OpenClaw + xCloud

Manage servers with OpenClaw on xCloud

Managing servers with OpenClaw means messaging a self-hosted agent runtime on WhatsApp, Telegram, Slack or Discord and letting it use the xCloud servers skill and MCP tools to read, change and reboot your servers with your approval.

  • Skill: xcloud:servers
  • Toolsets: servers, alerts, user
  • Free with every xCloud account

YouFrankfurt feels slow. Is the server healthy?

servers_monitoringread-only

AgentDisk on frankfurt-1 is at 91% and its status reads Low disk space. CPU and memory are normal. I can read its recent tasks to see whether anything is stuck. Want that?

YouYes.

servers_tasksread-only

AgentNo failed or running tasks, so nothing is stuck on the server side. Freeing space means clearing local backups or caches. Resizing the server is a dashboard step, and I cannot do it from here.

. Keep a human in the loop: xCloud stops and asks before anything that creates, deploys, updates, reboots, deletes or buys.

Setup

How Do You Set Up OpenClaw to Manage servers on xCloud?

Connect OpenClaw once; every job on this account uses the same connection. Then ask in plain words.

  1. Install the xCloud skill from ClawHub

    This installs the nine xCloud skills into the active workspace skills folder. Add --global to install them into ~/.openclaw/skills for every local agent. The clawhub CLI installs the same listing with clawhub install xcloud.

    Terminal
    openclaw skills install @asif2bd/xcloud
  2. Add the xCloud MCP server and sign in

    Run these on the installation that owns the connector. The --auth oauth flag matters: openclaw mcp login only runs for HTTP servers saved with OAuth, so without it the login is refused. The login prints an authorization URL, and OpenClaw normally captures the redirect on a loopback address and saves the credentials; Settings, MCP, Sign in in the Control UI does the same. On the xCloud approval screen tick the teams and choose Read-only or Full access.

    Terminal
    openclaw mcp add xcloud \
      --url https://app.xcloud.host/mcp \
      --transport streamable-http \
      --auth oauth
    openclaw mcp login xcloud
  3. Check the skill and the connection

    The first command lists the skills that are eligible to run in this environment, and xcloud should be among them. The second opens a live connection and reports the tools the server offers. A saved server entry proves nothing until the probe passes. Then ask who am I on xCloud.

    Terminal
    openclaw skills list --eligible
    openclaw mcp doctor xcloud --probe
  4. Check it worked

    Then ask OpenClaw for the job itself, for example:

    Prompt
    Frankfurt feels slow. Check its CPU, memory and disk and tell me whether anything is close to full.

In practice

How Does Server management Work from OpenClaw?

OpenClaw is a runtime you run yourself, and the place you talk to it is a chat. For server work that is the right place, because the problem usually reaches you as an alert on your phone. You message the agent, for example: Frankfurt feels slow, is the server healthy? OpenClaw reads the server's monitoring figures and its status, reads the alerts xCloud has raised and answers in the thread. If it finds Low disk space or a pending reboot, it says so first. A change request works the same way. Ask it to add a firewall rule and it lists the existing rules with servers_firewallRules, shows the new rule with its name, protocol, allow or deny, port and source address, and waits for your reply before it creates anything.

Two pieces make this work, and OpenClaw uses both. The xcloud:servers skill from ClawHub carries the judgement: name the server before changing it, state the impact, wait for approval on anything that can interrupt a service, read the task list until the work settles, and treat a reboot as unfinished until xCloud reports a verified new boot. The MCP connection carries the tools themselves, so the same message that asks for a reboot ends with a verified answer in the chat. Run openclaw mcp doctor xcloud --probe once before you rely on it for a change, because a saved server entry proves nothing until the probe passes.

OpenClaw also has automations, and server health is a natural job for them. A Monday 8am automation can read every server, collect disk and memory readings, list the unread alerts and the banned IP addresses, and announce one summary in your Telegram or Slack channel without you opening a terminal. It runs in an isolated session, so write the server names into the prompt. When the summary shows something that needs doing, you answer in the chat, where the agent can ask for approval and you can give it.

OpenClaw specific: The skill on its own can read but not change. Without the MCP connection, the xcloud skill falls back to a GET-only REST wrapper that needs bash, curl, jq and an XCLOUD_API_TOKEN. That wrapper can list servers and read monitoring and tasks, but it cannot restart a service, set a Node.js default, add a firewall rule or reboot. If a chat request for a change gets a dashboard link instead of an action, run openclaw mcp doctor xcloud --probe on the installation that owns the connector. An automation has no one to approve a change, so keep scheduled server jobs to reads and reports.

What xCloud does for server management

xCloud lets the agent list your servers, read their monitoring, and manage services, Node.js and PHP versions, cron jobs, firewall rules, Fail2Ban and sudo users. Changes that can interrupt a server stop for your approval, and a reboot is only reported as done after xCloud verifies a new boot.

  1. Pick the team and the server. The agent works on one team at a time and uses the server you name. If a name is missing or matches several servers, it lists them and asks. It always restates which server it is about to change before it changes it.
  2. Read the state first. It reads the server's status, installed services, runtimes and monitoring figures. A status such as low disk space or reboot required is worth surfacing on its own. Monitoring history is a paid-plan feature, so a free plan answers 403.
  3. Say what will change, then ask. For a service, runtime, cron, firewall or sudo change, the agent names the server, the item and the impact, for example that a Node.js default affects every Node site on the server. It waits for your approval when the change could interrupt a service.
  4. Follow the task to the end. xCloud accepts server work and returns before it finishes. The agent reads the server's task list until the task settles and reports the real outcome, not the acceptance.
  5. Reboot with proof. A reboot starts a tracked operation. The agent reads that operation until xCloud reports a verified new boot. If the result is unconfirmed it investigates and never repeats the reboot just to check.
  6. Buy a server only after approval. A new server is billable. The agent checks what you already have, reads the plans and the card on file, shows the plan, region and price, and waits for a yes. It sends the purchase once with an idempotency key so a retry cannot buy a second server.

Reference

Server management Settings and Limits on xCloud

The facts OpenClaw works within when it manages servers. Where a row names the dashboard, that step stays yours to take there.

Setting or limitWhat applies
InventoryEvery server on the team with its status, stack and the sites it hosts, plus the tasks, supervisor processes and site snapshots on a server
MonitoringCurrent CPU, memory and disk are readable. Monitoring history is a paid-plan feature: xCloud answers 403 on the free plan, which is a plan limit and not a permission
ServicesInstall, enable, restart and disable. A restart runs without a server-side prompt; the agent still confirms the exact server, service and impact before any service change, because disabling ssh, nginx or a database can lock you out or cause downtime
Node.js versionsRead the installed versions and set the default. The default is server-wide and affects every Node site on the server
PHP versionsInstall, uninstall, set the default, patch and toggle OPcache. The server default changes only the command-line php and the version new sites get; it does not change existing sites, and a single site's PHP version is a dashboard setting under Site > Site Settings
Cron jobsList, create, update, delete, run now and read the last output for server cron jobs. Site cron is a separate resource
Firewall rulesList, create, delete, enable and disable rules with a name, protocol, allow or deny, port and optional source IP
Fail2Ban and IP accessList, ban and unban IP addresses, read the SSH restriction status, and whitelist your current IP or xCloud's own IPs
Sudo usersList, create or update and delete sudo users. A password is a secret and private keys are never returned
Verified rebootsStart a tracked reboot and read its operation; only a verified new boot proves it worked. An unconfirmed reboot can be rechecked without rebooting again
Buying a serverBillable, so it needs an approved plan, region and price, a card on file and an idempotency key. It buys xCloud-managed servers only
Dashboard-onlyResizing or deleting a server, a provider backup of the whole server (Server > Backup), bringing your own server, databases and database users, and PHP settings such as memory limit or upload size

Rules OpenClaw has to follow

  • A change that can interrupt a server stops for your approval, and the agent names the server, the service and the impact first.
  • Buying a server is billable: the agent shows the plan, region and price and waits for your yes, and it never retries a purchase without checking your server list first.
  • A reboot is only reported as done when xCloud verifies a new boot, and an unconfirmed reboot is investigated, not repeated.
  • Disabling ssh, nginx, a database or a runtime service needs your explicit confirmation immediately before the call, because it can lock you out or take sites offline.
  • Resizing or deleting a server, provider server backups, bringing your own server and per-site PHP versions are dashboard steps; the agent gives you the path and the dashboard link xCloud returned.

Example prompts

What Can You Ask OpenClaw to Do for Server management?

Type these as written and swap in your own repository, site and server names. Reads and routine actions such as backups, cache purges, PageSpeed scans and vulnerability scans run straight away; creating, deploying, updating, rebooting, deleting, buying or starting a broken-link scan stops and asks first.

Prompt
Frankfurt feels slow. Check its CPU, memory and disk and tell me whether anything is close to full.
Prompt
Add a firewall rule on the Frankfurt server that allows port 5432 only from 203.0.113.10. Show me the rule before you create it.
Prompt
Every Monday at 8am, read all my servers and post here which have low disk, a pending reboot or banned IPs. Change nothing.
Prompt
List all my xCloud servers with CPU, RAM and disk usage, and flag any server above 80% disk.
Prompt
List the cron jobs on the Frankfurt server with their schedules.
Prompt
Create a server cron job for the WooCommerce Action Scheduler every five minutes. Show me the final command and schedule before creating it.
Prompt
Install Redis on the Frankfurt server and enable the service.
Prompt
Switch the Frankfurt server's default Node.js to the latest LTS major.
Prompt
Reboot the staging server and tell me when it is back.
Prompt
Show me the IP addresses Fail2Ban has banned on the Frankfurt server, and unban 203.0.113.10.
Prompt
Create a new xCloud server on the smallest plan in Singapore. Show me the plan and price first and wait for my approval.

OpenClaw and Server management: Frequently Asked Questions

What people ask before they let OpenClaw manage servers through xCloud.

Can I approve an xCloud server reboot from my phone in OpenClaw?

Yes. OpenClaw asks in the chat, you reply yes, and it starts a tracked reboot and reports back only when xCloud verifies a new boot. If the result stays unconfirmed it investigates and does not reboot a second time.

Can an OpenClaw automation restart a service or reboot a server on its own?

It should not. The servers skill confirms the server, the service and the impact before any change, and xCloud stops a reboot, a runtime change or a purchase for explicit confirmation. Keep automations to reads and reports, and send the change as a message you can approve.

Does the agent ask before it reboots a server?

Yes. A reboot stops for your explicit confirmation, then the agent starts a tracked reboot and reads the operation until xCloud reports a verified new boot. If the result stays unconfirmed it investigates rather than rebooting a second time.

Can an AI agent buy a new server for me?

Yes, but only after you approve it. A new server is billable, so the agent first checks your existing servers, reads the available plans and your card on file, then shows the plan, region and price and waits for your yes. It sends the purchase once, so a retry cannot buy a second server.

If the agent changes the server's PHP default, do my sites change version?

No. The server default changes the command-line php and the version new sites get, and it moves no existing site. Each site keeps its own PHP version, which you change in the dashboard under Site > Site Settings.

Can the agent resize or delete a server?

No. Resizing and deleting a server are dashboard-only, as are a provider backup of the whole server, databases and bringing your own server. The agent can tell you where the control is and give you the server's dashboard link.

Why did the agent say monitoring history is not available?

Monitoring history is a paid-plan feature, so xCloud answers 403 on the free plan. Current CPU, memory and disk readings are still available, and the agent will say that it is a plan limit, not a missing permission.

Other agents

Server management with Other Agents

The same job, the same xCloud tools, a guide for each client.

Run Your Hosting from OpenClaw

xCloud MCP, the Agent Skills and the Public API are free with every account. Connect once and ask.