AI & AGENTS

Your servers, over MCP.

Connect Claude or any MCP client to Depfloy and it can deploy, roll back, read logs and change environment variables on the servers you own — inside exactly the permissions the person it acts for already has.

The MCP server is available on the Pro plan and above. Compare plans →

CLAUDE · MCP
The 14:02 deploy on acme-app failed — roll back and show me why.
▸ depfloy.list_rollback_candidates project=acme-app
▸ depfloy.rollback release=142 → rollback queued
▸ depfloy.get_deployment_logs lines=40
Rolled back to release-142 — the site never stopped serving, because the failed release was never linked. The build died at composer install: ext-intl is missing on acme-web-1. Want me to install it and re-run the deploy?
It acts as you, not as itself

A connection is one user in one organization. Every call is checked against that user's role and the token's abilities — both have to allow it.

$ depfloy deploy acme-app
→ building on acme-web-1 … release live in 1m 14s
$ depfloy logs acme-app --source nginx_error
THE TOOLS

What an agent can reach.

Grouped the way an operator thinks about them rather than alphabetically. Each one is the same API the dashboard uses, so an agent cannot do anything a person could not. Two recipes ship with the connection as well — one for running a deployment, one for working out why a deployment failed — so a client does not have to be told the order to do them in.

Deploy and recover

Trigger a deploy and follow it to the end, cancel one started by mistake, or roll back to a previous release. Deploys queue and return an id — the agent polls until it finishes rather than guessing. Recycling replaces the running process from the release already live, which fixes a bad process without changing what the site serves.

deploy get_deployment list_deployments cancel_deployment rollback list_rollback_candidates recycle_project
Find out what went wrong

Application logs, nginx access and error logs, supervisor programs, and host metrics. This is the group agents actually use most, because reading a log is the step before every fix.

get_deployment_logs read_project_logs get_monitoring get_background_job_logs
Configuration

Read and change environment variables, check domains and certificates, put a project into maintenance mode while something is being repaired.

get_env update_env list_domains list_certificates set_maintenance_mode
Operations

Restart a service or a worker, run a command in the project directory, trigger a backup off-schedule before a risky change.

restart_service restart_background_job run_project_command run_backup list_backups
BOUNDARIES

The interesting part is what it cannot do.

Handing an agent production access is only reasonable if the limits are real. These are enforced on the server, not in the prompt.

Two permission checks

The role of the user and the abilities of the token both have to permit a call. A token created for reading cannot deploy even when its owner is an Owner.

One organization at a time

A connection reaches one organization. Ids from another are not even visible unless the call names it explicitly and the user belongs to it.

Logs are data, not orders

Output from your app, your visitors and your server is passed to the agent as material to report on. Text inside a log that looks like an instruction is meant to be surfaced, not obeyed.

FAQ

Agent questions

What stops an agent from doing something destructive? +
The same thing that stops a person: permissions. Every tool call is checked against the role of the user the connection acts for and the abilities of the token it was created with. A read-scoped token cannot deploy, no matter how the request is phrased.
Can an agent see all of my organizations? +
A connection acts as one user in one organization and reaches nothing outside it. Other organizations the user belongs to are reported by whoami, and acting in one of them is an explicit argument on each call.
What if a log line tells the agent to do something? +
Log output and command output come from your application, your visitors and your server, so the server instructs the agent to treat them as data to report rather than instructions to follow. An agent that reads "delete everything" in a log should tell you it saw that, not act on it.
Do I need Claude specifically? +
No. It is a standard MCP server, so any MCP client works. Claude is the one we test against most.
Is there a CLI as well? +
Yes. The same operations are available from a terminal, which is the better fit for scripts and CI where you want an exact command rather than a conversation.
Does the agent have to know which tool to call? +
For a single action, no — it picks from what you ask. For the two jobs where the order matters, the server ships the order as a recipe: deploy_and_follow and diagnose_deployment. Clients that support MCP prompts offer them as something you pick; the tools work either way.

Point an agent at one project.

7 days free, no credit card. Create a token scoped to reading, connect it, and see what it can tell you about a deploy.