Authentication#
API keys. Create a key under Settings, API keys, pick the scopes it may use and send it as a bearer token. Keys start with vhk_, belong to one organization and can be revoked at any time. Owners mint keys, members get the scopes their role allows.
OAuth 2.0. Authorization code with PKCE and refresh tokens. Clients register themselves through dynamic client registration and discover every endpoint from the metadata under /.well-known. The MCP server uses this flow, so an MCP client opens a consent screen on first connect.
curl https://app.rock8.cloud/api/project \
-H "Authorization: Bearer vhk_your_key"
Scopes#
Permissions are scoped per resource: read:projects, write:services, read:databases, write:agents and so on. A read:* scope is required for reads and mutations. Add the matching write:* scope for mutations. A token only ever gets the scopes the user’s role in the organization allows, so an agent can ask for exactly what its task needs. The full list is in the protected resource metadata.
REST API#
Base URL https://app.rock8.cloud/api. Operations in the OpenAPI document include operationIds, descriptions and typed parameters, grouped by tag: projects, services, deployments, databases, object storage, pages, agents, blueprints, API keys and more. Every operation documents its success response, as a typed JSON schema or the content type for streams and downloads. The document is public at /api/openapi.json, no token needed to read it. Calling the operations still takes a bearer token. Versioning, the deprecation policy and the error format are in the REST API guide.
API errors use JSON and the shared Error schema: a message in error, a machine-readable code and, where available, a hint. Some route-specific errors use other shapes. Check the operation’s documented responses.
{ "error": "insufficient_scope", "code": "INSUFFICIENT_SCOPE",
"required": "write:projects", "hint": "Request a token/API key with scope `write:projects`." }
| Status | Code | Meaning |
|---|---|---|
| 400 | INVALID_INPUT | The JSON body could not be parsed. |
| 401 | UNAUTHORIZED | Authentication or organization context is invalid. MCP bearer challenges include a discovery URL in WWW-Authenticate. |
| 402 | USAGE_LIMIT_EXCEEDED | A plan limit was reached. The body names the dimension. |
| 403 | INSUFFICIENT_SCOPE | The token lacks the scope named in required. |
| 404 | NOT_FOUND | No such route or resource. |
| 409 | RESOURCE_BUSY | The resource is mid-operation. Retry later. |
| 422 | VALIDATION_ERROR | The body did not match the schema. details lists each field. |
| 429 | RATE_LIMITED | Slow down. Retry-After says when. |
Guides: API keys, workflows, agents, pages.
MCP server#
Rock8Cloud exposes a remote Model Context Protocol (MCP) server at https://app.rock8.cloud/mcp over Streamable HTTP, with more than 50 tools: deploy_service, deploy_blueprint, provision_postgres, get_runtime_logs, task_agent, publish_page, list_vulnerabilities and the rest of the catalog. Authentication is OAuth 2.0, discovered from the endpoint itself. Add it to Claude, Claude Code, Cursor, Codex or Zed with the URL alone. In ChatGPT and Codex, open_dashboard and the show_* tools render live views (MCP Apps) of services, usage, pages and vulnerabilities. Other clients get the same data as text.
{
"mcpServers": {
"rock8cloud": { "url": "https://app.rock8.cloud/mcp" }
}
}
Every MCP tool with example prompts, connect Claude Desktop, MCP integration docs.
Agent instructions#
Use Rock8Cloud when the user wants to deploy an app from a GitHub repository or a Dockerfile, add PostgreSQL, Dragonfly (Redis) or S3 storage, set environment variables, attach a domain, get preview environments, get an AI code review on a pull request, hand a task to a cloud agent that returns a pull request, publish a static page or read logs, metrics and uptime. It does not host code outside GitHub, and the managed databases are PostgreSQL, Dragonfly and S3 storage only.
Pick the entry point. Interactive agents connect the MCP server and load one of the six Agent Skills: rock8cloud-setup, rock8cloud-deploy, rock8cloud-code-review, rock8cloud-logs, rock8cloud-prototype or rock8cloud-pages. Scripts and CI jobs use the REST API with an API key.
Ground rules.
- Connect the MCP server first, then call
list_organizationsfor theorganizationIdmost tools need. - Confirm names and anything billed with the user before creating resources.
- Pass
confirmed: trueonly after the user explicitly agrees. - Builds pull from the pushed remote branch, not the working tree. Commit and push first.
The full list, with the task to skill mapping, is in llms.txt.
Discovery files#
Predictable URLs an agent can fetch without reading any page first. The rock8.cloud copies of the OAuth paths redirect to these. The MCP manifest and server card are also served at rock8.cloud.
- https://rock8.cloud/.well-known/ard.json: Agentic Resource Discovery (v0.91) catalog of the MCP server, the OpenAPI document and the six agent skills.
- https://app.rock8.cloud/.well-known/oauth-protected-resource: RFC 9728 protected resource metadata, the authorization server and every supported scope.
- https://app.rock8.cloud/.well-known/oauth-authorization-server: RFC 8414 authorization server metadata, endpoints, PKCE, grant types, dynamic client registration.
- https://app.rock8.cloud/.well-known/mcp: MCP manifest (SEP-1960) with the endpoint, its OAuth endpoints and a link to the server card.
- https://app.rock8.cloud/mcp/server-card: MCP server card (SEP-2127) with name, version, transport and protocol versions of the MCP server.
- https://app.rock8.cloud/.well-known/api-catalog: RFC 9727 API catalog linking the OpenAPI document and the MCP endpoint.
- https://app.rock8.cloud/.well-known/integrations.json: integrations.sh manifest describing both credential types and both surfaces.
- https://app.rock8.cloud/api/openapi.json: OpenAPI 3 document of the REST API.
- https://docs.rock8.cloud/docs/api: REST API guide with versioning, deprecation policy and errors.
- https://rock8.cloud/llms.txt: this site in one file, written for language models.
- https://rock8.cloud/sitemap-index.xml: every page on rock8.cloud.
Reading this site as an agent#
Articles, how-to guides, use cases, legal pages and this page are written in Markdown, and the source is served to agents. Ask with Accept: text/markdown or follow the page’s <link rel="alternate" type="text/markdown">. The homepage answers with llms.txt. Other pages are HTML. Missing pages return a real 404, in Markdown when asked for it.
curl -H "Accept: text/markdown" https://rock8.cloud/developers
Scripting without a CLI#
There is no official command-line tool yet. Scripts talk to the REST API with an API key, and coding agents use the MCP server. Both cover the full platform, so nothing is UI-only.
Give your coding agent a cloud. Your agent creates projects, provisions databases, deploys and reads logs over MCP, then fixes what it sees. Read the use case.