Hermes Agent + xCloud
Install one-click apps with Hermes Agent on xCloud
Installing one-click apps with Hermes Agent means messaging an agent that already lives in your terminal or in Telegram, Slack or Discord, and letting it find the app in the xCloud catalogue, check your server, install after your approval and report back when it finishes.
- Skill: xcloud:deploy
- Toolsets: oneclick-apps, catalog, servers
- Free with every xCloud account
YouInstall Uptime Kuma on Frankfurt, staging hostname. Message me when it is done.
oneclickApps_compatibilityread-only
AgentFrankfurt fits: stack, runtime, billing and resources all pass. I will install Uptime Kuma on a free staging hostname. Go ahead?
YouGo ahead.
oneclickApps_installneeds approval
AgentDone. Uptime Kuma finished provisioning and answers on your staging hostname. Ask me for the login details in a private chat when you want them.
. Keep a human in the loop: xCloud stops and asks before anything that creates, deploys, updates, reboots, deletes or buys.
Setup
How Do You Set Up Hermes Agent to Install one-click apps on xCloud?
Connect Hermes Agent once; every job on this account uses the same connection. Then ask in plain words.
Add the xCloud MCP server
Add this under mcp_servers in ~/.hermes/config.yaml. If the file already has an mcp_servers block, add only the xcloud entry. Then start a new Hermes session, or run /reload-mcp in the one that is open.
mcp_servers: xcloud: url: "https://app.xcloud.host/mcp" auth: oauthAuthorize xCloud
On first connect Hermes prints an authorize URL and waits for the sign-in. Run this command to start it yourself or to re-authorize later. On the xCloud approval screen tick the teams and choose Read-only or Full access. Hermes caches the tokens in ~/.hermes/mcp-tokens/xcloud.json and reuses them on later runs.
hermes mcp login xcloudNo browser? Use an API key
For a server with no browser, create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things in Settings, Developers, API Tokens and send it as a header in place of auth: oauth. Keep ~/.hermes/config.yaml out of version control when it holds a token.
mcp_servers: xcloud: url: "https://app.xcloud.host/mcp" headers: Authorization: "Bearer YOUR_TOKEN"Check it worked
Then ask Hermes Agent for the job itself, for example:
Hermes, which of my servers can take Ghost? Check the fit on each and tell me which one you would pick.
In practice
How Does One-click apps Work from Hermes Agent?
Hermes is not a window you keep open. The gateway runs on a machine of yours, and you message it from your phone the way you would message a colleague: install Uptime Kuma on my Frankfurt server, a staging hostname is fine. Hermes calls the catalogue search, reads the install form, runs the compatibility check for the server you named and answers in a few lines of chat. Memory helps here. Tell it once that Frankfurt is your production server and Singapore holds experiments, and a later request such as put Ghost on the experiments server resolves without a question. It still asks before it installs, and your yes in the chat is what lets the install call go out with its confirmation.
Installs take a while, which suits a chat agent. Hermes sends the install, then polls oneclickApps_status in the background and replies when the install reaches a terminal state, so you can lock your phone in between. If something fails, the message names the phase, pre_install, install, post_install or provisioning, and Hermes can read the site's recent events and tell you what it found before offering any retry. A server that is too small stays too small, so you get a suggestion to pick a larger one rather than a second attempt. For the eleven apps that install only from the dashboard, such as n8n, Hermes checks the fit and then gives you the click path in chat instead of trying.
Be deliberate about what you put on a timer. Hermes cron runs jobs in fresh sessions with nobody there to say yes, so keep scheduled work to reads, for example a weekly message that lists which of your servers have RAM and disk to spare for the app you are planning. Installing, stopping and redeploying belong in a live conversation. Chat apps also keep history, so ask for login details only in a private chat with Hermes, and do not ask it to remember them.
Hermes Agent specific: Credentials are the sharp edge on this page. Hermes shows login details once in its reply, but a reply in Telegram, Slack or Discord is a message that stays in that app's history and may sync to other devices. Ask for them in a one-to-one chat, move them into a password manager straight away and delete the message if your chat app allows it. If the app has no generated login, you create the first administrator inside the app and there is nothing to fetch.
What xCloud does for one-click apps
xCloud lists the one-click catalogue, checks whether an app fits a given server, installs it once you approve and reports each install phase until it finishes. Afterwards the agent can fetch the login details and stop, start or redeploy the app. A few apps install only from the dashboard, and the agent tells you where to click.
- Find the app. The agent searches the catalogue by name or purpose and shows what it found. An empty catalogue means the list has not synced on that environment, so the agent never answers that an app does not exist from an empty list.
- Read the install form. The agent reads the app's fields. Fields xCloud generates for you can be left out. For the address you choose a free xCloud staging hostname or your own domain, and a live domain needs the full site name.
- Check the server fits. You name the server, or the agent lists yours and asks. The compatibility check covers the server stack, runtime, state, billing and RAM, CPU and disk against the latest monitoring snapshot. If monitoring data is missing the resource check was skipped, and the agent says the result is inconclusive.
- Approve and install. The agent restates the app, the server and the address, and asks once. On your yes it sends the install with an explicit confirmation and an idempotency key, so a retried request cannot create a second copy.
- Poll the install. The agent polls the install status every five to ten seconds until it is terminal. A failure names its phase: pre_install, install, post_install or provisioning, so you know where it stopped.
- Hand over and manage. The agent gives you the URL. It fetches the login details only when you ask, shows them once in the reply and tells you to store them in a password manager. Later it can stop, start, restart or redeploy the app after your approval.
Reference
One-click apps Settings and Limits on xCloud
The facts Hermes Agent works within when it installs one-click apps. Where a row names the dashboard, that step stays yours to take there.
| Setting or limit | What applies |
|---|---|
| Catalogue | Searchable by name. It holds hundreds of apps, and most run on a Docker server. Public facts such as supported stacks and minimum size come from the catalogue listing |
| Compatibility check | Per server: stack, runtime, server state, billing and RAM, CPU and disk. monitor_available set to false means the resource check was skipped, not passed |
| Too-small servers | A server that is too small stays too small. The agent suggests a larger server instead of retrying the install |
| Stack requirements | An app that needs another stack is refused with a 422 that reads "This app requires a ... server. This server is on the ... stack." |
| Dashboard-only installs | n8n, Supabase, Nextcloud, Mautic, LibreChat, Open WebUI, Ollama, Umami, WireGuard, phpMyAdmin and Site.pro. The API answers 404 for these eleven; install them from Add site, One-Click Apps in the dashboard |
| Address | Staging hostname for a free xCloud address, or go live with your own domain. A demo site promoted to a live domain cannot return to the demo address |
| Idempotency | The install carries an Idempotency-Key, so a retried request cannot create a duplicate site |
| Install phases | pre_install, install, post_install and provisioning. is_terminal marks the end, and failed_phase says where a failure happened |
| Credentials | Read on request and shown once in the reply. Some apps have none to read because you create the first admin inside the app |
| Lifecycle | Stop, start, restart and redeploy run synchronously. Stop takes the app offline and redeploy recreates its containers. Both answer 422 while an install is running or after a failed install |
| Agentic servers | An OpenClaw, Hermes, Paperclip or DeepSeek Harness server never takes a one-click app |
Rules Hermes Agent has to follow
- Installing, stopping and redeploying an app stop for your approval; browsing the catalogue and the compatibility check never change anything.
- A missing resource reading is reported as inconclusive, never as a pass.
- Login details are shown once, only when you ask, and never repeated in a summary or a later message.
- For the eleven dashboard-only apps the agent checks that the server fits, then gives you the dashboard path instead of trying the install.
- A failed install is not retried blindly: the agent names the failed phase and reads the site's recent events first.
Example prompts
What Can You Ask Hermes Agent to Do for One-click apps?
Type these as written and swap in your own repository, site and server names. Reads and routine actions such as backups, cache purges, PageSpeed scans and vulnerability scans run straight away; creating, deploying, updating, rebooting, deleting, buying or starting a broken-link scan stops and asks first.
Hermes, which of my servers can take Ghost? Check the fit on each and tell me which one you would pick.Install Uptime Kuma on the Frankfurt server with a staging hostname and message me here when it is ready.The Uptime Kuma install failed an hour ago. Which phase stopped, and what do the recent events say?Which one-click apps are compatible with my Frankfurt server?Search the one-click catalogue for a self-hosted blog and tell me what each result needs from a server.Install Uptime Kuma on the Frankfurt server on a staging hostname, wait until it is ready, then give me the login details.Check whether Immich fits my Amsterdam server before I install it, and tell me if the resource check was inconclusive.I want n8n on my Frankfurt server. Check that the server fits, then tell me where to click to install it.The Uptime Kuma install on the Frankfurt server failed. Which phase failed, and what do the recent events say?Redeploy the Ghost app on blog.example.com, but tell me what a redeploy does before you run it.Hermes Agent and One-click apps: Frequently Asked Questions
What people ask before they let Hermes Agent install one-click apps through xCloud.
Will Hermes Agent tell me when a one-click install finishes?
Yes. It polls the install status after you approve and replies in the chat when the install is terminal. A failure message names the phase that stopped, so you know whether it was pre_install, install, post_install or provisioning.
Can I schedule one-click app installs with Hermes cron?
No, keep installs out of cron. Scheduled jobs run in fresh sessions with nobody to approve, and xCloud stops for confirmation before an install, a stop or a redeploy. Use cron for reads, such as a weekly list of servers with room for the app you plan to add.
Can an agent install any app in the one-click catalogue?
Most of them. Eleven apps install only from the dashboard: n8n, Supabase, Nextcloud, Mautic, LibreChat, Open WebUI, Ollama, Umami, WireGuard, phpMyAdmin and Site.pro. For those the agent checks that your server fits and points you to Add site, One-Click Apps.
How does the agent know an app will fit my server?
It runs the compatibility check for that server, which covers the stack, runtime, server state, billing and the RAM, CPU and disk readings from the latest monitoring snapshot. If monitoring data is missing, the agent tells you the resource check was inconclusive.
What does a 422 during an app install mean?
Usually that the app needs a different server stack than the one you picked, and the message names both. Pick a server on the required stack. A 422 on stop, start or redeploy means an install is still running or the last install failed.
Where do the login details for a one-click app come from?
The agent can read them from xCloud when you ask and shows them once in the reply. Store them in a password manager. Some apps have no generated login because you create the first administrator inside the app.
Can an agent stop or restart a one-click app?
Yes. Stop, start, restart and redeploy are available, and they run straight away once you approve. Stop takes the app offline and redeploy recreates its containers, so the agent asks before either.
Other agents
One-click apps with Other Agents
The same job, the same xCloud tools, a guide for each client.
- Install one-click apps with Claude CodeAnthropic's terminal coding agent. One claude mcp add command, plus the xCloud skills plugin with nine skills on top.
- Install one-click apps with ClaudeAnthropic's chat assistant on the web and desktop. Add xCloud as a custom connector, no terminal needed.
- Install one-click apps with Claude CoworkAnthropic's desktop agent for delegated work. Add the xCloud connector, then hand off hosting jobs.
- Install one-click apps with CursorThe AI code editor. One mcp.json entry with the compact URL, because Cursor stops at 40 tools.
- Install one-click apps with CodexOpenAI's coding agent for the terminal. A codex mcp add command or a config.toml entry, then codex mcp login.
- Install one-click apps with OpenCodeThe open-source terminal coding agent. One remote MCP entry, then opencode mcp auth xcloud.
- Install one-click apps with OpenClawThe open-source agent runtime with chat apps and automations. ClawHub skill plus the MCP client.
- Install one-click apps with WindsurfThe Cognition editor, now Devin Desktop. devin mcp add for the Devin Local agent, a serverUrl entry for legacy Cascade.
- Install one-click apps with GitHub CopilotCopilot agent mode in VS Code. One .vscode/mcp.json entry, or the Agent Plugins package.
- Install one-click apps with Gemini CLIGoogle's terminal agent. One gemini mcp add command, OAuth found automatically.
- Install one-click apps with ChatGPTOpenAI's chat assistant. A developer-mode app with the xCloud MCP URL and OAuth.
- Install one-click apps with ChatGPT dotsOpenAI's always-on agent in ChatGPT. Uses the xCloud MCP plugin you add in ChatGPT, with custom rules and scheduled tasks.
- Install one-click apps with GrokxAI's terminal agent, Grok Build. One grok mcp add command or a config.toml entry.
- Install one-click apps with Grok BotxAI's always-on Bots on a cloud computer. One Remote HTTPS MCP plugin, OAuth sign-in, routines on a schedule.
- Install one-click apps with KiroAWS's agentic IDE. One url entry in .kiro/settings/mcp.json, plus the portable xCloud Agent Plugins package.
- Install one-click apps with AntigravityGoogle's agentic IDE. One serverUrl entry in mcp_config.json and a browser sign-in.
- Install one-click apps with ZedThe Zed editor's Agent Panel. One context_servers entry in settings.json and a browser sign-in.
More Hermes Agent guides
- Hermes Agent and xCloud overview
- Deploy from Git with Hermes Agent
- Run Docker apps with Hermes Agent
- Manage WordPress with Hermes Agent
- Back up and stage sites with Hermes Agent
- Manage SSL and domains with Hermes Agent
- Manage servers with Hermes Agent
- Troubleshoot a broken site with Hermes Agent
- Speed up a slow site with Hermes Agent
- Secure sites and servers with Hermes Agent
Run Your Hosting from Hermes Agent
xCloud MCP, the Agent Skills and the Public API are free with every account. Connect once and ask.