Grok + xCloud

Manage Your Hosting from Grok Build with xCloud

Grok Build is xAI's coding agent for the terminal. Connected to xCloud through the MCP server, it deploys repositories, takes backups, updates WordPress, renews SSL and diagnoses failures from the shell you already work in.

  • One command: grok mcp add
  • Browser OAuth on first use
  • Free with every xCloud account

YouBack up example.com and tell me when the last backup ran.

sites_backupsread-only

AgentThe last backup ran 26 hours ago. I will start a new one now.

sites_backup

AgentBackup started. I will check it finishes before I report back.

AgentDone. The new backup of example.com completed a minute ago.

. Keep a human in the loop: xCloud stops and asks before anything that creates, deploys, updates, reboots, deletes or buys.

Setup

How Do I Connect Grok to xCloud?

Point Grok at the xCloud MCP server, approve access in your browser, then ask. The whole thing takes a couple of minutes.

  1. Add the xCloud MCP server

    Run this in your terminal, then start grok. The first time it calls xCloud, a browser opens on the xCloud approval screen, where you tick the teams and choose Read-only or Full access. Add --scope project to save the entry in .grok/config.toml for one repository instead.

    Terminal
    grok mcp add --transport http xcloud https://app.xcloud.host/mcp
  2. Or edit ~/.grok/config.toml

    Add this table to ~/.grok/config.toml, then run grok mcp doctor xcloud to check the connection. The url key is the one for HTTP servers.

    TOML
    [mcp_servers.xcloud]
    url = "https://app.xcloud.host/mcp"
  3. No browser? Use an API key

    For a headless machine, create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things in Settings, Developers, API Tokens. Put it in an environment variable the machine starts Grok with, such as XCLOUD_TOKEN in a systemd EnvironmentFile or your shell profile, and pass a reference to it with --header. Keep the single quotes so the shell leaves ${XCLOUD_TOKEN} alone: Grok expands ${VAR} in headers when it loads the config, so the token itself never lands in your shell history or in config.toml. Run grok mcp doctor xcloud to confirm it works.

    Terminal
    grok mcp add --transport http --header 'Authorization: Bearer ${XCLOUD_TOKEN}' xcloud https://app.xcloud.host/mcp
  4. Check it worked

    Grok Build runs a browser OAuth flow on first use and stores the tokens under ~/.grok, so nothing goes into config.toml. A headless machine passes an API key with the mcp:invoke scope and the abilities it needs as a header.

    Prompt
    Who am I on xCloud?

Three surfaces

Which Way Should I Connect Grok to xCloud?

The MCP server exposes one tool per customer-facing xCloud operation and leaves out eleven internal ones that only the Public API carries; the skills add workflow know-how on top of an MCP connection and, on their own, only read access. All three are free with every account and differ in what you set up and what holds the credentials.

xCloud MCP serverxCloud Agent SkillsPublic API
Terminal neededNo (recommended for Grok)Yes for the plugin or ClawHub installYes
AuthenticationOAuth sign-in, or an API key with mcp:invoke plus read or write abilities (recommended for Grok)The MCP connection, or a read-scoped API tokenAPI token with scoped abilities
What it addsOne tool per customer-facing xCloud operation (188 today) (recommended for Grok)Workflow know-how: routing, dry run, confirm, poll, diagnoseRaw REST for your own code
Changes to your infrastructureYes, after confirmation (recommended for Grok)Only through a connected MCP tool, after confirmationYes, with write scopes
Best forMost people; every MCP client (recommended for Grok)Agents that run shell commands and read skillsCI jobs, dashboards and long-running loops

Background

What Is Grok?

Grok Build is xAI's agent for coding in the terminal. You run grok in a project, ask for what you want and it works through the task with tools, including tools from MCP servers you add.

It is a Model Context Protocol client. You register a server with grok mcp add or in a [mcp_servers] table in ~/.grok/config.toml, check it with grok mcp list and grok mcp doctor, and open the MCP tab in a session with /mcps. Servers that need OAuth start a browser sign-in on first use.

xCloud's MCP server is a remote server of that kind. Once it is registered, Grok Build gets one tool per customer-facing xCloud operation, so a deploy, a backup or an SSL renewal is a sentence in the terminal instead of a trip to the dashboard.

Why Grok with xCloud?

One command to connect

grok mcp add writes the entry and OAuth starts in the browser on first use. grok mcp doctor checks the connection if something looks wrong.

Global or per project

Keep the entry in ~/.grok/config.toml to use xCloud everywhere, or add --scope project to keep it in one repository's .grok/config.toml.

Reuses config you already have

xAI's docs say Grok Build also loads MCP servers from ~/.claude.json, .cursor/mcp.json and a project .mcp.json. If xCloud is already set up in one of those clients, check grok mcp list before you add it again.

Example prompts

What Can You Ask Grok to Do on xCloud?

Type these as written and swap in your own site and server names. Reads and routine actions such as backups, cache purges, PageSpeed scans and vulnerability scans run straight away; creating, deploying, updating, rebooting, deleting, buying or starting a broken-link scan stops and asks first.

Prompt
Deploy https://github.com/acme/shop to my Frankfurt server and show me the dry run before you create anything.
Prompt
Update all plugins on example.com, but take a backup first and confirm the homepage still loads afterwards.
Prompt
The last deploy of the API site failed. Diagnose it, fix the build command and retry on the same site.
Prompt
Renew the SSL certificate for shop.example.com and tell me when it expires now.
Prompt
Audit example.com: is it up, is SSL healthy, any vulnerabilities, and how is performance?

Good to know

  • This page covers Grok Build, the terminal agent. Grok at grok.com has its own connector settings: check Grok's connector settings for a custom MCP connector and use the same server URL, https://app.xcloud.host/mcp.
  • Remote servers need --transport http on the command line. Without it, grok mcp add treats the argument as a local command.
  • OAuth tokens are kept in ~/.grok/mcp_credentials.json. Keep that file out of version control and out of backups you share.
  • If xCloud tools do not appear, run grok mcp doctor xcloud, then restart grok.

More prompts, grouped by job: What you can ask xCloud MCP to do.

Grok and xCloud: Frequently Asked Questions

Short answers about connecting Grok, what it may change and what it costs.

How do I connect Grok Build to xCloud?

Run grok mcp add --transport http xcloud https://app.xcloud.host/mcp in your terminal, then start grok and ask who you are on xCloud. A browser opens the first time so you can approve the teams and the access level.

What is the config.toml form for xCloud?

Add a [mcp_servers.xcloud] table to ~/.grok/config.toml with url set to https://app.xcloud.host/mcp. Then run grok mcp doctor xcloud to check the connection. Use grok mcp add with --scope project to keep the entry in a repository's .grok/config.toml instead.

Can I use xCloud from Grok at grok.com?

Yes, through a custom connector. Go to grok.com/connectors, choose New Connector, then Custom, enter https://app.xcloud.host/mcp as the server URL and sign in with xCloud when the browser asks; xAI's connectors page documents that flow. On Grok Business and Enterprise a team admin has to provision the connector in the cloud console before members can use it. The rest of this page covers Grok Build, the terminal agent.

Do I need an xCloud API key for Grok Build?

Not when you sign in with OAuth. Servers that need OAuth open a browser flow on first use. An API key is only for machines without a browser: create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things and pass it with the --header flag.

Can Grok Build change my servers without asking?

Not for the operations xCloud gates. Reads run straight away, and routine actions such as cache purges, backups, PageSpeed and vulnerability scans run without a prompt. Creating a site or server, deploying, updating plugins, rebooting, deleting or buying needs an explicit confirmation, and xCloud refuses the call without one.

How do I check or remove the xCloud server in Grok Build?

Run grok mcp list to see the configured servers and grok mcp doctor xcloud to diagnose the connection. Run grok mcp remove xcloud to take it out. Inside a session, /mcps opens the MCP tab.

Can Grok Build work across several xCloud teams?

Yes. On the approval screen you tick every team the connection may act on, and you name the team in your request. A site on a team you did not tick comes back as not found; reconnect and tick that team.

Is it free to use Grok Build with xCloud?

The xCloud side is free: the MCP server, the skills and the Public API are included with every xCloud account, including the free plan. Grok Build itself is provided by xAI under its own terms and pricing.

Other agents

Also Works With

The same xCloud account, the same operations, a guide for each client.

Run Your Hosting from Grok

xCloud MCP, the Agent Skills and the Public API are free with every account. Connect once and ask.