Key idea
Claude Code can already run commands and call tools. What it needs from you is access that stops at one project, rules for deploying well, and your yes before anything live changes. The MCP server lets it read your services and logs; csph with a project-scoped token lets it make changes you approve.
This guide assumes the app already runs on ComputeSphere. If it doesn't, start with Deploy a vibe-coded app: you create the service in the console, which is where you choose which repository ComputeSphere may read.
1. Add the MCP server
In your project's folder, run:
claude mcp add --transport http computesphere https://mcp.computesphere.com/mcp
Then, in a Claude Code session, run /mcp and choose computesphere. Your browser opens to sign in to ComputeSphere. Opening the URL any other way returns 401: it only answers signed-in agents.
To share the setup with your team, add --scope project: Claude Code writes it to .mcp.json in the project root, and asks each person to approve the server before using it.
2. Give it the deploy rules
ComputeSphere's agent kit writes down how to deploy well: listen on 0.0.0.0 and PORT, keep secrets out of code, use a real health check, roll back before hot-fixing, and ask before changing anything live. Copy it into the root of your repository:
curl -fsSL -o AGENTS.md https://raw.githubusercontent.com/computesphere-samples/learn/main/agent-kit/AGENTS.md
Claude Code reads AGENTS.md when the project has no CLAUDE.md. If yours has one, add a line containing @AGENTS.md to it, which imports the file. Then add your own specifics under it: the service name, its port and health path, and how to run the tests.
Prefer a skill?
The kit has the same guidance as a skill, loaded only when a deploy comes up:
mkdir -p .claude/skills/deploy-to-computesphere
curl -fsSL -o .claude/skills/deploy-to-computesphere/SKILL.md \
https://raw.githubusercontent.com/computesphere-samples/learn/main/agent-kit/SKILL.md
3. Hand it a project-scoped token
Create the token
In the console, go to Settings, then User tokens, and choose New token. Name it for the job, such as
agent_deploy. Choose Project access and pick the one project. Set the expiry to 7 days or less, then Create token. Or with csph:csph auth token create --name agent_deploy --scope project \ --restrictions <project-id> --expiry "2026-10-08 23:59:59"You should seeA token starting csph_, shown once.
Put it in the terminal, not the chat
Start Claude Code from a terminal where the token is set, without it showing:
read -rs COMPUTESPHERE_API_TOKEN && export COMPUTESPHERE_API_TOKEN claudecsph prefers
COMPUTESPHERE_API_TOKENto your own sign-in, so every csph command Claude Code runs is limited to that project. Never paste a token into the chat: whatever's in the chat is sent to the model provider and saved in the transcript.You should seeNothing on screen; the variable is set.
Check what it can reach
Ask Claude Code to run
csph services list --project <project-id>. It lists that project's services. Any other project returns403,API token is not authorized for this resource.You should seeYour project's services, and a 403 for any other project.
4. Approve each change
Claude Code asks before it runs a shell command, unless you've allowed that command. For deploys, keep it that way, and read each one before you say yes:
- The command. Status, logs and history are routine.
redeploy,restart,rollback,scale,stop,delete,secrets setand--replacechange your live app. - The ID. Does the deployment belong to the service you mean?
csph deployments list --service <service-id>shows it. - Where. The right project and environment.
When an MCP tool that changes something asks for confirmation, Claude Code shows it to you. Approve the exact action, or say no. The agent kit tells Claude Code never to confirm on your behalf.
Make the rule stick
Claude Code's permission rules can force a prompt even if someone allowed a command earlier. In .claude/settings.json:
{
"permissions": {
"ask": [
"Bash(csph deployments redeploy *)",
"Bash(csph deployments restart *)",
"Bash(csph deployments rollback *)",
"Bash(csph apply *)",
"mcp__computesphere__applyManifest",
"mcp__computesphere__restartDeployment",
"mcp__computesphere__rollbackDeployment"
]
}
}
5. A session that works
Ask for one thing at a time, and ask it to report what it saw:
The notes service in production is slow. Read its runtime logs from the last 30 minutes and its deploy history, and tell me what changed. Don't change anything.
It can use the MCP server's read tools here: listServices, listDeployments, getDeploymentStatus, getDeploymentRuntimeLogs, getDeploymentDeployLogs, getDeploymentBuildLogs and listDeploymentVersions. Then, if a release is at fault:
Propose the rollback command for the last good version. Show me the deployment ID and project first.
You approve csph deployments rollback <deployment-id>, and it confirms the service is Running and answering.
New code still ships through Git: the agent works on a branch, you review the diff and merge, and you start the build from the console with Redeploy, then Build & deploy. csph deployments redeploy applies saved settings; it doesn't pick up new commits.
6. Revoke the token
When the work is done, in Settings, User tokens, hover over the token and choose the delete icon, or run csph auth token delete <token-id>. Revoke straight away if it was ever pasted somewhere it shouldn't be. To cut off the MCP server, run claude mcp remove computesphere.
What can go wrong
| What you see | Usual cause | Fix |
|---|---|---|
/mcp shows the server as needing authentication | You haven't signed in yet, or the sign-in expired | Run /mcp, choose computesphere and sign in again |
403 ... not authorized for this resource | The token is for another project, or it expired | Check the project ID; create a new token |
| csph acts on your whole account | COMPUTESPHERE_API_TOKEN isn't set in the terminal Claude Code runs in, so csph uses your own sign-in | Set it, and run csph context to check |
| The agent says it deployed, and nothing changed | Redeploy doesn't pick up new commits | Merge, then Redeploy, Build & deploy in the console |
| A token appears in the chat | It was pasted, or printed by a command | Revoke it now and create a new one |
| The agent proposes deleting something to "fix" it | It's optimising for the error going away | Say no; roll back first, then read the logs |