The @devicecloud.dev/dcd package ships a second binary, dcd-mcp — a Model Context Protocol server that lets AI agents (Claude, Cursor, VS Code, and other MCP clients) drive DeviceCloud directly: list devices, submit cloud test runs, check status, and download artifacts.
{% hint style="warning" %} The MCP server is a new, beta capability. The tool surface may change. {% endhint %}
{% hint style="warning" %} Please note that we accept no liability for anything your agent(s) may read or execute when using our MCP server. LLMs are a new technology and should be used with caution at your own risk. {% endhint %}
Add the server to your MCP client's configuration. It runs over stdio via npx, so there's nothing to install separately:
Auth is inherited from the CLI:
- Set
DEVICE_CLOUD_API_KEYin the server'senv(as above), or - Run
dcd loginonce and the server will pick up the stored session.
When both are present, the environment variable wins.
Credentials are resolved lazily on the first tool call, not at startup — so your client can connect and enumerate the tools before you've supplied a key, and a bad credential surfaces as a tool error rather than a server that won't start.
The server exposes five tools. Four are read-only; dcd_run_cloud_test submits a run and is billable.
| Tool | What it does |
|---|---|
dcd_list_devices |
Discover available devices, OS versions, and Maestro versions |
dcd_list_runs |
List recent test runs (filter by name/date, paginated) |
dcd_get_status |
Get the status and per-test results of a run |
dcd_download_artifacts |
Download a run's artifacts or report to disk |
dcd_run_cloud_test |
Submit a flow to run on the cloud (billable) |
See Tools Reference for every parameter, default, and return shape.
dcd_run_cloud_test consumes test credits, so it's annotated as a destructive/non-read-only tool so well-behaved clients can (and should) prompt before calling it. To hide it entirely (recommended for autonomous or untrusted agents), either:
- pass
--read-onlyinargs, or - set
DCD_MCP_READONLY=1inenv.
The remaining tools are all read-only. A read-only server doesn't just refuse the tool — it never advertises it, so an agent can't attempt a billable run at all:
{
"mcpServers": {
"devicecloud": {
"command": "npx",
"args": ["-y", "@devicecloud.dev/dcd", "dcd-mcp", "--read-only"],
"env": { "DEVICE_CLOUD_API_KEY": "<your-api-key>" }
}
}
}
{ "mcpServers": { "devicecloud": { "command": "npx", "args": ["-y", "@devicecloud.dev/dcd", "dcd-mcp"], "env": { "DEVICE_CLOUD_API_KEY": "<your-api-key>" } } } }