Agents
AI agents (MCP)
DeployMate includes a Model Context Protocol server, so an agent such as Claude can look at your fleet, explain failures, deploy, and set up new apps. You decide what it may do by choosing a token; the server enforces it.
Set it up
- In the dashboard open API tokens (the key icon). Create a token, read-only to begin with. Copy it when it appears: it is shown once, and DeployMate keeps only a fingerprint.
- Get the
deploymatebinary on the machine where your agent runs (the macOS or Linux archive from the release). It talks to your server over HTTPS and needs no access to it beyond the token. - Register it. For Claude Code:
claude mcp add deploymate \ -e DEPLOYMATE_URL=https://your-dashboard \ -e DEPLOYMATE_TOKEN=dm_... \ -- /path/to/deploymate mcp
or, in a .mcp.json:
{
"mcpServers": {
"deploymate": {
"command": "/path/to/deploymate",
"args": ["mcp"],
"env": { "DEPLOYMATE_URL": "https://your-dashboard", "DEPLOYMATE_TOKEN": "dm_..." }
}
}
}
Start a new session and ask "how is everything?"
Three levels of trust
| Scope | The agent can |
|---|---|
read | See everything: the fleet, apps, deployments, build logs, container logs, history, services. Variables show names only. |
deploy | Also: deploy, redeploy, retry a failed deploy, roll back, start, stop, restart, run the CI workflow. |
provision | Also: create projects, apps and databases/caches, start services, set variables, connect a repository, add a domain, set an app's image and port. |
The agent only sees the tools its token allows, and the server refuses the rest even if one is called by hand.
The tools
| Read | fleet_status list_projects get_project get_app list_deployments get_deployment get_deployment_log get_app_logs get_app_activity get_service wait_for_deployment |
|---|---|
| Deploy | deploy_app redeploy_app run_workflow retry_deployment rollback_deployment restart_app start_app stop_app |
| Provision | create_project create_app create_service start_service set_variables connect_repository add_domain configure_app |
What it can never do
- Delete anything. There is no delete in the API at all — not apps, services, projects or data.
- Read a secret. Variables are write-only:
set_variablesstores a value (encrypted), and nothing ever returns it. Connection strings, the GitHub token and the webhook secret never leave the dashboard.connect_repositoryreturns only the public deploy key. - Manage tokens or touch backup credentials.
And everything it does is on the record: each change is listed on the API tokens page and in the affected app's history, with the name of the token that made it. Writes are rate-limited per token (20 a minute, 200 an hour), so a looping agent hits a wall, not your server.
Treat build logs as untrusted textAn agent that reads logs and commit messages reads text other people wrote. Keep write scopes for agents you supervise, and prefer a read-only token for anything that runs unattended. Revoke a token at any time on the API tokens page; it stops working immediately.
Good first prompts
- "How is everything?" —
fleet_status - "Why did the last deploy of invoicer fail?" —
get_app,get_deployment_log - With a deploy token: "Retry it and tell me when it's done." —
retry_deployment,wait_for_deployment - With a provision token: "Create a staging copy of the API with its own Postgres."