MCP CLOUD

Your MCP server works locally. Put it online.

Deploy from a stdio command, a Git repo, or a container image. Clients get an authenticated endpoint with saved state and a full view of activity.

START WITH WHAT YOU HAVE
stdio
Local command
git
Repository
image
Container
Hosted MCP endpoint
token requiredstate savedactivity logged
DEPLOY

Three ways in. One endpoint out.

MCP CLIENTSClaude, Cursor, your CI
  • HTTPS with a client token
GATEWAYmcp.caa.sh/<id>
  • checks the token
  • applies tool grants
  • traces every call
SANDBOX · ITS OWN VMYour MCP serverstdio bridge → npx search-mcp
  • /workspace persists
  • nightly snapshots
EGRESSAllowlist
  • everything else blocked
  • keys added on the way out
ALLOWED HOSTS
  • api.search.example.com
  • everything else

YOUR CODE GETS INTO THE SANDBOX THREE WAYS

MCP CLOUD

Your server, online.
Checked at the door.

An MCP server is one YAML file: where the code comes from, the machine it gets, the hosts it may reach, and which clients may call which tools. caas.sh runs it in its own sandbox behind an authenticated endpoint.

YAMLsearch-mcp.yaml
1 SERVER · 2 CLIENTSCALL 02 OF 04
server: search-mcp
source:
stdio: npx search-mcp
size: 1 vCPU · 1 GiB · 5 GB
state:
persistent: true
snapshots: nightly at 02:00
idle: stop after 30m
01tokens:AUTHno token, no tool call
02 - name: laptop-claude
tools: [search.query, search.fetch]ACCESSthis client, these tools
03 - name: ci-pipeline
tools: [search.query]GRANTSsearch.fetch not granted
expires: 30d
04egress: [api.search.example.com]OUTBOUNDeverything else blocked

AUTHline 10 · no token, no tool call

ACCESSline 12 · this client, these tools

GRANTSline 14 · search.fetch not granted

OUTBOUNDline 17 · everything else blocked

GATEWAY · SEARCH-MCPHealthy
mcp.caa.sh/mcp_3n8w1cSelect a callTap a call
  1. trace 7f3a91…arguments not stored
CALLS · 24H
7,230
BLOCKED
37
COST · 24H
≈ $0.77

ACCESS

No token, no tool call.

The gateway checks every request against a revocable client token and its tool grants before anything reaches your server.

STATE

It remembers between calls.

Files and app state persist across calls and restarts, with nightly snapshots you can roll back to.

VISIBILITY

See every call, not the payload.

Traces record the tool, caller, timing and result, never the arguments, with a trace ID that reaches your server’s logs.

Put your server online.

Bring the command, repo, or image you already have.