# MCP Cloud — caas.sh

**Your MCP server works locally. Put it online.**

Deploy from a stdio command, a Git repo, or a container image. Clients get an authenticated endpoint with saved state and a full view of activity.

## Start with what you have

- **stdio** — local command
- **git** — repository
- **image** — container

Each becomes a hosted MCP endpoint: token required, state saved, activity logged.

## Deploy: three ways in, one endpoint out

A call goes from your MCP client (Claude, Cursor, your CI) over HTTPS with a client token to the gateway at mcp.caa.sh/<id>, which checks the token, applies tool grants and traces the call. It reaches your MCP server in its own sandbox VM — /workspace persists, with nightly snapshots — and anything the server sends out passes an egress allowlist that blocks everything else and adds keys on the way out.

Your code gets into the sandbox three ways:

1. **Stdio command.** Take the local MCP process you already run and expose its tools through a remote endpoint. `stdio: npx search-mcp` — uploaded from your committed tree.
2. **Git repo.** Deploy server code straight from a repository into its own sandbox. `repo: github.com/acme/server` — cloned on boot, dependencies installed.
3. **Container image.** Run an image you already build behind the MCP gateway. `image: registry.caas.sh/acme/server:1` — pulled from registry.caas.sh by digest.

## Your server, online. Checked at the door.

An MCP server is one YAML file: where the code comes from, the machine it gets, the hosts it may reach, and which clients may call which tools. caas.sh runs it in its own sandbox behind an authenticated endpoint.

```yaml
server: search-mcp
source:
  stdio: npx search-mcp
size: 1 vCPU · 1 GiB · 5 GB
state:
  persistent: true
  snapshots: nightly at 02:00
idle: stop after 30m

tokens:
  - name: laptop-claude
    tools: [search.query, search.fetch]
  - name: ci-pipeline
    tools: [search.query]
    expires: 30d

egress: [api.search.example.com]
```

Recent calls through the gateway at mcp.caa.sh/mcp_3n8w1c:

1. **search.query** — no token · **blocked at the gateway**
2. **search.query** — laptop-claude · 1.24 s · OK · trace 7f3a91…, arguments not stored
3. **search.fetch** — ci-pipeline · **tool not granted**
4. **search.query** — 0.96 s · OK · telemetry.example.net blocked by the outbound rules

Last 24 hours: 7,230 calls · 37 blocked · about $0.77 ([pricing](https://caas.sh/pricing.html#gateway)).

- **Access — no token, no tool call.** The gateway checks every request against a revocable client token and its tool grants before anything reaches your server.
- **State — it remembers between calls.** Files and app state persist across calls and restarts, with nightly snapshots you can roll back to.
- **Visibility — see every call, not the payload.** Traces record the tool, caller, timing and result, never the arguments, with a trace ID that reaches your server’s logs.

[Deploy this server](https://console.caas.sh/)

## Put your server online

Bring the command, repo, or image you already have. Get started in the [console](https://console.caas.sh/).

[Features](https://caas.sh/features.html) · [Pricing](https://caas.sh/pricing.html)
