# Built for coding agents, approved with one click.

URL: https://antideploy.com/platform/agent-api

Your agent reads one page, asks you to approve one link, and from then on makes every call itself: deploy, set variables, read logs, create a database. The whole contract is one unauthenticated request, written for software to read.

## At a glance

- **One sentence**: Paste it into Claude Code, Codex, Cursor, Antigravity or Windsurf
- **One approval**: You open a link and click Approve. That is your whole part
- **Scoped credentials**: Account tokens, and project keys for one app that are safe for CI
- **Written for machines**: agent.md, llms.txt and a machine-readable contract at /api/v1

## One link to approve. Then it runs itself.

The only thing a person does in the whole flow is open a link and click Approve. Every other call is your agent's.

### Connect with a device login.

Your agent starts a device login, shows you a link and a code, and polls until you approve. If you are signed out, or have no account yet, the same link takes you through Google or GitHub and back to Approve, so there is no sign-up first. The token goes into a file, never into the chat.

- A code lasts fifteen minutes, and a refusal is final
- The token is written to `~/.antideploy/config.json` and is never printed
- The response names the account you approved, so you know which one it is

[Read agent.md](https://antideploy.com/agent.md)

**What your agent shows you**

```bash
curl -X POST "$API/device/code" -d '{"clientName":"Claude Code"}'

Open  https://antideploy.com/activate?code=WDJB-MJHT
Confirm the code reads WDJB-MJHT, then click Approve.

curl -X POST "$API/device/token" -d '{"deviceCode":"..."}'
Approved. Token saved to ~/.antideploy
```

### Or add the MCP server once.

For any client that speaks MCP, add the server once and your agent can deploy, read the result and fix what broke without you relaying it. Everything beyond its tools is plain HTTP, which every agent can already do.

- Nothing to install, it runs with npx
- Works with any MCP client
- The same API covers the rest of the platform

[Read the agent guide](https://antideploy.com/docs/deploying/mcp)

**Claude Code**

```bash
claude mcp add antideploy \
    -e ANTIDEPLOY_API_KEY=ad_your_key \
    -- npx -y antideploy-mcp
```

Related: `deploy`, `deployment_status`, `set_env`, `list_env`, `api_info`

## Software talking to software.

Everything a coding agent needs is written to be read by one: instructions in plain text, a contract in JSON, and errors that say what to do next.

- **A sentence, not a setup.** The pasted sentence names one page, `agent.md`, which is a procedure: connect, set up what the project needs, deploy, and tell you where it is live and on which account.
- **One approval, scoped and revocable.** Your agent gets a token for your account only after you approve it. You can see and revoke it at any time at `antideploy.com/tokens`.
- **Account tokens and project keys.** An account token (prefix `adu_`) is for your agent and never goes in the project. A project key (prefix `ad_`) is for one application, is built to survive being committed, and is what you use in CI. Each application can have up to ten.
- **A contract made for software.** `GET /api/v1` is unauthenticated and always answers. It carries every endpoint, request shape, error code and limit, and its start section is the whole path from an empty terminal to a live URL.
- **Warnings are data.** Warnings and hazards in a response are structured fields meant to be relayed to you, not decoration. An error says what is wrong, whether to retry and what to do instead.
- **It tells you if it is blocked.** If an agent's sandbox blocks outbound requests to `antideploy.com`, agent.md gives it the exact sentence to tell you, so you can allow the domain and carry on.

## What an agent can do.

All of it through the API, with an account token. A project key can do the same for its own application.

| Area | Calls |
| --- | --- |
| Applications and deploys | Create and list applications, deploy, redeploy, roll back, read deploy history and watch a deploy, change the address, deploy on push and the root directory. |
| Variables | Set variables, list their names and remove one. Values are never readable. |
| Services | Create and inspect a [database](https://antideploy.com/platform/database), [bucket](https://antideploy.com/platform/file-storage), [sign-in](https://antideploy.com/platform/authentication) and [email](https://antideploy.com/platform/email), and create [AI keys](https://antideploy.com/platform/ai-models). |
| Operating | Read [logs, metrics and health](https://antideploy.com/platform/logs-and-monitoring), manage [cron jobs](https://antideploy.com/platform/cron-jobs), and run [security scans](https://antideploy.com/platform/security-checks). |
| Credentials | Mint and revoke project keys for CI, with an account token. |

## What an agent cannot do.

Kept in your browser on purpose, because they are irreversible, or because they spend your money or widen access.

| Action | Who does it |
| --- | --- |
| Delete an application | You, in the console. |
| Drop a database | You, in the console. |
| Read a secret back | Nobody. Values are write-only. The one exception is a service's own variables, written straight to a file. |
| Mint another account token | You approve each one, once, in a browser. |
| Add money to the AI wallet | You, in Settings, then Billing. |
| Attach a custom domain | You, on the application's Domains tab. |

## Here's where it stops.

A platform that only tells you what it is good at is one you find the edges of in production. These are the Agent API's.

### An agent that cannot reach us

If a sandbox blocks outbound requests to antideploy.com, nothing else works. agent.md tells the agent what to say, and you allow the domain or run the agent on your own machine.

### Deleting stays human

An agent can create a database but cannot drop one, and cannot delete an application. Those are done in the console, on purpose.

### Limits are answers, not retries

Deploys are limited per hour per app, and a plan limit answers with a 402 that is not a rate limit. A good agent says what the message says and lets you choose.

### MCP covers the essentials

The MCP server covers deploying, status and variables. Everything else is plain HTTP, which every agent can already do.

## Agent questions, answered.

Anything else? Write to us and a person answers.

[support@antideploy.com](mailto:support@antideploy.com)

### Which coding agents does it work with?

Claude Code, Codex, Cursor, Antigravity and Windsurf, and any agent that can read a web page and make requests. There is also an MCP server, `npx -y antideploy-mcp`, for any client that speaks MCP.

### Do I need to sign up before I start?

No. Paste the sentence into your agent first. When it needs you, it shows a link: sign in with GitHub, Google or an email link, check the code matches, and click Approve. That is the only thing you do by hand.

### What can my agent do with my account?

Deploy, set variables, read status, logs and metrics, create a database, bucket, sign-in and email, create AI keys, schedule jobs and run security scans. It cannot delete an app, drop a database, read a secret back, attach a domain or add money to your wallet.

### How do I revoke my agent's access?

From the Tokens page at `antideploy.com/tokens`. A revoked token stops working immediately.

### Where is the token kept?

In `~/.antideploy/config.json` on your machine, readable only by you, and never in the project directory. Your agent is told never to print it.

### What is a project key?

A credential for one application that is built to survive being committed, so it suits CI. It can deploy and read that application and cannot mint other keys. You can have up to ten per application.

### Where is the API described?

At `antideploy.com/api/v1`, one unauthenticated request that returns every endpoint, request shape, error code and limit as JSON.

### What is llms.txt?

A short plain-text entry point at `antideploy.com/llms.txt` for an agent that has been told to ship something and knows nothing else. It points at the contract and the procedure.

### What if my agent's sandbox blocks the network?

Then it cannot reach us, and it should say so. agent.md gives it the exact sentence: allow `antideploy.com` in the environment's network settings, run the agent on your own machine, or upload the folder in the console.

## Everything else your app can use.

Every service is created by your coding agent, wired into your app, and included in the plans. [See the whole platform](https://antideploy.com/platform).

- [Hosting](https://antideploy.com/platform/hosting)
- [Static sites](https://antideploy.com/platform/static-sites)
- [Deployments](https://antideploy.com/platform/deployments)
- [Database](https://antideploy.com/platform/database)
- [Authentication](https://antideploy.com/platform/authentication)
- [File storage](https://antideploy.com/platform/file-storage)
- [Email](https://antideploy.com/platform/email)
- [AI models](https://antideploy.com/platform/ai-models)
- [Cron jobs](https://antideploy.com/platform/cron-jobs)
- [Custom domains](https://antideploy.com/platform/custom-domains)
- [Environment variables](https://antideploy.com/platform/environment-variables)
- [Logs and monitoring](https://antideploy.com/platform/logs-and-monitoring)
- [Security checks](https://antideploy.com/platform/security-checks)
- [Console](https://antideploy.com/platform/console)

Facts on this page were checked against the live platform on 5 October 2026.

## Tell your agent once. It does the rest.

Copy the sentence, paste it into your agent, click Approve. Nothing is added to your project, and you can tear it all down in one click.

To set this up, give your coding agent this sentence:

```text
Set this project up to deploy on Antideploy. Fetch https://antideploy.com/agent.md and follow it.
```
