Hermes Agent + xCloud
Manage Your Hosting from Hermes Agent with xCloud
Hermes Agent is an open-source AI agent from Nous Research that keeps memory across sessions, works from a terminal or from chat apps such as Telegram and Slack, and runs scheduled tasks on its own. Connected to xCloud through the MCP server, it deploys, backs up, updates and diagnoses your servers and sites on request, and on a timer it reads, scans and reports, leaving the changes for a session you are watching.
- Three lines in ~/.hermes/config.yaml
- Scheduled checks with hermes cron
- Free with every xCloud account
YouWhich of my sites have pending WordPress updates? Back them up first.
sites_wordpress_updatesread-only
Agentblog.example.com has 3 plugin updates and docs.example.com has 1 theme update. I will back both up, then apply the updates. Go ahead?
YouYes.
sites_wordpress_updateneeds approval
AgentBackups finished and 4 updates applied. Both homepages answer 200.
. Keep a human in the loop: xCloud stops and asks before anything that creates, deploys, updates, reboots, deletes or buys.
Setup
How Do I Connect Hermes Agent to xCloud?
Point Hermes Agent at the xCloud MCP server, approve access in your browser, then ask. The whole thing takes a couple of minutes. The xCloud Agent Skills are an optional layer on top of that connection: they teach the agent the workflows, they do not replace it.
Add the xCloud MCP server
Add this under mcp_servers in ~/.hermes/config.yaml. If the file already has an mcp_servers block, add only the xcloud entry. Then start a new Hermes session, or run /reload-mcp in the one that is open.
mcp_servers: xcloud: url: "https://app.xcloud.host/mcp" auth: oauthAuthorize xCloud
On first connect Hermes prints an authorize URL and waits for the sign-in. Run this command to start it yourself or to re-authorize later. On the xCloud approval screen tick the teams and choose Read-only or Full access. Hermes caches the tokens in ~/.hermes/mcp-tokens/xcloud.json and reuses them on later runs.
hermes mcp login xcloudNo browser? Use an API key
For a server with no browser, create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things in Settings, Developers, API Tokens and send it as a header in place of auth: oauth. Keep ~/.hermes/config.yaml out of version control when it holds a token.
mcp_servers: xcloud: url: "https://app.xcloud.host/mcp" headers: Authorization: "Bearer YOUR_TOKEN"Check it worked
auth: oauth signs you in through the browser, and Hermes caches the tokens locally for later runs and scheduled tasks. A server without a browser can send an API key that carries the mcp:invoke scope and the read or write abilities it needs in a header instead.
Who am I on xCloud?
Three surfaces
Which Way Should I Connect Hermes Agent to xCloud?
The MCP server exposes one tool per customer-facing xCloud operation and leaves out eleven internal ones that only the Public API carries; the skills add workflow know-how on top of an MCP connection and, on their own, only read access. All three are free with every account and differ in what you set up and what holds the credentials.
| xCloud MCP server | xCloud Agent Skills | Public API | |
|---|---|---|---|
| Terminal needed | No (recommended for Hermes Agent) | Yes for the plugin or ClawHub install | Yes |
| Authentication | OAuth sign-in, or an API key with mcp:invoke plus read or write abilities (recommended for Hermes Agent) | The MCP connection, or a read-scoped API token | API token with scoped abilities |
| What it adds | One tool per customer-facing xCloud operation (188 today) (recommended for Hermes Agent) | Workflow know-how: routing, dry run, confirm, poll, diagnose | Raw REST for your own code |
| Changes to your infrastructure | Yes, after confirmation (recommended for Hermes Agent) | Only through a connected MCP tool, after confirmation | Yes, with write scopes |
| Best for | Most people; every MCP client (recommended for Hermes Agent) | Agents that run shell commands and read skills | CI jobs, dashboards and long-running loops |
Background
What Is Hermes Agent?
Hermes Agent is an open-source AI agent built by Nous Research. It runs from a terminal interface or from a gateway that connects it to Telegram, Discord, Slack, WhatsApp and Signal, and it works with the model provider you choose. It keeps memory across sessions, so what you told it yesterday is still there today.
Hermes speaks the Model Context Protocol. You add a server under mcp_servers in ~/.hermes/config.yaml, and Hermes discovers the server's tools and registers them for the agent to call. A remote server that needs sign-in uses auth: oauth, and Hermes prints an authorize link, waits for the callback and caches the tokens.
Hermes also has a built-in cron scheduler. Jobs run in fresh agent sessions and deliver their results to a chat or another configured target, so a hosting check can run while you are away. That makes it a useful pairing with xCloud: it can ask for a read-only view of your infrastructure every day without you opening a terminal.
Why Hermes Agent with xCloud?
Memory that carries over
Hermes keeps its memory across sessions. Tell it once which server is your Frankfurt one and which site is the staging copy, and later requests can lean on that instead of starting from nothing.
Checks that run themselves
Hermes cron jobs run unattended and deliver the result to a chat. Point one at xCloud for a daily look at downtime, expiring certificates and pending WordPress updates, and review the report over coffee.
Ask from the chat you already use
Run the Hermes gateway and message it from Telegram, Slack or Discord. The same xCloud connection answers there as in the terminal, with the same approval step before it creates, deploys, updates or deletes anything.
Guides
What Can Hermes Agent Do on xCloud?
One guide per hosting job, each with the Hermes Agent setup, the xCloud tools involved, a settings reference, example prompts and the limits that apply.
- Deploy from Git with Hermes AgentTurn a GitHub, GitLab or Bitbucket repository into a live site on a server you already have.
- Run Docker apps with Hermes AgentRun a Dockerfile or Docker Compose app on a Docker server, keep it backed up and recover it when a deploy fails.
- Install one-click apps with Hermes AgentPick an app from the xCloud catalogue, check it fits your server, install it and get the login details.
- Manage WordPress with Hermes AgentKeep WordPress sites updated, scanned and healthy, and create new ones, by asking in plain words.
- Back up and stage sites with Hermes AgentCheck that your sites are backed up, take a backup before a risky change, and open a staging copy to test it on.
- Manage SSL and domains with Hermes AgentCheck a site's certificate and DNS, install or renew HTTPS, and see which domains point at it.
- Manage servers with Hermes AgentSee how your servers are doing, change services and runtimes, tighten security and reboot with proof it worked.
- Troubleshoot a broken site with Hermes AgentFind out why a site returns a 500, 502 or 503, shows a critical error or has stopped answering.
- Speed up a slow site with Hermes AgentFind out why a site is slow, from real numbers, and learn which fix is a dashboard switch.
- Secure sites and servers with Hermes AgentFind vulnerable sites, manage server firewall rules and banned IPs, and see which protections are on.
Example prompts
What Can You Ask Hermes Agent to Do on xCloud?
Type these as written and swap in your own site and server names. Reads and routine actions such as backups, cache purges, PageSpeed scans and vulnerability scans run straight away; creating, deploying, updating, rebooting, deleting, buying or starting a broken-link scan stops and asks first.
Deploy https://github.com/example/shop to my Frankfurt server and show me the dry run before you create anything.Every morning at 9am, check all my sites for downtime, expiring SSL certificates and pending WordPress updates, and message me a summary. Change nothing.Back up every WordPress site that has pending updates, then list what each update would change and wait for my go-ahead.The API site returns a 502. Read the recent events and logs, find the cause and tell me what you would change.Remember that my production server is the Frankfurt one and staging sites go on the Singapore server.Good to know
- Hermes reads mcp_servers when a session starts. After editing config.yaml, start a new session or run /reload-mcp, otherwise the xCloud tools will not appear.
- If Hermes runs on a server without a browser, finish the sign-in over SSH: Hermes tells you how to reach its callback port or paste the redirected URL. Otherwise use the API-key step.
- xCloud exposes 188 operations plus two search tools. To keep Hermes's tool list short, connect https://app.xcloud.host/mcp?profile=compact, or filter the server's tools with tools.include in config.yaml.
- This page sets up the MCP connection. The xCloud skills are plain Markdown files and Hermes has its own skills system, but xCloud documents install commands for Claude Code and OpenClaw only, so start with MCP.
Run hosting checks on a schedule with Hermes cron
Hermes has a built-in cron scheduler that runs jobs in fresh agent sessions and delivers the result to a chat or another target. Authorize xCloud once with hermes mcp login xcloud, and scheduled runs reuse the cached tokens. You can create the job from the terminal, or just ask Hermes in chat: Every morning at 9am, check my sites and send me a summary. Keep scheduled jobs to reads, PageSpeed and vulnerability scans and reports: a Docker backup stops the app while it captures, so start one from a session you are watching, and anything that creates, deploys, updates or deletes still needs your approval.
hermes cron create "every 12h" \
"Use xCloud to check every site for downtime, expiring SSL certificates and pending WordPress updates. Report only and change nothing." \
--name "Hosting check"More prompts, grouped by job: What you can ask xCloud MCP to do.
Hermes Agent and xCloud: Frequently Asked Questions
Short answers about connecting Hermes Agent, what it may change and what it costs.
How do I connect Hermes Agent to xCloud?
Add an xcloud entry under mcp_servers in ~/.hermes/config.yaml with url set to https://app.xcloud.host/mcp and auth set to oauth. Start a new session, run hermes mcp login xcloud and approve access in the browser, then ask who am I on xCloud to confirm.
How do I re-authorize xCloud in Hermes Agent?
Run hermes mcp login xcloud. Hermes prints the authorize URL, waits for the callback and replaces the cached tokens in ~/.hermes/mcp-tokens/xcloud.json. Start a new session or run /reload-mcp so the running session picks up the new sign-in.
Can Hermes Agent use xCloud without a browser?
Yes. Create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things in Settings, Developers, API Tokens and give the xcloud entry a headers block with Authorization set to Bearer and your token, instead of auth: oauth. Over SSH you can also finish the OAuth sign-in by following Hermes's callback instructions.
Can Hermes Agent run xCloud tasks on a schedule?
Yes. Hermes has a built-in cron scheduler, for example hermes cron create "every 12h" followed by a prompt and a --name. Jobs run in fresh sessions and deliver their results to a chat. Keep scheduled jobs to reads, PageSpeed and vulnerability scans and reports, with backups left to a session you are watching because a Docker backup stops the app while it captures, and say so in the prompt: xCloud stops for confirmation before it creates, deploys, updates, reboots or deletes and before a broken-link scan, but routine actions such as a backup, a cache purge or a service restart run without that step, so a job with nobody watching could carry them out.
Can Hermes Agent change my servers without asking?
Not for the operations xCloud gates. Reads run straight away, and routine actions such as cache purges, backups, PageSpeed and vulnerability scans run without a prompt. Creating a site or server, deploying, updating plugins, rebooting, deleting or buying is refused by xCloud unless the call carries an explicit confirmation, so Hermes asks you first.
Can Hermes Agent use the xCloud skills as well?
Hermes has its own skills system built on Markdown skill files, and the xCloud skills are plain Markdown, so the two fit together. xCloud documents install commands for Claude Code and OpenClaw but not for Hermes, so set up the MCP connection first and treat skills as an extra.
Can I limit Hermes Agent to read-only access on xCloud?
Yes. On the xCloud approval screen choose Read-only instead of Full access. Hermes can then look at servers, sites, logs and backups, and any tool that would change something is refused. That is a good setting for a scheduled report job.
Can I run Hermes Agent itself on an xCloud server?
Yes, that is a separate product: xCloud can host Hermes Agent on your own server, and there is a guide to deploy it. This page is the other direction, where Hermes manages your xCloud servers and sites through the MCP connection.
Is it free to use Hermes Agent with xCloud?
The xCloud side is free: the MCP server and the Public API are included with every xCloud account, including the free plan. Hermes is open source, and any model usage is billed by the provider you configure in Hermes.
Other agents
Also Works With
The same xCloud account, the same operations, a guide for each client.
- Claude CodeAnthropic's terminal coding agent. One claude mcp add command, plus the xCloud skills plugin with nine skills on top.
- ClaudeAnthropic's chat assistant on the web and desktop. Add xCloud as a custom connector, no terminal needed.
- Claude CoworkAnthropic's desktop agent for delegated work. Add the xCloud connector, then hand off hosting jobs.
- CursorThe AI code editor. One mcp.json entry with the compact URL, because Cursor stops at 40 tools.
- CodexOpenAI's coding agent for the terminal. A codex mcp add command or a config.toml entry, then codex mcp login.
- OpenCodeThe open-source terminal coding agent. One remote MCP entry, then opencode mcp auth xcloud.
- OpenClawThe open-source agent runtime with chat apps and automations. ClawHub skill plus the MCP client.
- WindsurfThe Cognition editor, now Devin Desktop. devin mcp add for the Devin Local agent, a serverUrl entry for legacy Cascade.
- GitHub CopilotCopilot agent mode in VS Code. One .vscode/mcp.json entry, or the Agent Plugins package.
- Gemini CLIGoogle's terminal agent. One gemini mcp add command, OAuth found automatically.
- ChatGPTOpenAI's chat assistant. A developer-mode app with the xCloud MCP URL and OAuth.
- ChatGPT dotsOpenAI's always-on agent in ChatGPT. Uses the xCloud MCP plugin you add in ChatGPT, with custom rules and scheduled tasks.
- GrokxAI's terminal agent, Grok Build. One grok mcp add command or a config.toml entry.
- Grok BotxAI's always-on Bots on a cloud computer. One Remote HTTPS MCP plugin, OAuth sign-in, routines on a schedule.
- KiroAWS's agentic IDE. One url entry in .kiro/settings/mcp.json, plus the portable xCloud Agent Plugins package.
- AntigravityGoogle's agentic IDE. One serverUrl entry in mcp_config.json and a browser sign-in.
- ZedThe Zed editor's Agent Panel. One context_servers entry in settings.json and a browser sign-in.
Run Your Hosting from Hermes Agent
xCloud MCP, the Agent Skills and the Public API are free with every account. Connect once and ask.