How to Connect Kiro to xCloud MCP
Updated October 4, 2026 · 4 min read
Kiro is Amazon Web Services’ agentic IDE, where an AI agent plans and edits your project from a chat panel. Connected to xCloud through one line of MCP configuration, it deploys repositories, updates WordPress, checks SSL and diagnoses failures without you leaving the editor.
This guide covers the connection only. For what Kiro can do once it is connected, with one guide per hosting job, see the Kiro and xCloud guide. The xCloud side is free with every account, including the free plan.
What you need
- An xCloud account. If you do not have one yet, sign up for free.
- Kiro installed and signed in.
- A browser for the OAuth sign-in. A machine without a browser can use an API key instead; the steps below show both.
The xCloud MCP server lives at one endpoint, https://app.xcloud.host/mcp, over the MCP Streamable HTTP transport. The same setup also lives in your dashboard under Settings → Developers → MCP.
Step 1: Add xCloud to your Kiro MCP config
Open the Command Palette (Cmd+Shift+P on Mac, Ctrl+Shift+P on Windows and Linux), search for MCP and choose Kiro: Open workspace MCP config (JSON) for .kiro/settings/mcp.json, or Kiro: Open user MCP config (JSON) for ~/.kiro/settings/mcp.json. Paste this, save, and Kiro reconnects on its own. The first connection opens the xCloud approval screen in your browser, where you tick the teams and choose Read-only or Full access.
{
"mcpServers": {
"xcloud": {
"url": "https://app.xcloud.host/mcp"
}
}
}
Step 2: Choose which xCloud tools Kiro may run
Optional. autoApprove lists tools Kiro runs without asking, and disabledTools hides tools from the agent altogether. The two names here are real xCloud tools; swap in your own. Avoid the “*” wildcard in autoApprove, so Kiro’s own prompt stays as a second check beside xCloud’s confirmation.
{
"mcpServers": {
"xcloud": {
"url": "https://app.xcloud.host/mcp",
"autoApprove": ["xcloud_docs_search", "xcloud_agent_search"],
"disabledTools": ["sites_destroy"]
}
}
}
Step 3: No browser sign-in? Use an API key
Create a token with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things in Settings, Developers, API Tokens, export it as XCLOUD_API_TOKEN, and pass it in headers. Kiro only expands environment variables you have approved, so add XCLOUD_API_TOKEN under the Mcp Approved Env Vars setting. Never paste the token into the file or into chat.
{
"mcpServers": {
"xcloud": {
"url": "https://app.xcloud.host/mcp",
"headers": {
"Authorization": "Bearer ${XCLOUD_API_TOKEN}"
}
}
}
}
Approve access in your browser
The first time Kiro reaches for an xCloud tool, your browser opens on the xCloud authorization screen. Tick the teams the connection may act on and choose Read-only or Full access. Kiro opens the browser sign-in for an OAuth-protected server and uses Dynamic Client Registration, which xCloud supports, so the url line is all the configuration it needs. A machine without a browser passes an API key that carries the mcp:invoke scope and the read or write abilities it needs in headers.

Every connection is listed with your API keys, so you can revoke it at any time. Read-only is enough for reports and checks; choose Full access when you want the agent to deploy, update or change things. With Full access, routine actions such as a backup, a cache purge or a service restart run without an xCloud prompt, while creating, deploying, updating, rebooting, deleting or buying still waits for your confirmation.
Check it worked
Ask Kiro:
Who am I on xCloud?
It should answer with your real account name, email and teams, not a guess. If it says it has no xCloud tools, re-check the step above and restart the client.
What Kiro can do on xCloud
On the xCloud side, reads run straight away, and anything that creates, deploys, updates, reboots, deletes or buys is previewed first and waits for your confirmation. Kiro’s own approval prompts, where it has them, apply on top of that. A few prompts to start with:
Use xCloud to list my servers and tell me which ones are above 80 percent disk usage.
Deploy https://github.com/acme/shop to my Frankfurt server and show me the dry run before you create anything.
Update all plugins on example.com, then check that the homepage still loads.
There is a guide for each hosting job, from deploying a repository to fixing a 502, on the Kiro and xCloud guide, and a longer prompt library in What You Can Ask xCloud MCP to Do.
Good to know
- MCP support has to be switched on in Kiro first: open Settings, search for MCP and enable the MCP support setting.
- If the same server name appears in several places, an agent config’s mcpServers field beats the workspace file, and the workspace file beats the user file.
- Kiro expands only approved environment variables. If a ${XCLOUD_API_TOKEN} header does not work, add the variable under the Mcp Approved Env Vars setting.
- Kiro’s documentation says to review tool permissions before adding tools to autoApprove, and that advice applies here: approve reads, not changes.
Frequently asked questions
How do I connect Kiro to xCloud?
Open the Command Palette, run Kiro: Open workspace MCP config (JSON) or Kiro: Open user MCP config (JSON), and add an xcloud entry under mcpServers with url set to https://app.xcloud.host/mcp. Save the file, approve the access level in the browser tab that opens, and ask who am I on xCloud to confirm.
Where does Kiro keep its MCP configuration?
In two places: .kiro/settings/mcp.json inside a workspace, and ~/.kiro/settings/mcp.json for every workspace. If both define the same server, the workspace entry takes precedence. Either file takes effect when you save it.
Does Kiro need an xCloud API key?
Not when you sign in with OAuth. Kiro opens the browser, you choose the teams and the access level, and the connection is live. An API key is only for a machine without a browser. Create one with the mcp:invoke scope plus the read abilities for the areas it will use (read:servers and read:sites, with read:billing and read:addons for billing and add-on tools) and the matching write: abilities if it should change things and pass it in headers as Authorization: Bearer followed by the token.
Do I have to restart Kiro after editing mcp.json?
No. Kiro watches its MCP files and reconnects when you save, restarting only the servers whose entries changed. If the xCloud tools do not appear, check that the MCP support setting is enabled and that the JSON is valid.
Next steps
- Kiro and xCloud: every job guide
- How to connect xCloud MCP to your AI agent for the other clients
- How to install and use xCloud AI Agent Skills
- Multi-team API tokens and MCP access
If you run into any issues connecting, feel free to reach out to our support team.