Windsurf + xCloud

Back up and stage sites with Windsurf on xCloud

Backing up and staging sites with Windsurf means asking the Devin Local agent in your editor to read your xCloud backup state, take a backup before a risky change and create a staging copy of a Git site, without leaving the project window.

  • Skill: xcloud:sites
  • Toolsets: sites
  • Free with every xCloud account

YouWhich of my sites have no backup schedule?

sites_backupSettingsread-only

AgentTwo of five: blog.example.com and docs.example.com. Schedules for native sites are set in the dashboard under Site, Site Backup, Backup Settings. Want a backup of either now?

YouBack up the blog now.

sites_backup

AgentBackup of blog.example.com completed and stored locally.

. Keep a human in the loop: xCloud stops and asks before anything that creates, deploys, updates, reboots, deletes or buys.

Setup

How Do You Set Up Windsurf to Back up and stage sites on xCloud?

Connect Windsurf once; every job on this account uses the same connection. Then ask in plain words.

  1. Add xCloud to the Devin Local agent

    New tabs in Devin Desktop use the Devin Local agent, which reads MCP servers from the Devin CLI config files. Run this in a terminal: the URL is treated as Streamable HTTP, and the second command opens the browser for the xCloud sign-in (the agent also prompts on first use). By default the entry lands in .devin/mcp_config.local.json for the current project; add -s user to the first command to share it across projects in ~/.config/devin/mcp_config.json, where the entry reads url plus transport http.

    Shell
    devin mcp add xcloud https://app.xcloud.host/mcp
    devin mcp login xcloud
  2. Or edit the legacy Cascade config

    If your tab runs the legacy Cascade agent, click the three-dot menu in the Cascade panel, then the Open MCP config file icon in the MCPs section, and add this under mcpServers. Cascade allows 100 tools in total and the full xCloud server offers 188 operations plus two search tools, so point serverUrl at the compact profile, five tools that reach every operation through search and call; a single toolset such as ?toolsets=sites (60 tools) also fits, but sites and servers together are 121 tools. Windsurf's file has been at ~/.codeium/windsurf/mcp_config.json, and the current documentation lists ~/.config/devin/mcp_config.json on macOS and Linux and %APPDATA%\devin\mcp_config.json on Windows; the icon opens the one your version reads.

    JSON
    {
      "mcpServers": {
        "xcloud": {
          "serverUrl": "https://app.xcloud.host/mcp?profile=compact"
        }
      }
    }
  3. No browser sign-in? Use an API key

    Create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things in Settings, Developers, API Tokens, export it as XCLOUD_TOKEN and add a headers field to the xcloud entry. Both agents fill in the ${env:XCLOUD_TOKEN} reference from your environment, so the token itself stays out of the file. The Devin Local entry is shown; for Cascade the same headers field sits beside serverUrl.

    JSON
    "xcloud": {
      "url": "https://app.xcloud.host/mcp",
      "transport": "http",
      "headers": {
        "Authorization": "Bearer ${env:XCLOUD_TOKEN}"
      }
    }
  4. Check it worked

    Then ask Windsurf for the job itself, for example:

    Prompt
    Back up the shop site before this migration, and tell me when the backup has finished.

In practice

How Does Backups and staging Work from Windsurf?

Windsurf, now shipped as Devin Desktop, puts the Devin Local agent beside the code, and the agent works with the files open in your workspace. That helps before a risky change, because it can see what you changed: a migration, a plugin swap, a deploy script. Type back up the shop site before this migration into the chat and it calls xCloud, finds the site by name, reads its backup status and says whether it is a native site or a Docker app. For a native site it starts a local backup by default, or a remote one when a storage provider is connected. For a Docker app it warns that the app stops briefly. xCloud runs the backup without a confirmation prompt of its own, but Devin Local asks before an MCP tool runs by default, so expect an approval card in the chat first. Once you allow it, you see the tool card and then a plain sentence when the backup has completed.

The agent is just as useful for the questions that come before the backup. Ask which sites have no schedule and it reads the backup settings for each of them and returns a list. Ask when the last backup ran and it reads the status and the most recent entries. The answer is a short table in the chat that you can keep beside the code you are about to change. It does not change a native site's schedule, retention or destination, because those are read-only through xCloud and live in the dashboard under Site, Site Backup, Backup Settings. For a Docker app it can change the schedule, and it shows you the change first.

For staging, name the branch. The agent asks xCloud to create a staging environment for a Laravel, Node.js, custom PHP or Lovable site. Creating a site is previewed first, so xCloud waits for your explicit confirmation, and Devin Local asks before the tool call as well, which makes two gates. The agent then returns the staging URL, which you open in your browser to test the change before it reaches production. A WordPress staging copy and every restore are dashboard steps: the agent gives you the path and the dashboard link and leaves the click to you. When you later push staging data back to production in the dashboard, ask the agent for a backup of production first.

Windsurf specific: Connect with devin mcp add xcloud https://app.xcloud.host/mcp, then devin mcp login xcloud, and Devin Local can take the full server, since no tool cap is documented for it. If your tab runs the legacy Cascade agent, it allows 100 tools in total and the full server is more than that on its own, so point its serverUrl at https://app.xcloud.host/mcp?toolsets=sites, the toolset that holds the backup, backup settings and staging operations. Cascade opens its config file from Open MCP config file in the Cascade panel menu, and Devin Local reads ~/.config/devin/mcp_config.json or a project .devin/mcp_config.json.

What xCloud does for backups and staging

xCloud lets the agent read every site's backup state, start a backup on demand for native and Docker sites, and create a staging environment for Git sites. Restores, storage providers and WordPress staging stay in the dashboard, and the agent tells you the exact path when you ask for one.

  1. Find the site. The agent resolves the site by name or domain, restates which one it is about to act on, and reads whether it is a native site or a Docker app, because the two use different backup operations.
  2. Read the protection state. It reads the backup settings, status, count and recent backups. That answers whether the site has a schedule, when the last backup ran, whether it succeeded and where it is stored, before anything is changed.
  3. Back up now. A backup starts without an approval prompt. A native site takes a local backup by default or a remote one when a storage provider is connected. A Docker app is stopped briefly while its volumes are captured, so the agent says so before it backs up a production app.
  4. Wait for the result. xCloud queues the backup and returns straight away. The agent follows the backup task or row until it is terminal, then reports completed or failed instead of treating the queued response as done.
  5. Stage the change. For a Git site such as Laravel, Node.js, custom PHP or Lovable, the agent creates a staging environment from the branch you name, after you approve, and gives you its URL. A WordPress staging site is a dashboard step, and the agent gives you the path.
  6. Hand off restores and settings. If you ask to restore a backup, change a native site's schedule or add a storage provider, the agent explains that these are dashboard-only and gives the path and the site's dashboard link. It never improvises a workaround.

Reference

Backups and staging Settings and Limits on xCloud

The facts Windsurf works within when it backs up and stage sites. Where a row names the dashboard, that step stays yours to take there.

Setting or limitWhat applies
Native site backupOn demand through the API; the type is local (the default) or remote. A remote backup needs a storage provider with a working connection, otherwise xCloud refuses it with a 422 before anything is queued
Docker app backupOn demand through the API for Compose deploys and most one-click apps. The app is cold-stopped for a moment while volumes are captured. A remote copy goes to an S3-compatible or SFTP provider; Google Drive and pCloud are not supported for Docker apps
Reading backupsBackup list, count, status and settings are readable for every site. Docker apps also expose one backup's detail
Docker backup housekeepingThe agent can label a Docker backup with a note and delete one. Deleting is irreversible, so it names the exact backup by date and note first
Native schedule and retentionRead-only through the API. Change them in the dashboard under Site > Site Backup > Backup Settings
Docker backup settingsWritable through the API: automatic backup on or off, daily, weekly or monthly frequency, and the number of days to keep backups
RestoresDashboard-only for every site type: Site > Site Backup > Previous Backups > Restore. A backup can also be restored to another site from the same page
Storage providersDashboard-only, under Integrations > Storage Provider. Backup settings return a provider's identifier and status, never its credentials
Team-wide backup policyApplying one backup policy to many sites is dashboard-only, under Global Settings > Site Backup
Git stagingCreated through the API for Git sites on paid plans. On the free plan xCloud answers 403 because it is a plan limit, not a permission
WordPress stagingDashboard-only: xCloud answers 422 when the API is asked for it. Push and pull between staging and production also happen in the dashboard
SnapshotsSnapshots are listed per site. The server-wide snapshot list holds site snapshots, not a server image. Taking or restoring a snapshot, and a whole-server provider backup, stay in the dashboard

Rules Windsurf has to follow

  • A backup runs without an approval prompt, but the agent says when it briefly stops a Docker app and does not trigger one on a busy production app without telling you.
  • A queued backup is not a finished backup: the agent reports completed or failed only after it has read the result.
  • Restoring a backup, changing a native site's schedule, adding a storage provider and creating WordPress staging are dashboard steps; the agent gives you the path instead of guessing an operation.
  • Creating a staging environment stops for your approval, and deleting a backup names the exact backup first.
  • Before you push staging data to production in the dashboard, take a backup of the production site so you can recover if the push goes wrong.

Example prompts

What Can You Ask Windsurf to Do for Backups and staging?

Type these as written and swap in your own repository, site and server names. Reads and routine actions such as backups, cache purges, PageSpeed scans and vulnerability scans run straight away; creating, deploying, updating, rebooting, deleting, buying or starting a broken-link scan stops and asks first.

Prompt
Back up the shop site before this migration, and tell me when the backup has finished.
Prompt
Read the backup settings on every site and list the ones with no schedule. Do not change anything.
Prompt
Create a staging environment for the api site from the branch I have open and give me the URL.
Prompt
When was the last backup of the shop site, did it succeed, and where is it stored?
Prompt
Check the backup settings on every site and list the ones with no schedule.
Prompt
Take a backup of the n8n Docker app now, before I upgrade it, and tell me when it is done.
Prompt
Switch the n8n Docker app to a daily backup and keep backups for 14 days. Show me the change before you apply it.
Prompt
Create a staging environment for the API site from the feature/checkout branch and give me its URL.
Prompt
List the snapshots of the shop site and tell me which is newest.
Prompt
I need to restore the shop site to last night's backup. Tell me where to click.

Windsurf and Backups and staging: Frequently Asked Questions

What people ask before they let Windsurf back up and stage sites through xCloud.

Does Windsurf need the full xCloud server to take a backup?

No. Devin Local can take the full URL, https://app.xcloud.host/mcp, because no tool cap is documented for it. If your tab runs the legacy Cascade agent, add ?toolsets=sites to its serverUrl instead, which keeps the backup, backup settings and staging operations under Cascade's 100-tool cap.

Can Windsurf's agent change my backup schedule from the editor?

For Docker apps, yes, after it shows you the change: automatic backups on or off, daily, weekly or monthly, and the days kept. For native sites the schedule, retention and destination are read-only through xCloud, so the agent gives you the dashboard path under Site, Site Backup, Backup Settings.

Can an AI agent restore a backup for me?

No. Restoring a native or Docker backup is a dashboard step, under Site > Site Backup > Previous Backups > Restore. The agent can list the backups, tell you which one is newest and completed, and give you the site's dashboard link so you can start the restore yourself.

Does the agent ask before it takes a backup?

No. A backup is a routine action, so xCloud runs it without a confirmation prompt. For a Docker app the agent tells you first that the app stops briefly while its data is captured, and it reports the result only after the backup has finished.

Can the agent change my backup schedule?

For Docker apps, yes: it can turn automatic backups on or off, set daily, weekly or monthly, and set how many days backups are kept. For native sites the schedule, retention and destination are read-only through the API, so you change them in the dashboard under Site > Site Backup > Backup Settings.

Can the agent connect my S3 bucket or other storage?

No. Storage providers are added in the dashboard, under Integrations > Storage Provider, so credentials never pass through a chat. Once a provider exists, the agent can read which one a site's backup settings point at and use it for a remote backup.

Can the agent create a staging site for WordPress?

Not through the API. xCloud answers 422 for WordPress staging, so you create it in the dashboard from the site overview. For Laravel, Node.js, custom PHP and Lovable sites the agent can create a staging environment, which needs a paid plan.

Other agents

Backups and staging with Other Agents

The same job, the same xCloud tools, a guide for each client.

Run Your Hosting from Windsurf

xCloud MCP, the Agent Skills and the Public API are free with every account. Connect once and ask.