provider backup of the whole server (Server > Backup), bringing your own server, databases and database users, and PHP settings such as memory limit or upload size |
Rules Grok Bot has to follow
- A change that can interrupt a server stops for your approval, and the agent names the server, the service and the impact first.
- Buying a server is billable: the agent shows the plan, region and price and waits for your yes, and it never retries a purchase without checking your server list first.
- A reboot is only reported as done when xCloud verifies a new boot, and an unconfirmed reboot is investigated, not repeated.
- Disabling ssh, nginx, a database or a runtime service needs your explicit confirmation immediately before the call, because it can lock you out or take sites offline.
- Resizing or deleting a server, provider server backups, bringing your own server and per-site PHP versions are dashboard steps; the agent gives you the path and the dashboard link xCloud returned.
Example prompts
What Can You Ask Grok Bot to Do for Server management?
Type these as written and swap in your own repository, site and server names. Reads and routine actions such as backups, cache purges, PageSpeed scans and vulnerability scans run straight away; creating, deploying, updating, rebooting, deleting, buying or starting a broken-link scan stops and asks first.
@xcloud List all my xCloud servers with CPU, RAM and disk usage and flag any server above 80% disk. Change nothing.@xcloud Switch the Frankfurt server's default Node.js to the latest LTS major. Tell me which sites it affects and wait for my approval.@xcloud Reboot the staging server and tell me when xCloud has verified that it came back.List all my xCloud servers with CPU, RAM and disk usage, and flag any server above 80% disk.List the cron jobs on the Frankfurt server with their schedules.Create a server cron job for the WooCommerce Action Scheduler every five minutes. Show me the final command and schedule before creating it.Install Redis on the Frankfurt server and enable the service.Switch the Frankfurt server's default Node.js to the latest LTS major.Reboot the staging server and tell me when it is back.Show me the IP addresses Fail2Ban has banned on the Frankfurt server, and unban 203.0.113.10.Create a new xCloud server on the smallest plan in Singapore. Show me the plan and price first and wait for my approval.Grok Bot and Server management: Frequently Asked Questions
What people ask before they let Grok Bot manage servers through xCloud.
Can a Grok Bot reboot my server while I am away?
Not unattended. A reboot stops for an explicit confirmation, so a routine can notice that a server needs a reboot and report it, then wait for your yes. After you approve, the Bot follows the tracked reboot until xCloud reports a verified new boot.
How do I keep my hosting Bot from changing production by accident?
Put the boundary in the Bot's description, for example never change production without approval, and add an Ask first rule under Auto-review for reboots, service changes and firewall rules. Ask first wins over Always allow in your own chats, but personal rules are desktop-local and do not cover a Team Bot in a channel where nobody can answer a card; there only team-enforced Auto-review rules or a Read-only connection hold. xCloud still requires its own confirmation before it reboots or deletes anything.
Does the agent ask before it reboots a server?
Yes. A reboot stops for your explicit confirmation, then the agent starts a tracked reboot and reads the operation until xCloud reports a verified new boot. If the result stays unconfirmed it investigates rather than rebooting a second time.
Can an AI agent buy a new server for me?
Yes, but only after you approve it. A new server is billable, so the agent first checks your existing servers, reads the available plans and your card on file, then shows the plan, region and price and waits for your yes. It sends the purchase once, so a retry cannot buy a second server.
If the agent changes the server's PHP default, do my sites change version?
No. The server default changes the command-line php and the version new sites get, and it moves no existing site. Each site keeps its own PHP version, which you change in the dashboard under Site > Site Settings.
Can the agent resize or delete a server?
No. Resizing and deleting a server are dashboard-only, as are a provider backup of the whole server, databases and bringing your own server. The agent can tell you where the control is and give you the server's dashboard link.
Why did the agent say monitoring history is not available?
Monitoring history is a paid-plan feature, so xCloud answers 403 on the free plan. Current CPU, memory and disk readings are still available, and the agent will say that it is a plan limit, not a missing permission.
Other agents
Server management with Other Agents
The same job, the same xCloud tools, a guide for each client.
- Manage servers with Claude CodeAnthropic's terminal coding agent. One claude mcp add command, plus the xCloud skills plugin with nine skills on top.
- Manage servers with ClaudeAnthropic's chat assistant on the web and desktop. Add xCloud as a custom connector, no terminal needed.
- Manage servers with Claude CoworkAnthropic's desktop agent for delegated work. Add the xCloud connector, then hand off hosting jobs.
- Manage servers with CursorThe AI code editor. One mcp.json entry with the compact URL, because Cursor stops at 40 tools.
- Manage servers with CodexOpenAI's coding agent for the terminal. A codex mcp add command or a config.toml entry, then codex mcp login.
- Manage servers with OpenCodeThe open-source terminal coding agent. One remote MCP entry, then opencode mcp auth xcloud.
- Manage servers with Hermes AgentNous Research's agent with memory and a built-in scheduler. An mcp_servers entry in config.yaml and one login.
- Manage servers with OpenClawThe open-source agent runtime with chat apps and automations. ClawHub skill plus the MCP client.
- Manage servers with WindsurfThe Cognition editor, now Devin Desktop. devin mcp add for the Devin Local agent, a serverUrl entry for legacy Cascade.
- Manage servers with GitHub CopilotCopilot agent mode in VS Code. One .vscode/mcp.json entry, or the Agent Plugins package.
- Manage servers with Gemini CLIGoogle's terminal agent. One gemini mcp add command, OAuth found automatically.
- Manage servers with ChatGPTOpenAI's chat assistant. A developer-mode app with the xCloud MCP URL and OAuth.
- Manage servers with ChatGPT dotsOpenAI's always-on agent in ChatGPT. Uses the xCloud MCP plugin you add in ChatGPT, with custom rules and scheduled tasks.
- Manage servers with GrokxAI's terminal agent, Grok Build. One grok mcp add command or a config.toml entry.
- Manage servers with KiroAWS's agentic IDE. One url entry in .kiro/settings/mcp.json, plus the portable xCloud Agent Plugins package.
- Manage servers with AntigravityGoogle's agentic IDE. One serverUrl entry in mcp_config.json and a browser sign-in.
- Manage servers with ZedThe Zed editor's Agent Panel. One context_servers entry in settings.json and a browser sign-in.
More Grok Bot guides
- Grok Bot and xCloud overview
- Deploy from Git with Grok Bot
- Run Docker apps with Grok Bot
- Install one-click apps with Grok Bot
- Manage WordPress with Grok Bot
- Back up and stage sites with Grok Bot
- Manage SSL and domains with Grok Bot
- Troubleshoot a broken site with Grok Bot
- Speed up a slow site with Grok Bot
- Secure sites and servers with Grok Bot
Run Your Hosting from Grok Bot
xCloud MCP, the Agent Skills and the Public API are free with every account. Connect once and ask.