Skip to content
deploy
Browse the documentation

Use Vimonto Deploy from AI assistants (MCP)

Connect Claude Code, Claude Desktop, Cursor or VS Code to Vimonto Deploy through its MCP server: check servers and sites, deploy and follow tasks with an API token.

View as Markdown Updated October 11, 2026

Vimonto Deploy has a built-in MCP server, so AI assistants such as Claude Code, Claude Desktop, Cursor and VS Code can work with your organizations: list servers and sites, deploy a site and follow the deploy, read a failed task's output, create a database, and run backups and recipes. MCP, the Model Context Protocol, is the open standard these assistants use to call tools in other applications.

The MCP server is the API in another form. It signs in with a personal API token, and the assistant can do exactly what that token and your role allow, on the servers you have access to. Nothing can be deleted through it.

How do you connect an assistant?

  1. Open the account menu at the top right and choose Account settings → API tokens.
  2. Click New token, give it a Name such as "Claude Code", and choose its Scopes (see scopes). For an assistant that only needs to look around, Read is enough.
  3. Click Create token.
  4. The dialog Your new token shows the token and, under Connect an AI assistant, a Prompt with your token and address filled in. Click Copy and paste it into Claude Code, Cursor, VS Code or Claude Desktop: the assistant adds the connection to its own configuration, keeps the servers you already have, tells you whether to restart it, and checks that the connection works.

Prefer to set it up yourself? The tabs Claude Code, Claude Desktop, Cursor and VS Code next to Prompt show the command or configuration for each, also with your token and address filled in, as described below.

The token is shown once. When you close the dialog, the setup with the token is gone too; make a new token if you need it again. The AI assistants section on the same page shows the address of the MCP server at any time.

The server address is /mcp on the address where you use Vimonto Deploy, such as https://deploy.example.com/mcp. It speaks the Streamable HTTP transport and expects the token as a bearer token in the Authorization header. In the examples below replace deploy.example.com with your own address and YOUR_TOKEN with the token.

Claude Code

Run this in your terminal:

claude mcp add --transport http vimonto-deploy https://deploy.example.com/mcp \
  --header "Authorization: Bearer YOUR_TOKEN"

Add --scope user to use it in every project, not only the current one. Check it with claude mcp list, or /mcp inside Claude Code.

Cursor

Add this to ~/.cursor/mcp.json (every project) or .cursor/mcp.json in a project:

{
  "mcpServers": {
    "vimonto-deploy": {
      "url": "https://deploy.example.com/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_TOKEN"
      }
    }
  }
}

VS Code

Add this to .vscode/mcp.json in a project, or run MCP: Open User Configuration from the command palette for every project:

{
  "servers": {
    "vimonto-deploy": {
      "type": "http",
      "url": "https://deploy.example.com/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_TOKEN"
      }
    }
  }
}

Claude Desktop and other assistants that only start local servers

Claude Desktop's configuration file starts local MCP servers only. mcp-remote bridges such an assistant to a remote server; it needs Node.js. Open Settings → Developer → Edit Config in Claude Desktop, add this to claude_desktop_config.json and restart Claude:

{
  "mcpServers": {
    "vimonto-deploy": {
      "command": "npx",
      "args": ["-y", "mcp-remote", "https://deploy.example.com/mcp", "--header", "Authorization:${AUTH_HEADER}"],
      "env": {
        "AUTH_HEADER": "Bearer YOUR_TOKEN"
      }
    }
  }
}

The token is in env rather than in args because some systems split arguments with spaces. The same configuration works in any assistant that can only start a command.

What can the assistant do?

The token's scopes decide which tools the assistant sees at all. A tool the token has no scope for is not listed and can't be called.

Scope Tools
Read Everything that reads: organizations, servers, sites, deployments, tasks, databases, backups and recipes.
Deploy list_organizations, list_sites (one site, by domain or ID), list_deployments, get_deployment, deploy_site and get_task.
Write Everything Read allows, plus deploy_site, create_database, run_backup and run_recipe.

Your role is checked on top of that, exactly as in the app and the API: deploying needs a role that may manage sites, creating a database one that may manage servers, and so on. A viewer's token can read, but every change is refused. With team access, servers outside your teams and their sites don't exist for the assistant.

The tools

Tool Scopes What it does
list_organizations any Who the token belongs to, its scopes, and your organizations with your role in each.
list_servers read, write The organization's servers you have access to.
get_server read, write One server: type, status, provider, IP addresses, PHP version, database.
list_sites read, deploy, write Sites on your servers, filtered by domain, site ID or server. With only Deploy, a domain or site ID is required.
get_site read, write One site, by ID or domain.
list_deployments read, deploy, write A site's deployments, newest first, 25 per page.
get_deployment read, deploy, write One deployment with its commit and task.
deploy_site deploy, write Deploys the site's branch, like Deploy now.
get_task read, deploy, write A task's status, step, progress, error and the last lines of its output.
list_databases read, write A server's databases.
create_database write Creates an empty database on a server.
list_backups read, write A server's backup configurations with their latest backups.
run_backup write Runs a backup configuration now.
list_recipes read, write The organization's recipes with their scripts.
run_recipe write Runs a recipe on one or more servers.

Every tool takes an organization (its slug); the assistant may leave it out when you belong to one organization only. Sites can be named by their domain, so you can simply ask: "Deploy shop.example.com and tell me when it's live."

Deploys, databases, backups and recipes run as background tasks. The tool answers at once with a task ID, and the assistant follows the task with get_task until it has succeeded or failed. When a deploy fails, it reads the error and the end of the output, which is usually enough to tell you why.

What isn't possible

There are no tools that delete anything: no removing databases, sites or servers. Creating servers and sites, changing environment files and managing domains are not available either; use the app for those.

Is it secure?

  • Tokens only. Being signed in to the app in your browser doesn't open the MCP server; every request needs a valid, unexpired API token. Revoking the token on API tokens disconnects the assistant straight away.
  • Never more than you. The assistant acts as you, limited to the token's scopes, your current role and your server access. When your role changes, the assistant's reach changes with it.
  • No secrets. Passwords, SSH keys, .env files, deploy URLs and tokens are never part of an answer. Task output and recipe scripts are shown as they are in the app, so don't print secrets in deploy scripts.
  • Everything is logged. Changes made by an assistant appear in the audit log under your name, with the token's name ("API token Claude Code").
  • Rate limited. Each token may make 120 requests a minute, shared with the API.
  • Your assistant asks first. Tools that change something are marked as such, so assistants ask for your approval before they deploy or run a recipe. Deploying and running recipes are marked as destructive, because they change what runs on your servers.

Frequently asked questions

Which assistants work?

Every assistant that supports remote MCP servers over Streamable HTTP with a custom header, such as Claude Code, Cursor and VS Code. Assistants that only start local servers, such as Claude Desktop through its configuration file, connect through mcp-remote.

Why does the assistant say a server or site doesn't exist?

It doesn't exist in that organization, or you have no access to it: your team access hides servers outside your teams. Also check that the assistant uses the right organization; list_organizations lists them.

Why doesn't the assistant see a tool?

The token doesn't have the scope for it. A Read token can't deploy, for example. Make a new token with the scope you need and replace the token in the assistant's configuration.

Can I use the same token for the API, the CLI and an assistant?

Yes, but separate tokens are safer: you can revoke one without breaking the others, and the audit log shows which one made a change.