BlogStart here

How Antideploy works, from one sentence to a live link.

Your agent logs in, Antideploy reads the code, builds it, starts it, checks it and watches it. Here is each step.

How the Agent API works
  • Your agent asksIt reads one page and starts a login
  • Antideploy readsIt works out what your app is
  • It builds and startsThen checks the app answers
  • It keeps watchingHealth, logs and a security check

The short answer

When you paste the sentence, your agent reads a page that tells it what to do. It logs in with one approval from you, creates your app, sends your project, and follows the deploy. Antideploy reads the code, builds it, runs it behind HTTPS, checks that it answers, and then keeps watching it.

The steps

  1. Your agent reads the instructions

    The sentence points at agent.md, a procedure written for agents. It leads to a contract at /api/v1, which lists every endpoint, request shape, error code and limit in one unauthenticated request.

  2. You approve one link

    The agent starts a device login and shows you a link and a code. You approve, and the agent saves a token on your machine. From then on it makes every call itself.

  3. Antideploy reads your project

    It works out the language, framework, start command, port and what the app needs, and names the file each answer came from. It flags code that would deploy and then lose data, such as a SQLite file, uploads saved to disk or a scheduler inside the process. A project that matches a refused category stops here.

  4. It builds a container

    Antideploy builds your project with standard buildpacks, or with your own Dockerfile if there is one at the root. A static site is built if it needs building and served as files.

  5. It prepares the database

    If your code needs Postgres, one is created beside the app and DATABASE_URL is set. If you have a migration command, such as prisma migrate deploy, it runs before the new version goes live. A failed migration fails the deploy, so a broken schema never goes live.

  6. It starts the app and checks it

    The app starts with your start command and the port in PORT. It has to answer a health check before the deploy counts as live. If it never starts listening, the deploy fails and says so.

  7. It opens the app to the world

    The app gets its address, such as my-app.antideploy.app, with a certificate. Your agent tells you where it is live and on which account.

  8. It runs a security check

    Right after the deploy goes live, Antideploy looks at what the running app shows the public: keys in the browser code, downloadable files such as .env, and CORS and header problems. It never holds the deploy up.

  9. It keeps watching

    About every five minutes it checks that the app is running. You get an email when an app goes down and another when it is back. Your agent can read the logs, metrics and health at any time.

Where each step can stop

Every step either passes or stops with a plain reason.

  • Analysis. The project is not recognised, or it matches a refused category.
  • Build. A dependency cannot be installed, or the code does not compile.
  • Migration. The schema change fails, so the new version is not released.
  • Start. The app never listens on its port, or it crashes on boot.
  • Security check. It reports findings, but it never fails the deploy.

01Before you commit

Here's where it stops.

A platform that only tells you what it is good at is one you find the edges of in production. These are the ones to know before your first deploy.

  1. One deploy at a time

    A second deploy of the same app is refused until the first finishes. Different apps deploy side by side.

  2. Apps sleep when idle

    On every plan, an app nobody is using goes to sleep and the next visit wakes it. The first request took 2.9 to 13.9 seconds in our measurements, depending on the stack. There are no always-on workers, so use a cron job or a webhook for background work.

02Questions

How-it-works questions, answered.

Anything else? Write to us and a person answers.

support@antideploy.com
What does my agent actually call?

The Antideploy API at antideploy.com/api/v1. It creates the app, sends the project, reads deploy status, logs, metrics and health, sets variables and creates services.

Is the build the same every time?

The analysis is deterministic: the same code gets the same answer. Builds can differ if a dependency range resolves to a newer version, which is why a committed lock file matters.

Can two deploys run at once?

Not for the same app. A second deploy is refused until the first finishes. Different apps deploy side by side.

What happens to the old version?

The new version replaces the old one on the app's single machine. Releases are not zero-downtime, so if the new version does not start, the app is down until a working version is deployed.

Deploy something. Start with one sentence.

Paste one sentence into your coding agent, click Approve once, and get a live link. No card, no trial clock.

Start from GitHub or a folder
Prompt copied Paste it into Claude Code, Codex or Cursor and press Enter.