Windsurf + xCloud
Manage servers with Windsurf on xCloud
Managing servers with Windsurf means asking the Devin Local agent in your editor to read your xCloud servers and change their cron jobs, services and security rules while the code that depends on them is open beside it.
- Skill: xcloud:servers
- Toolsets: servers, alerts, user
- Free with every xCloud account
YouAdd a server cron job on Frankfurt that runs this project's scheduler every minute.
servers_cron-jobsread-only
AgentFrankfurt has two cron jobs and neither runs a scheduler. From the project I would add: * * * * * php artisan schedule:run, run from the shop site's directory. Create it?
YouYes.
servers_cron-jobs_createneeds approval
AgentCreated. Want me to run it once now and read the output, so you know it works before you rely on it?
YouYes, run it.
servers_cron-jobs_executeneeds approval
servers_cron-jobs_outputread-only
AgentThe run finished with no errors; the output is in the job log.
. Keep a human in the loop: xCloud stops and asks before anything that creates, deploys, updates, reboots, deletes or buys.
Setup
How Do You Set Up Windsurf to Manage servers on xCloud?
Connect Windsurf once; every job on this account uses the same connection. Then ask in plain words.
Add xCloud to the Devin Local agent
New tabs in Devin Desktop use the Devin Local agent, which reads MCP servers from the Devin CLI config files. Run this in a terminal: the URL is treated as Streamable HTTP, and the second command opens the browser for the xCloud sign-in (the agent also prompts on first use). By default the entry lands in .devin/mcp_config.local.json for the current project; add -s user to the first command to share it across projects in ~/.config/devin/mcp_config.json, where the entry reads url plus transport http.
devin mcp add xcloud https://app.xcloud.host/mcp devin mcp login xcloudOr edit the legacy Cascade config
If your tab runs the legacy Cascade agent, click the three-dot menu in the Cascade panel, then the Open MCP config file icon in the MCPs section, and add this under mcpServers. Cascade allows 100 tools in total and the full xCloud server offers 188 operations plus two search tools, so point serverUrl at the compact profile, five tools that reach every operation through search and call; a single toolset such as ?toolsets=sites (60 tools) also fits, but sites and servers together are 121 tools. Windsurf's file has been at ~/.codeium/windsurf/mcp_config.json, and the current documentation lists ~/.config/devin/mcp_config.json on macOS and Linux and %APPDATA%\devin\mcp_config.json on Windows; the icon opens the one your version reads.
{ "mcpServers": { "xcloud": { "serverUrl": "https://app.xcloud.host/mcp?profile=compact" } } }No browser sign-in? Use an API key
Create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things in Settings, Developers, API Tokens, export it as XCLOUD_TOKEN and add a headers field to the xcloud entry. Both agents fill in the ${env:XCLOUD_TOKEN} reference from your environment, so the token itself stays out of the file. The Devin Local entry is shown; for Cascade the same headers field sits beside serverUrl.
"xcloud": { "url": "https://app.xcloud.host/mcp", "transport": "http", "headers": { "Authorization": "Bearer ${env:XCLOUD_TOKEN}" } }Check it worked
Then ask Windsurf for the job itself, for example:
Create a server cron job on the Frankfurt server that runs the scheduler command in this project every minute. Show me the final command and schedule before you create it.
In practice
How Does Server management Work from Windsurf?
The strongest reason to manage a server from Windsurf is that the agent can see your project. Say your application needs a scheduler to run every minute. You ask the agent to create a server cron job for it on the Frankfurt server. It reads the project to find the command, calls servers_cron-jobs to see what already runs on that server, and shows you the final command and schedule before it creates the job. After you approve, it calls servers_cron-jobs_create, runs the job once with servers_cron-jobs_execute and reads the last output with servers_cron-jobs_output, so you know the command works and not just that it was saved. Say server cron job when you mean one, because xCloud keeps site cron as a separate resource.
The same chat handles the reading you would otherwise do in the dashboard. Ask which servers show Low disk space or Reboot Required and the agent lists them with their usage. Ask for the firewall rules on a server and it returns each rule with its name, protocol, action, port and source address, so you can check that a database port is not open to the world before you deploy the code that talks to it. Services, Node.js defaults and PHP versions follow the pattern you know from the job: the agent restates the server, names the impact, asks, and reads the server's task list until the work settles. A cron job create or a reboot is previewed by xCloud and waits for your explicit confirmation, while a service restart runs without an xCloud prompt, and Devin Local asks before any of them because it asks before an MCP tool runs by default.
Connecting is devin mcp add xcloud https://app.xcloud.host/mcp followed by devin mcp login xcloud, and Devin Local documents no tool cap, so the full URL is fine. If your tab runs the legacy Cascade agent, one constraint shapes this job: Cascade allows 100 tools in total across every MCP server you connect. Server management only needs the server, alert and account areas of xCloud, so scope its connection to those and leave the rest out. Cascade then spends its slots on the tools you will use and keeps room for the other servers in your config.
Windsurf specific: The full xCloud server offers 188 operations plus two search tools, which is more than legacy Cascade's 100-tool total. For server work, point Cascade's serverUrl at https://app.xcloud.host/mcp?toolsets=servers,alerts,user so it loads only the server, alert and account areas, or use the compact profile for a five-tool footprint. Cascade remote entries use serverUrl or url plus optional headers, and if the tools do not show up after you edit the file, check that you changed the file Open MCP config file opens. Devin Local needs none of that: its entry is a url with transport set to http, in ~/.config/devin/mcp_config.json or a project .devin/mcp_config.json, and devin mcp login xcloud handles the sign-in.
What xCloud does for server management
xCloud lets the agent list your servers, read their monitoring, and manage services, Node.js and PHP versions, cron jobs, firewall rules, Fail2Ban and sudo users. Changes that can interrupt a server stop for your approval, and a reboot is only reported as done after xCloud verifies a new boot.
- Pick the team and the server. The agent works on one team at a time and uses the server you name. If a name is missing or matches several servers, it lists them and asks. It always restates which server it is about to change before it changes it.
- Read the state first. It reads the server's status, installed services, runtimes and monitoring figures. A status such as low disk space or reboot required is worth surfacing on its own. Monitoring history is a paid-plan feature, so a free plan answers 403.
- Say what will change, then ask. For a service, runtime, cron, firewall or sudo change, the agent names the server, the item and the impact, for example that a Node.js default affects every Node site on the server. It waits for your approval when the change could interrupt a service.
- Follow the task to the end. xCloud accepts server work and returns before it finishes. The agent reads the server's task list until the task settles and reports the real outcome, not the acceptance.
- Reboot with proof. A reboot starts a tracked operation. The agent reads that operation until xCloud reports a verified new boot. If the result is unconfirmed it investigates and never repeats the reboot just to check.
- Buy a server only after approval. A new server is billable. The agent checks what you already have, reads the plans and the card on file, shows the plan, region and price, and waits for a yes. It sends the purchase once with an idempotency key so a retry cannot buy a second server.
Reference
Server management Settings and Limits on xCloud
The facts Windsurf works within when it manages servers. Where a row names the dashboard, that step stays yours to take there.
| Setting or limit | What applies |
|---|---|
| Inventory | Every server on the team with its status, stack and the sites it hosts, plus the tasks, supervisor processes and site snapshots on a server |
| Monitoring | Current CPU, memory and disk are readable. Monitoring history is a paid-plan feature: xCloud answers 403 on the free plan, which is a plan limit and not a permission |
| Services | Install, enable, restart and disable. A restart runs without a server-side prompt; the agent still confirms the exact server, service and impact before any service change, because disabling ssh, nginx or a database can lock you out or cause downtime |
| Node.js versions | Read the installed versions and set the default. The default is server-wide and affects every Node site on the server |
| PHP versions | Install, uninstall, set the default, patch and toggle OPcache. The server default changes only the command-line php and the version new sites get; it does not change existing sites, and a single site's PHP version is a dashboard setting under Site > Site Settings |
| Cron jobs | List, create, update, delete, run now and read the last output for server cron jobs. Site cron is a separate resource |
| Firewall rules | List, create, delete, enable and disable rules with a name, protocol, allow or deny, port and optional source IP |
| Fail2Ban and IP access | List, ban and unban IP addresses, read the SSH restriction status, and whitelist your current IP or xCloud's own IPs |
| Sudo users | List, create or update and delete sudo users. A password is a secret and private keys are never returned |
| Verified reboots | Start a tracked reboot and read its operation; only a verified new boot proves it worked. An unconfirmed reboot can be rechecked without rebooting again |
| Buying a server | Billable, so it needs an approved plan, region and price, a card on file and an idempotency key. It buys xCloud-managed servers only |
| Dashboard-only | Resizing or deleting a server, a provider backup of the whole server (Server > Backup), bringing your own server, databases and database users, and PHP settings such as memory limit or upload size |
Rules Windsurf has to follow
- A change that can interrupt a server stops for your approval, and the agent names the server, the service and the impact first.
- Buying a server is billable: the agent shows the plan, region and price and waits for your yes, and it never retries a purchase without checking your server list first.
- A reboot is only reported as done when xCloud verifies a new boot, and an unconfirmed reboot is investigated, not repeated.
- Disabling ssh, nginx, a database or a runtime service needs your explicit confirmation immediately before the call, because it can lock you out or take sites offline.
- Resizing or deleting a server, provider server backups, bringing your own server and per-site PHP versions are dashboard steps; the agent gives you the path and the dashboard link xCloud returned.
Example prompts
What Can You Ask Windsurf to Do for Server management?
Type these as written and swap in your own repository, site and server names. Reads and routine actions such as backups, cache purges, PageSpeed scans and vulnerability scans run straight away; creating, deploying, updating, rebooting, deleting, buying or starting a broken-link scan stops and asks first.
Create a server cron job on the Frankfurt server that runs the scheduler command in this project every minute. Show me the final command and schedule before you create it.Which of my servers show Low disk space or Reboot Required? List them with their disk usage.Show every firewall rule on the Frankfurt server and tell me whether port 3306 is open to anyone. Do not change anything.List all my xCloud servers with CPU, RAM and disk usage, and flag any server above 80% disk.List the cron jobs on the Frankfurt server with their schedules.Create a server cron job for the WooCommerce Action Scheduler every five minutes. Show me the final command and schedule before creating it.Install Redis on the Frankfurt server and enable the service.Switch the Frankfurt server's default Node.js to the latest LTS major.Reboot the staging server and tell me when it is back.Show me the IP addresses Fail2Ban has banned on the Frankfurt server, and unban 203.0.113.10.Create a new xCloud server on the smallest plan in Singapore. Show me the plan and price first and wait for my approval.Windsurf and Server management: Frequently Asked Questions
What people ask before they let Windsurf manage servers through xCloud.
How do I connect the xCloud server tools in Windsurf without hitting a tool limit?
On Devin Local, connect the full URL, https://app.xcloud.host/mcp, because no tool cap is documented for it. On the legacy Cascade agent, which allows 100 tools in total, connect https://app.xcloud.host/mcp?toolsets=servers,alerts,user as the serverUrl, which loads only the server, alert and account tools. The compact profile, ?profile=compact, exposes five tools if you want the smallest footprint, and disabledTools lists tool names to switch off.
Can Windsurf's agent write a server cron job from the code in my project?
Yes. It reads the project for the command, lists the cron jobs already on the server, and shows you the final command and schedule before it creates the job. After you approve it can run the job once and read the last output to confirm it works.
Does the agent ask before it reboots a server?
Yes. A reboot stops for your explicit confirmation, then the agent starts a tracked reboot and reads the operation until xCloud reports a verified new boot. If the result stays unconfirmed it investigates rather than rebooting a second time.
Can an AI agent buy a new server for me?
Yes, but only after you approve it. A new server is billable, so the agent first checks your existing servers, reads the available plans and your card on file, then shows the plan, region and price and waits for your yes. It sends the purchase once, so a retry cannot buy a second server.
If the agent changes the server's PHP default, do my sites change version?
No. The server default changes the command-line php and the version new sites get, and it moves no existing site. Each site keeps its own PHP version, which you change in the dashboard under Site > Site Settings.
Can the agent resize or delete a server?
No. Resizing and deleting a server are dashboard-only, as are a provider backup of the whole server, databases and bringing your own server. The agent can tell you where the control is and give you the server's dashboard link.
Why did the agent say monitoring history is not available?
Monitoring history is a paid-plan feature, so xCloud answers 403 on the free plan. Current CPU, memory and disk readings are still available, and the agent will say that it is a plan limit, not a missing permission.
Other agents
Server management with Other Agents
The same job, the same xCloud tools, a guide for each client.
- Manage servers with Claude CodeAnthropic's terminal coding agent. One claude mcp add command, plus the xCloud skills plugin with nine skills on top.
- Manage servers with ClaudeAnthropic's chat assistant on the web and desktop. Add xCloud as a custom connector, no terminal needed.
- Manage servers with Claude CoworkAnthropic's desktop agent for delegated work. Add the xCloud connector, then hand off hosting jobs.
- Manage servers with CursorThe AI code editor. One mcp.json entry with the compact URL, because Cursor stops at 40 tools.
- Manage servers with CodexOpenAI's coding agent for the terminal. A codex mcp add command or a config.toml entry, then codex mcp login.
- Manage servers with OpenCodeThe open-source terminal coding agent. One remote MCP entry, then opencode mcp auth xcloud.
- Manage servers with Hermes AgentNous Research's agent with memory and a built-in scheduler. An mcp_servers entry in config.yaml and one login.
- Manage servers with OpenClawThe open-source agent runtime with chat apps and automations. ClawHub skill plus the MCP client.
- Manage servers with GitHub CopilotCopilot agent mode in VS Code. One .vscode/mcp.json entry, or the Agent Plugins package.
- Manage servers with Gemini CLIGoogle's terminal agent. One gemini mcp add command, OAuth found automatically.
- Manage servers with ChatGPTOpenAI's chat assistant. A developer-mode app with the xCloud MCP URL and OAuth.
- Manage servers with ChatGPT dotsOpenAI's always-on agent in ChatGPT. Uses the xCloud MCP plugin you add in ChatGPT, with custom rules and scheduled tasks.
- Manage servers with GrokxAI's terminal agent, Grok Build. One grok mcp add command or a config.toml entry.
- Manage servers with Grok BotxAI's always-on Bots on a cloud computer. One Remote HTTPS MCP plugin, OAuth sign-in, routines on a schedule.
- Manage servers with KiroAWS's agentic IDE. One url entry in .kiro/settings/mcp.json, plus the portable xCloud Agent Plugins package.
- Manage servers with AntigravityGoogle's agentic IDE. One serverUrl entry in mcp_config.json and a browser sign-in.
- Manage servers with ZedThe Zed editor's Agent Panel. One context_servers entry in settings.json and a browser sign-in.
More Windsurf guides
- Windsurf and xCloud overview
- Deploy from Git with Windsurf
- Run Docker apps with Windsurf
- Install one-click apps with Windsurf
- Manage WordPress with Windsurf
- Back up and stage sites with Windsurf
- Manage SSL and domains with Windsurf
- Troubleshoot a broken site with Windsurf
- Speed up a slow site with Windsurf
- Secure sites and servers with Windsurf
Run Your Hosting from Windsurf
xCloud MCP, the Agent Skills and the Public API are free with every account. Connect once and ask.