Back to Browse

Antideploy MCP Server

Cloud & DevOpsModerate5.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Deploy an app to Antideploy from a coding agent. No Dockerfile, no YAML, no cloud console.

About

Deploy an app to Antideploy from a coding agent. No Dockerfile, no YAML, no cloud console.

Security Report

5.2
Moderate5.2Moderate Risk

This is a well-designed MCP server for deploying applications to Antideploy. Authentication is properly enforced via API key stored in environment variables. The code handles sensitive operations safely, includes proper input validation, and implements appropriate file filtering to prevent unwanted data upload. Permissions are narrowly scoped to the deployment use case with network access to the Antideploy platform. The only minor concerns are broad exception handling in the directory walk and lack of response body size limits in some API calls. Supply chain analysis found 6 known vulnerabilities in dependencies (1 critical, 3 high severity). Package verification found 1 issue.

7 files analyzed · 10 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

What You'll Need

Set these up before or after installing:

Antideploy API key for the application, created in the console under the application's settings. Starts with ad_.Required

Environment variable: ANTIDEPLOY_API_KEY

Base URL of the Antideploy instance. Defaults to https://antideploy.com. Only set for a self-hosted or staging instance.Optional

Environment variable: ANTIDEPLOY_URL

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "com-antideploy-antideploy-mcp": {
      "env": {
        "ANTIDEPLOY_URL": "your-antideploy-url-here",
        "ANTIDEPLOY_API_KEY": "your-antideploy-api-key-here"
      },
      "args": [
        "-y",
        "antideploy-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

antideploy-mcp

Deploy an application to Antideploy from inside a coding agent. Claude Code, Cursor, Windsurf, Codex, anything that speaks MCP.

You describe what you want built. The agent writes it, then deploys it, without either of you writing a Dockerfile, a YAML file, or touching a cloud console.

you  ─▶  agent writes the app  ─▶  deploy  ─▶  https://your-app.antideploy.com

Install

Nothing to install. The agent runs it with npx.

Claude Code

claude mcp add antideploy -e ANTIDEPLOY_API_KEY=ad_your_key -- npx -y antideploy-mcp

Cursor, Windsurf, and anything else with an mcp.json

{
  "mcpServers": {
    "antideploy": {
      "command": "npx",
      "args": ["-y", "antideploy-mcp"],
      "env": { "ANTIDEPLOY_API_KEY": "ad_your_key" }
    }
  }
}

Getting a key

Create an application at antideploy.com, then create an API key for it. The key identifies the application, so you never pass an application id: one key, one app. That is deliberate: this key ends up pasted into a project directory, which means it will eventually be committed or screenshotted, so it is scoped to a single application, can write secrets but never read them back, and can be revoked on its own.

Deploying somewhere new means a new app and a new key.

Tools

ToolWhat it does
deployPackages the project directory and deploys it. Returns a taskId.
deployment_statusProgress for one deploy: steps, the analyzed spec, warnings, hazards.
list_envEnvironment variable names. Values are never returned.
set_envStore or replace environment variables.
api_infoThe platform API's own description of itself.

Deploys are asynchronous. deploy hands back a taskId; poll deployment_status until it reports succeeded or failed.

Two things worth knowing

The whole directory is sent, not just the entry point. The single most common way to break a deploy on this platform is to upload one file: it builds fine, starts fine, and then serves a page whose every asset 404s.

A .env in the directory is uploaded on purpose. Its values go into Antideploy's encrypted secret store and the file itself is dropped from the build context, so you don't retype nine API keys you already have on disk. If that is not what you want, move the file before deploying.

Skipped automatically: node_modules, .git, build output (dist, build, .next, target, …), virtualenvs, editor and tool caches, and private keys (*.pem, *.key, id_rsa, …).

Limits

Files4,000
Per file5 MB
Total upload28 MB
Concurrent deploys1 per application

Checked locally before anything is uploaded, so hitting one costs you an error rather than a transfer.

Configuration

Variable
ANTIDEPLOY_API_KEYRequired. The key for the application to deploy.
ANTIDEPLOY_URLOptional. Defaults to https://antideploy.com.

What Antideploy does with what you send

Reads the source and works out the runtime, framework, build and start commands, the port, and every environment variable the code references, deterministically, citing the file each conclusion came from, not by asking a model to guess. Then provisions what the app needs, including a Postgres database with DATABASE_URL injected and migrations run before the app starts rather than after it has already crashed. Then builds a container with buildpacks, releases it behind HTTPS, and keeps it running: health checks, logs, and rollback to an already-built image in about forty seconds.

Full documentation: antideploy.com/docs

License

MIT

Reviews

No reviews yet

Be the first to review this server!