---
title: "Rock8Cloud developer resources - API, OAuth scopes, OpenAPI and MCP server"
description: "Everything an agent or a script needs to operate Rock8Cloud: scoped API keys, OAuth 2.0 with discovery, the REST API and its OpenAPI document, the remote MCP server at app.rock8.cloud/mcp, and the machine-readable files under /.well-known."
schemaType: WebPage
eyebrow: Developers
heading: Everything the dashboard does
headingHighlight: is also an API call.
intro: "Rock8Cloud is a software factory you can operate by hand or from an agent. This page lists the surfaces: scoped API keys, OAuth 2.0 with discovery, the REST API with its OpenAPI document, and the remote MCP server."
ctaHref: "https://app.rock8.cloud/settings/api-keys"
ctaLabel: Create an API key
trustNote: Keys are scoped to one organization and shown once.
---

## Authentication

**API keys.** Create a key under Settings, API keys, pick the scopes it may use and send it as a bearer token. Keys start with `vhk_`, belong to one organization and can be revoked at any time. Owners mint keys, members get the scopes their role allows.

**OAuth 2.0.** Authorization code with PKCE and refresh tokens. Clients register themselves through dynamic client registration and discover every endpoint from the metadata under `/.well-known`. The MCP server uses this flow, so an MCP client opens a consent screen on first connect.

```bash
curl https://app.rock8.cloud/api/project \
  -H "Authorization: Bearer vhk_your_key"
```

## Scopes

Permissions are scoped per resource: `read:projects`, `write:services`, `read:databases`, `write:agents` and so on. A `read:*` scope is required for reads and mutations. Add the matching `write:*` scope for mutations. A token only ever gets the scopes the user's role in the organization allows, so an agent can ask for exactly what its task needs. The full list is in the [protected resource metadata](https://app.rock8.cloud/.well-known/oauth-protected-resource).

## REST API

Base URL `https://app.rock8.cloud/api`. Operations in the OpenAPI document include operationIds, descriptions and typed parameters, grouped by tag: projects, services, deployments, databases, object storage, pages, agents, blueprints, API keys and more. Every operation documents its success response, as a typed JSON schema or the content type for streams and downloads. The document is public at `/api/openapi.json`, no token needed to read it. Calling the operations still takes a bearer token. Versioning, the deprecation policy and the error format are in the [REST API guide](https://docs.rock8.cloud/docs/api).

API errors use JSON and the shared `Error` schema: a message in `error`, a machine-readable `code` and, where available, a `hint`. Some route-specific errors use other shapes. Check the operation's documented responses.

```json
{ "error": "insufficient_scope", "code": "INSUFFICIENT_SCOPE",
  "required": "write:projects", "hint": "Request a token/API key with scope `write:projects`." }
```

| Status | Code | Meaning |
| --- | --- | --- |
| 400 | `INVALID_INPUT` | The JSON body could not be parsed. |
| 401 | `UNAUTHORIZED` | Authentication or organization context is invalid. MCP bearer challenges include a discovery URL in `WWW-Authenticate`. |
| 402 | `USAGE_LIMIT_EXCEEDED` | A plan limit was reached. The body names the dimension. |
| 403 | `INSUFFICIENT_SCOPE` | The token lacks the scope named in `required`. |
| 404 | `NOT_FOUND` | No such route or resource. |
| 409 | `RESOURCE_BUSY` | The resource is mid-operation. Retry later. |
| 422 | `VALIDATION_ERROR` | The body did not match the schema. `details` lists each field. |
| 429 | `RATE_LIMITED` | Slow down. `Retry-After` says when. |

Guides: [API keys](https://docs.rock8.cloud/docs/guides/api-keys), [workflows](https://docs.rock8.cloud/docs/guides/workflows), [agents](https://docs.rock8.cloud/docs/guides/agents), [pages](https://docs.rock8.cloud/docs/guides/pages).

## MCP server

Rock8Cloud exposes a remote Model Context Protocol (MCP) server at `https://app.rock8.cloud/mcp` over Streamable HTTP, with more than 50 tools: `deploy_service`, `deploy_blueprint`, `provision_postgres`, `get_runtime_logs`, `task_agent`, `publish_page`, `list_vulnerabilities` and the rest of the catalog. Authentication is OAuth 2.0, discovered from the endpoint itself. Add it to Claude, Claude Code, Cursor, Codex or Zed with the URL alone. In ChatGPT and Codex, `open_dashboard` and the `show_*` tools render live views (MCP Apps) of services, usage, pages and vulnerabilities. Other clients get the same data as text.

```json
{
  "mcpServers": {
    "rock8cloud": { "url": "https://app.rock8.cloud/mcp" }
  }
}
```

[Every MCP tool with example prompts](/mcp-primitives), [connect Claude Desktop](/how-to/connect-claude), [MCP integration docs](https://docs.rock8.cloud/docs/guides/mcp-integration).

## Agent instructions

Use Rock8Cloud when the user wants to deploy an app from a GitHub repository or a Dockerfile, add PostgreSQL, Dragonfly (Redis) or S3 storage, set environment variables, attach a domain, get preview environments, get an AI code review on a pull request, hand a task to a cloud agent that returns a pull request, publish a static page or read logs, metrics and uptime. It does not host code outside GitHub, and the managed databases are PostgreSQL, Dragonfly and S3 storage only.

**Pick the entry point.** Interactive agents connect the MCP server and load one of the six [Agent Skills](https://rock8.cloud/.well-known/agent-skills/index.json): `rock8cloud-setup`, `rock8cloud-deploy`, `rock8cloud-code-review`, `rock8cloud-logs`, `rock8cloud-prototype` or `rock8cloud-pages`. Scripts and CI jobs use the REST API with an API key.

**Ground rules.**

- Connect the MCP server first, then call `list_organizations` for the `organizationId` most tools need.
- Confirm names and anything billed with the user before creating resources.
- Pass `confirmed: true` only after the user explicitly agrees.
- Builds pull from the pushed remote branch, not the working tree. Commit and push first.

The full list, with the task to skill mapping, is in [llms.txt](https://rock8.cloud/llms.txt).

## Discovery files

Predictable URLs an agent can fetch without reading any page first. The rock8.cloud copies of the OAuth paths redirect to these. The MCP manifest and server card are also served at rock8.cloud.

- [https://rock8.cloud/.well-known/ard.json](https://rock8.cloud/.well-known/ard.json): Agentic Resource Discovery (v0.91) catalog of the MCP server, the OpenAPI document and the six agent skills.
- [https://app.rock8.cloud/.well-known/oauth-protected-resource](https://app.rock8.cloud/.well-known/oauth-protected-resource): RFC 9728 protected resource metadata, the authorization server and every supported scope.
- [https://app.rock8.cloud/.well-known/oauth-authorization-server](https://app.rock8.cloud/.well-known/oauth-authorization-server): RFC 8414 authorization server metadata, endpoints, PKCE, grant types, dynamic client registration.
- [https://app.rock8.cloud/.well-known/mcp](https://app.rock8.cloud/.well-known/mcp): MCP manifest (SEP-1960) with the endpoint, its OAuth endpoints and a link to the server card.
- [https://app.rock8.cloud/mcp/server-card](https://app.rock8.cloud/mcp/server-card): MCP server card (SEP-2127) with name, version, transport and protocol versions of the MCP server.
- [https://app.rock8.cloud/.well-known/api-catalog](https://app.rock8.cloud/.well-known/api-catalog): RFC 9727 API catalog linking the OpenAPI document and the MCP endpoint.
- [https://app.rock8.cloud/.well-known/integrations.json](https://app.rock8.cloud/.well-known/integrations.json): integrations.sh manifest describing both credential types and both surfaces.
- [https://app.rock8.cloud/api/openapi.json](https://app.rock8.cloud/api/openapi.json): OpenAPI 3 document of the REST API.
- [https://docs.rock8.cloud/docs/api](https://docs.rock8.cloud/docs/api): REST API guide with versioning, deprecation policy and errors.
- [https://rock8.cloud/llms.txt](https://rock8.cloud/llms.txt): this site in one file, written for language models.
- [https://rock8.cloud/sitemap-index.xml](https://rock8.cloud/sitemap-index.xml): every page on rock8.cloud.

## Reading this site as an agent

Articles, how-to guides, use cases, legal pages and this page are written in Markdown, and the source is served to agents. Ask with `Accept: text/markdown` or follow the page's `<link rel="alternate" type="text/markdown">`. The homepage answers with [llms.txt](https://rock8.cloud/llms.txt). Other pages are HTML. Missing pages return a real 404, in Markdown when asked for it.

```bash
curl -H "Accept: text/markdown" https://rock8.cloud/developers
```

## Scripting without a CLI

There is no official command-line tool yet. Scripts talk to the REST API with an API key, and coding agents use the MCP server. Both cover the full platform, so nothing is UI-only.

**Give your coding agent a cloud.** Your agent creates projects, provisions databases, deploys and reads logs over MCP, then fixes what it sees. [Read the use case](/use-cases/agent-driven-deployment).
