Your servers, over MCP.
Connect Claude or any MCP client to Depfloy and it can deploy, roll back, read logs and change environment variables on the servers you own — inside exactly the permissions the person it acts for already has.
The MCP server is available on the Pro plan and above. Compare plans →
A connection is one user in one organization. Every call is checked against that user's role and the token's abilities — both have to allow it.
What an agent can reach.
Grouped the way an operator thinks about them rather than alphabetically. Each one is the same API the dashboard uses, so an agent cannot do anything a person could not. Two recipes ship with the connection as well — one for running a deployment, one for working out why a deployment failed — so a client does not have to be told the order to do them in.
Trigger a deploy and follow it to the end, cancel one started by mistake, or roll back to a previous release. Deploys queue and return an id — the agent polls until it finishes rather than guessing. Recycling replaces the running process from the release already live, which fixes a bad process without changing what the site serves.
Application logs, nginx access and error logs, supervisor programs, and host metrics. This is the group agents actually use most, because reading a log is the step before every fix.
Read and change environment variables, check domains and certificates, put a project into maintenance mode while something is being repaired.
Restart a service or a worker, run a command in the project directory, trigger a backup off-schedule before a risky change.
The interesting part is what it cannot do.
Handing an agent production access is only reasonable if the limits are real. These are enforced on the server, not in the prompt.
The role of the user and the abilities of the token both have to permit a call. A token created for reading cannot deploy even when its owner is an Owner.
A connection reaches one organization. Ids from another are not even visible unless the call names it explicitly and the user belongs to it.
Output from your app, your visitors and your server is passed to the agent as material to report on. Text inside a log that looks like an instruction is meant to be surfaced, not obeyed.
Agent questions
What stops an agent from doing something destructive? + −
Can an agent see all of my organizations? + −
What if a log line tells the agent to do something? + −
Do I need Claude specifically? + −
Is there a CLI as well? + −
Does the agent have to know which tool to call? + −
Point an agent at one project.
7 days free, no credit card. Create a token scoped to reading, connect it, and see what it can tell you about a deploy.