Kiro + xCloud

Manage Your Hosting from Kiro with xCloud

Kiro is Amazon Web Services' agentic IDE, where an AI agent plans and edits your project from a chat panel. Connected to xCloud through one line of MCP configuration, it deploys repositories, updates WordPress, checks SSL and diagnoses failures without you leaving the editor.

  • One url entry in mcp.json
  • Workspace or user-level config
  • Free with every xCloud account

YouWhich sites on my Acme team have pending WordPress plugin updates?

sites_wordpress_updatesread-only

AgentTwo: blog.example.com has 3 plugin updates and shop.example.com has 1. Update both?

YouYes, update the blog first and check the homepage afterwards.

sites_wordpress_updateneeds approval

AgentBlog updated, 3 plugins, https://blog.example.com answers 200. Shall I continue with the shop?

. Keep a human in the loop: xCloud stops and asks before anything that creates, deploys, updates, reboots, deletes or buys.

Setup

How Do I Connect Kiro to xCloud?

Point Kiro at the xCloud MCP server, approve access in your browser, then ask. The whole thing takes a couple of minutes. The xCloud Agent Skills are an optional layer on top of that connection: they teach the agent the workflows, they do not replace it.

  1. Add xCloud to your Kiro MCP config

    Open the Command Palette (Cmd+Shift+P on Mac, Ctrl+Shift+P on Windows and Linux), search for MCP and choose Kiro: Open workspace MCP config (JSON) for .kiro/settings/mcp.json, or Kiro: Open user MCP config (JSON) for ~/.kiro/settings/mcp.json. Paste this, save, and Kiro reconnects on its own. The first connection opens the xCloud approval screen in your browser, where you tick the teams and choose Read-only or Full access.

    JSON
    {
      "mcpServers": {
        "xcloud": {
          "url": "https://app.xcloud.host/mcp"
        }
      }
    }
  2. Choose which xCloud tools Kiro may run

    Optional. autoApprove lists tools Kiro runs without asking, and disabledTools hides tools from the agent altogether. The two names here are real xCloud tools; swap in your own. Avoid the "*" wildcard in autoApprove, so Kiro's own prompt stays as a second check beside xCloud's confirmation.

    JSON
    {
      "mcpServers": {
        "xcloud": {
          "url": "https://app.xcloud.host/mcp",
          "autoApprove": ["xcloud_docs_search", "xcloud_agent_search"],
          "disabledTools": ["sites_destroy"]
        }
      }
    }
  3. No browser sign-in? Use an API key

    Create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things in Settings, Developers, API Tokens, export it as XCLOUD_API_TOKEN, and pass it in headers. Kiro only expands environment variables you have approved, so add XCLOUD_API_TOKEN under the Mcp Approved Env Vars setting. Never paste the token into the file or into chat.

    JSON
    {
      "mcpServers": {
        "xcloud": {
          "url": "https://app.xcloud.host/mcp",
          "headers": {
            "Authorization": "Bearer ${XCLOUD_API_TOKEN}"
          }
        }
      }
    }
  4. Check it worked

    Kiro opens the browser sign-in for an OAuth-protected server and uses Dynamic Client Registration, which xCloud supports, so the url line is all the configuration it needs. A machine without a browser passes an API key that carries the mcp:invoke scope and the read or write abilities it needs in headers.

    Prompt
    Who am I on xCloud?

Three surfaces

Which Way Should I Connect Kiro to xCloud?

The MCP server exposes one tool per customer-facing xCloud operation and leaves out eleven internal ones that only the Public API carries; the skills add workflow know-how on top of an MCP connection and, on their own, only read access. All three are free with every account and differ in what you set up and what holds the credentials.

xCloud MCP serverxCloud Agent SkillsPublic API
Terminal neededNo (recommended for Kiro)Yes for the plugin or ClawHub installYes
AuthenticationOAuth sign-in, or an API key with mcp:invoke plus read or write abilities (recommended for Kiro)The MCP connection, or a read-scoped API tokenAPI token with scoped abilities
What it addsOne tool per customer-facing xCloud operation (188 today) (recommended for Kiro)Workflow know-how: routing, dry run, confirm, poll, diagnoseRaw REST for your own code
Changes to your infrastructureYes, after confirmation (recommended for Kiro)Only through a connected MCP tool, after confirmationYes, with write scopes
Best forMost people; every MCP client (recommended for Kiro)Agents that run shell commands and read skillsCI jobs, dashboards and long-running loops

Background

What Is Kiro?

Kiro is an agentic IDE from Amazon Web Services. You describe what you want in a chat panel, and its agent reads your project, plans the work and edits files, asking before it runs tools you have not allowed. Kiro also ships a command-line interface, and its MCP documentation covers the IDE, the CLI and the web surface.

Kiro speaks the Model Context Protocol. A remote server goes into a JSON file as a url, with optional headers, an oauth block, autoApprove and disabledTools. Two files exist: .kiro/settings/mcp.json for one workspace and ~/.kiro/settings/mcp.json for every workspace. When both define a server, the workspace entry wins.

That makes xCloud a one-entry connection. The MCP server gives Kiro one tool per customer-facing xCloud operation, and the portable xCloud Agent Plugins package, which xCloud lists Kiro as a compatible client for, adds the workflow know-how as skills. Deploys, WordPress updates and diagnoses then happen from the same panel you write code in.

Why Kiro with xCloud?

A remote server, nothing to run locally

xCloud is a hosted MCP endpoint, so the config is a url and nothing else. There is no package to install, no process for Kiro to start and no token in the file when you sign in with OAuth.

Per-tool control in the same file

autoApprove lets Kiro run read tools without a prompt, and disabledTools removes tools you never want the agent to see. xCloud still stops at its own confirmation for anything that creates, deploys, updates, reboots, deletes or buys.

Project scope or personal scope

Put the entry in .kiro/settings/mcp.json to give one project its own xCloud connection, or in ~/.kiro/settings/mcp.json to have it everywhere. With OAuth the file holds only the URL, so a workspace file carries no secret.

Example prompts

What Can You Ask Kiro to Do on xCloud?

Type these as written and swap in your own site and server names. Reads and routine actions such as backups, cache purges, PageSpeed scans and vulnerability scans run straight away; creating, deploying, updating, rebooting, deleting, buying or starting a broken-link scan stops and asks first.

Prompt
Use xCloud to list my servers and tell me which ones are above 80 percent disk usage.
Prompt
Deploy https://github.com/acme/shop to my Frankfurt server and show me the dry run before you create anything.
Prompt
Update all plugins on example.com, then check that the homepage still loads.
Prompt
Why is staging.example.com returning a 502? Check the latest deployment events and the web server logs.
Prompt
Check the SSL certificate on shop.example.com and renew it if it expires within two weeks.

Good to know

  • MCP support has to be switched on in Kiro first: open Settings, search for MCP and enable the MCP support setting.
  • If the same server name appears in several places, an agent config's mcpServers field beats the workspace file, and the workspace file beats the user file.
  • Kiro expands only approved environment variables. If a ${XCLOUD_API_TOKEN} header does not work, add the variable under the Mcp Approved Env Vars setting.
  • Kiro's documentation says to review tool permissions before adding tools to autoApprove, and that advice applies here: approve reads, not changes.

More prompts, grouped by job: What you can ask xCloud MCP to do.

Kiro and xCloud: Frequently Asked Questions

Short answers about connecting Kiro, what it may change and what it costs.

How do I connect Kiro to xCloud?

Open the Command Palette, run Kiro: Open workspace MCP config (JSON) or Kiro: Open user MCP config (JSON), and add an xcloud entry under mcpServers with url set to https://app.xcloud.host/mcp. Save the file, approve the access level in the browser tab that opens, and ask who am I on xCloud to confirm.

Where does Kiro keep its MCP configuration?

In two places: .kiro/settings/mcp.json inside a workspace, and ~/.kiro/settings/mcp.json for every workspace. If both define the same server, the workspace entry takes precedence. Either file takes effect when you save it.

Does Kiro need an xCloud API key?

Not when you sign in with OAuth. Kiro opens the browser, you choose the teams and the access level, and the connection is live. An API key is only for a machine without a browser. Create one with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things and pass it in headers as Authorization: Bearer followed by the token.

Do I have to restart Kiro after editing mcp.json?

No. Kiro watches its MCP files and reconnects when you save, restarting only the servers whose entries changed. If the xCloud tools do not appear, check that the MCP support setting is enabled and that the JSON is valid.

How do I stop Kiro from running certain xCloud tools?

Add the tool names to disabledTools on the xcloud entry and Kiro leaves them out when it calls the agent. To skip Kiro's approval prompt for safe tools, list them in autoApprove instead. Keep changes out of autoApprove, so you still approve them in Kiro as well as in xCloud.

Can Kiro change my servers without asking?

Not for the operations xCloud gates. Kiro asks you to approve each MCP tool call unless the tool is listed in autoApprove, so with the configuration above only the two search tools skip Kiro's prompt; add the read tools you trust to autoApprove if you want them to run without it. xCloud adds its own gate: reads and routine actions such as cache purges, backups, PageSpeed and vulnerability scans need no xCloud confirmation, while creating a site or server, deploying, updating plugins, rebooting, deleting or buying is refused unless the call carries an explicit confirmation, and the tool tells Kiro to ask you first.

Does the xCloud Agent Plugins package work with Kiro?

xCloud lists Kiro among the clients for its portable Agent Plugins package, which holds plugin.json, mcp.json and the skills. Import support and the OAuth behavior depend on the client, so follow the install guide in the xcloud-agent-skills repository. The MCP entry above works on its own either way.

Is it free to use Kiro with xCloud?

The xCloud side is free: the MCP server, the skills and the Public API are included with every xCloud account, including the free plan. Kiro itself is provided and billed by AWS under its own plans.

Other agents

Also Works With

The same xCloud account, the same operations, a guide for each client.

Run Your Hosting from Kiro

xCloud MCP, the Agent Skills and the Public API are free with every account. Connect once and ask.