TL;DR - We made a way to use Cycle with AI models for doing things like deploying applications faster and diagnosing complex issues. If you'd like to get started right away with Cycle's Hosted MCP, check out our documentation.
Today, we're launching a brand new way to interface with the Cycle Platform, that just a year or two ago would have felt entirely like science fiction. Our first ever AI-oriented tooling, Cycle's Hosted MCP, is live today.
With it, we throw open the doors to a whole new way to do DevOps and infrastructure management. Using purely natural language and your favorite AI tooling, you can now manage complex application deployments, diagnose issues, parse container logs, and so much more on Cycle.
What is an MCP?
An MCP (model context protocol) is a protocol that standardizes how LLM applications connect to external tools, data, and services. It's essentially an adapter layer, that turns our existing API into something a model can discover and reason about, and most importantly, call in a safe and sandboxed way.
There are generally two ways that people build and use MCPs - local and remote. Local MCPs are run on an end user's machine and utilize API keys for auth. These local MCPs generally are only able to be run by AI tooling that also runs locally, and every single user has to install it and update it manually.
Remote MCPs are a bit more like a 'normal' API, where it is managed by someone else, generally uses OAuth for authentication, and users just need to add a URL to their tooling rather than install and manage an application.
For Cycle, a hosted MCP fits perfectly with how the rest of the platform works - automated updates, easy for our users to interface with, and secure.
Why we built an MCP for Cycle
"AI" and the ecosystem around it has taken the world by storm. At Cycle, we watch trends like these carefully, but cautiously. We go out of our way to avoid adding things that are trends, fads, or otherwise will bloat the platform for no real gain (Terraform being one example of something we explicitly avoided adding to the platform).
With how rapidly the ecosystem was changing, we decided to avoid adding any AI features into Cycle until we were certain that 1. It would be valuable to our customers in a meaningful way, and 2. That it wasn't just a fad that would go out of style, leaving us with bloat and legacy code that we may need to maintain even though it wasn't used by 99% of our customers.
To satisfy point 1, we didn't want to just throw in a bunch of magic AI functionality forced onto our users, an incredibly security and privacy focused group, just for the right to say Cycle was 'an AI' platform. And for 2, it meant carefully watching trends and recognizing when something was likely to stick around.
Recently, the MCP protocol launched the 2026-07-28 revision, adding some much needed authentication improvements and stateless calling. This signaled to us that MCP was here to stay and that real effort was being put into it. We started seeing MCP servers being discussed more and more, and that's when we decided it was time to build our own.
A remote hosted MCP server fits perfectly within the Cycle ecosystem:
- We can push automatic updates to it in alignment with API updates to the platform.
- Users don't need to install or manage anything.
- It doesn't live WITHIN the platform, with unrestrained access to private data and extremely sensitive systems. It's outside of the platform and acts as another interface, like the portal.
- It's opt-in for users that want it. For those using it with an API key, it inherits Cycle's granular role & capabilities built into the platform. For those authenticating with OAuth, it allows us to add additional levels of control and prevent any kind of Cycle auth token from reaching the LLM.
What can I do with Cycle's Hosted MCP?
Our main focus has been making it easier to do really complex things. We've built a lot of tools into the MCP that you can take advantage of, and more are on the way. Right now, with Cycle' Hosted MCP you can:
- Deploy multi-container applications and virtual machines in minutes, inside new environments.
- Start, stop, restart, and reconfigure containers and VMs, including scaling, resizing, and rolling back to a previous image.
- Diagnose issues across your hub, and search through aggregated container logs.
- Pull telemetry and metrics, with anomalies flagged for you.
- Manage DNS zones and records, and check if a domain has propagated yet.
- Provision new servers from your connected infrastructure providers, and track them as they come online.
- Manage scoped variables, image sources, clusters, and external volumes.
- Run commands inside running container instances and VMs.
Asking something like "Why is my API container unavailable" is enough for the model to pull logs, check telemetry, network connectivity, load balancer configuration, and a bunch more. It can correlate all of these things to diagnose even the most complex and difficult issues causing you problems.
It will also save a lot of time for people just getting started with Cycle. With a few tailored prompts, it can migrate large deployments off of kubernetes, EKS, or others and over to Cycle. The MCP teaches the model how Cycle works, and how to build proper configurations, and guides it as it deploys infrastructure, containers, and VMs.
How we approached security
Letting an LLM make changes to production infrastructure is no joke. The MCP needs to be built in a way that we can guarantee, unless you EXPLICITLY grant it the ability to make those changes, that it has no way to do so. We imagine a good chunk of people that use Cycle, and want to use the MCP, will never enable the ability to use mutating tools, and that's absolutely okay. So for our design, we set things up like this:
- When authenticating with OAuth, you choose what the MCP can do on your account: read, write, and/or exec. Anything outside of those permissions is hidden from the MCP entirely. If you only grant read, the model never even sees the tools that make changes, so there's nothing for it to call. It's also possible to set up a custom "AI" user in your hub, and manage ACLs that way so that it never even sees production resources.
- When using an API key, the MCP inherits Cycle's roles & capabilities, so it can only ever do what that key is allowed to do.
- Every tool that makes a change requires double verification.
That last one is where we spent a lot of our time. LLMs are scary good, but they are far from perfect. When the model calls a destructive tool, like deleting a container or an environment, nothing happens on the first call. Instead, the MCP returns exactly what would be affected: names, IDs, instance counts, which servers they're running on, and so on. The model has to present that to you, and only after you explicitly approve can it call the tool again to confirm. Even then, the confirmation has to use the exact ID from the preview, so the deletion is tied to what you actually approved.
Of course, even with all of these restrictions in place, it's always a risk. We're leaving that up to you to decide where your comfort level lies, and ensuring in as many ways possible that the choices you make are not only respected, but enforced by the MCP.
Some prompts to try
Here are some ideas to get you started with Cycle's Hosted MCP.
Read Only:
"Give me an overview of my hub. What environments do I have, what's running in each, and is anything unhealthy?"
"My api container keeps restarting in production. Check the logs and telemetry and tell me what's going on."
"Verify my domain is hitting my application and that everything is online."
"Is my production cluster healthy? How are server resources looking?"
Write:
"Scale my web container in staging to 3 instances."
"Deploy a 3 node mongo replica set into my development cluster, and make sure they all are talking to each other"
"Deploy 3 of the cheapest available servers with 8GB of RAM from any of my configured providers into different datacenters in Europe".
"Reimage my web server with the latest image from Dockerhub"
The sky is truly the limit here. We've also added a tool, called get_more_tools, so that if the model is unable to do what you're asking, it'll file a request to our team with what it's missing.
How to get started
We've put together a guide for a handful of the most popular tooling on our documentation. If you have any questions, requests, or just cool things you'd like to share about how you're using Cycle's Hosted MCP, feel free to post on our community site. We're excited to see how you all use this powerful new addition to the Cycle platform.

