Grok + xCloud
Manage Your Hosting from Grok Build with xCloud
Grok Build is xAI's coding agent for the terminal. Connected to xCloud through the MCP server, it deploys repositories, takes backups, updates WordPress, renews SSL and diagnoses failures from the shell you already work in.
- One command: grok mcp add
- Browser OAuth on first use
- Free with every xCloud account
YouBack up example.com and tell me when the last backup ran.
sites_backupsread-only
AgentThe last backup ran 26 hours ago. I will start a new one now.
sites_backup
AgentBackup started. I will check it finishes before I report back.
AgentDone. The new backup of example.com completed a minute ago.
. Keep a human in the loop: xCloud stops and asks before anything that creates, deploys, updates, reboots, deletes or buys.
Setup
How Do I Connect Grok to xCloud?
Point Grok at the xCloud MCP server, approve access in your browser, then ask. The whole thing takes a couple of minutes.
Add the xCloud MCP server
Run this in your terminal, then start grok. The first time it calls xCloud, a browser opens on the xCloud approval screen, where you tick the teams and choose Read-only or Full access. Add --scope project to save the entry in .grok/config.toml for one repository instead.
grok mcp add --transport http xcloud https://app.xcloud.host/mcpOr edit ~/.grok/config.toml
Add this table to ~/.grok/config.toml, then run grok mcp doctor xcloud to check the connection. The url key is the one for HTTP servers.
[mcp_servers.xcloud] url = "https://app.xcloud.host/mcp"No browser? Use an API key
For a headless machine, create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things in Settings, Developers, API Tokens. Put it in an environment variable the machine starts Grok with, such as XCLOUD_TOKEN in a systemd EnvironmentFile or your shell profile, and pass a reference to it with --header. Keep the single quotes so the shell leaves ${XCLOUD_TOKEN} alone: Grok expands ${VAR} in headers when it loads the config, so the token itself never lands in your shell history or in config.toml. Run grok mcp doctor xcloud to confirm it works.
grok mcp add --transport http --header 'Authorization: Bearer ${XCLOUD_TOKEN}' xcloud https://app.xcloud.host/mcpCheck it worked
Grok Build runs a browser OAuth flow on first use and stores the tokens under ~/.grok, so nothing goes into config.toml. A headless machine passes an API key with the mcp:invoke scope and the abilities it needs as a header.
Who am I on xCloud?
Three surfaces
Which Way Should I Connect Grok to xCloud?
The MCP server exposes one tool per customer-facing xCloud operation and leaves out eleven internal ones that only the Public API carries; the skills add workflow know-how on top of an MCP connection and, on their own, only read access. All three are free with every account and differ in what you set up and what holds the credentials.
| xCloud MCP server | xCloud Agent Skills | Public API | |
|---|---|---|---|
| Terminal needed | No (recommended for Grok) | Yes for the plugin or ClawHub install | Yes |
| Authentication | OAuth sign-in, or an API key with mcp:invoke plus read or write abilities (recommended for Grok) | The MCP connection, or a read-scoped API token | API token with scoped abilities |
| What it adds | One tool per customer-facing xCloud operation (188 today) (recommended for Grok) | Workflow know-how: routing, dry run, confirm, poll, diagnose | Raw REST for your own code |
| Changes to your infrastructure | Yes, after confirmation (recommended for Grok) | Only through a connected MCP tool, after confirmation | Yes, with write scopes |
| Best for | Most people; every MCP client (recommended for Grok) | Agents that run shell commands and read skills | CI jobs, dashboards and long-running loops |
Background
What Is Grok?
Grok Build is xAI's agent for coding in the terminal. You run grok in a project, ask for what you want and it works through the task with tools, including tools from MCP servers you add.
It is a Model Context Protocol client. You register a server with grok mcp add or in a [mcp_servers] table in ~/.grok/config.toml, check it with grok mcp list and grok mcp doctor, and open the MCP tab in a session with /mcps. Servers that need OAuth start a browser sign-in on first use.
xCloud's MCP server is a remote server of that kind. Once it is registered, Grok Build gets one tool per customer-facing xCloud operation, so a deploy, a backup or an SSL renewal is a sentence in the terminal instead of a trip to the dashboard.
Why Grok with xCloud?
One command to connect
grok mcp add writes the entry and OAuth starts in the browser on first use. grok mcp doctor checks the connection if something looks wrong.
Global or per project
Keep the entry in ~/.grok/config.toml to use xCloud everywhere, or add --scope project to keep it in one repository's .grok/config.toml.
Reuses config you already have
xAI's docs say Grok Build also loads MCP servers from ~/.claude.json, .cursor/mcp.json and a project .mcp.json. If xCloud is already set up in one of those clients, check grok mcp list before you add it again.
Guides
What Can Grok Do on xCloud?
One guide per hosting job, each with the Grok setup, the xCloud tools involved, a settings reference, example prompts and the limits that apply.
- Deploy from Git with GrokTurn a GitHub, GitLab or Bitbucket repository into a live site on a server you already have.
- Run Docker apps with GrokRun a Dockerfile or Docker Compose app on a Docker server, keep it backed up and recover it when a deploy fails.
- Install one-click apps with GrokPick an app from the xCloud catalogue, check it fits your server, install it and get the login details.
- Manage WordPress with GrokKeep WordPress sites updated, scanned and healthy, and create new ones, by asking in plain words.
- Back up and stage sites with GrokCheck that your sites are backed up, take a backup before a risky change, and open a staging copy to test it on.
- Manage SSL and domains with GrokCheck a site's certificate and DNS, install or renew HTTPS, and see which domains point at it.
- Manage servers with GrokSee how your servers are doing, change services and runtimes, tighten security and reboot with proof it worked.
- Troubleshoot a broken site with GrokFind out why a site returns a 500, 502 or 503, shows a critical error or has stopped answering.
- Speed up a slow site with GrokFind out why a site is slow, from real numbers, and learn which fix is a dashboard switch.
- Secure sites and servers with GrokFind vulnerable sites, manage server firewall rules and banned IPs, and see which protections are on.
Example prompts
What Can You Ask Grok to Do on xCloud?
Type these as written and swap in your own site and server names. Reads and routine actions such as backups, cache purges, PageSpeed scans and vulnerability scans run straight away; creating, deploying, updating, rebooting, deleting, buying or starting a broken-link scan stops and asks first.
Deploy https://github.com/acme/shop to my Frankfurt server and show me the dry run before you create anything.Update all plugins on example.com, but take a backup first and confirm the homepage still loads afterwards.The last deploy of the API site failed. Diagnose it, fix the build command and retry on the same site.Renew the SSL certificate for shop.example.com and tell me when it expires now.Audit example.com: is it up, is SSL healthy, any vulnerabilities, and how is performance?Good to know
- This page covers Grok Build, the terminal agent. Grok at grok.com has its own connector settings: check Grok's connector settings for a custom MCP connector and use the same server URL, https://app.xcloud.host/mcp.
- Remote servers need --transport http on the command line. Without it, grok mcp add treats the argument as a local command.
- OAuth tokens are kept in ~/.grok/mcp_credentials.json. Keep that file out of version control and out of backups you share.
- If xCloud tools do not appear, run grok mcp doctor xcloud, then restart grok.
More prompts, grouped by job: What you can ask xCloud MCP to do.
Grok and xCloud: Frequently Asked Questions
Short answers about connecting Grok, what it may change and what it costs.
How do I connect Grok Build to xCloud?
Run grok mcp add --transport http xcloud https://app.xcloud.host/mcp in your terminal, then start grok and ask who you are on xCloud. A browser opens the first time so you can approve the teams and the access level.
What is the config.toml form for xCloud?
Add a [mcp_servers.xcloud] table to ~/.grok/config.toml with url set to https://app.xcloud.host/mcp. Then run grok mcp doctor xcloud to check the connection. Use grok mcp add with --scope project to keep the entry in a repository's .grok/config.toml instead.
Can I use xCloud from Grok at grok.com?
Yes, through a custom connector. Go to grok.com/connectors, choose New Connector, then Custom, enter https://app.xcloud.host/mcp as the server URL and sign in with xCloud when the browser asks; xAI's connectors page documents that flow. On Grok Business and Enterprise a team admin has to provision the connector in the cloud console before members can use it. The rest of this page covers Grok Build, the terminal agent.
Do I need an xCloud API key for Grok Build?
Not when you sign in with OAuth. Servers that need OAuth open a browser flow on first use. An API key is only for machines without a browser: create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things and pass it with the --header flag.
Can Grok Build change my servers without asking?
Not for the operations xCloud gates. Reads run straight away, and routine actions such as cache purges, backups, PageSpeed and vulnerability scans run without a prompt. Creating a site or server, deploying, updating plugins, rebooting, deleting or buying needs an explicit confirmation, and xCloud refuses the call without one.
How do I check or remove the xCloud server in Grok Build?
Run grok mcp list to see the configured servers and grok mcp doctor xcloud to diagnose the connection. Run grok mcp remove xcloud to take it out. Inside a session, /mcps opens the MCP tab.
Can Grok Build work across several xCloud teams?
Yes. On the approval screen you tick every team the connection may act on, and you name the team in your request. A site on a team you did not tick comes back as not found; reconnect and tick that team.
Is it free to use Grok Build with xCloud?
The xCloud side is free: the MCP server, the skills and the Public API are included with every xCloud account, including the free plan. Grok Build itself is provided by xAI under its own terms and pricing.
Other agents
Also Works With
The same xCloud account, the same operations, a guide for each client.
- Claude CodeAnthropic's terminal coding agent. One claude mcp add command, plus the xCloud skills plugin with nine skills on top.
- ClaudeAnthropic's chat assistant on the web and desktop. Add xCloud as a custom connector, no terminal needed.
- Claude CoworkAnthropic's desktop agent for delegated work. Add the xCloud connector, then hand off hosting jobs.
- CursorThe AI code editor. One mcp.json entry with the compact URL, because Cursor stops at 40 tools.
- CodexOpenAI's coding agent for the terminal. A codex mcp add command or a config.toml entry, then codex mcp login.
- OpenCodeThe open-source terminal coding agent. One remote MCP entry, then opencode mcp auth xcloud.
- Hermes AgentNous Research's agent with memory and a built-in scheduler. An mcp_servers entry in config.yaml and one login.
- OpenClawThe open-source agent runtime with chat apps and automations. ClawHub skill plus the MCP client.
- WindsurfThe Cognition editor, now Devin Desktop. devin mcp add for the Devin Local agent, a serverUrl entry for legacy Cascade.
- GitHub CopilotCopilot agent mode in VS Code. One .vscode/mcp.json entry, or the Agent Plugins package.
- Gemini CLIGoogle's terminal agent. One gemini mcp add command, OAuth found automatically.
- ChatGPTOpenAI's chat assistant. A developer-mode app with the xCloud MCP URL and OAuth.
- ChatGPT dotsOpenAI's always-on agent in ChatGPT. Uses the xCloud MCP plugin you add in ChatGPT, with custom rules and scheduled tasks.
- Grok BotxAI's always-on Bots on a cloud computer. One Remote HTTPS MCP plugin, OAuth sign-in, routines on a schedule.
- KiroAWS's agentic IDE. One url entry in .kiro/settings/mcp.json, plus the portable xCloud Agent Plugins package.
- AntigravityGoogle's agentic IDE. One serverUrl entry in mcp_config.json and a browser sign-in.
- ZedThe Zed editor's Agent Panel. One context_servers entry in settings.json and a browser sign-in.
Run Your Hosting from Grok
xCloud MCP, the Agent Skills and the Public API are free with every account. Connect once and ask.