See AlmaSEO on a live client workspace The running app, fully populated. No signup, no login.

AI Agent Workspace

AI-assisted access to every client site you manage — however it's hosted.

Open a tab for each client and put an AI technician on every one — each already knowing that site's rankings, traffic, content, and history before you type. Reach a WordPress or static site over SSH, or a Cloudflare Pages site through the Cloudflare and GitHub APIs — same agent, same approvals, same client context. Ask what's wrong in plain language, approve the changes, and keep every finding attached to the client.

PowerShell gives you a terminal. Claude Code gives you a terminal assistant. AlmaSEO gives you a room full of AI technicians — one per client — each having already read that site's SEO reports before your first question, whether it reaches the site over SSH or drives Cloudflare and GitHub for you.

Connects over: SSH to WordPress and static sites, or the Cloudflare + GitHub APIs for sites on Cloudflare Pages — credentials and tokens encrypted at rest. Included on the Pro and Agency plans.

Full shell access · 33 types of live site data · every session saved to the client's history

An AI Agent Workspace session for Rapid Flow Plumbing — the agent pulls Search Console data, finds a noindex tag added to header.php that's blocking the whole site from Google, and prepares an approved one-line fix with a backup and live verification
One question — "why did traffic drop?" — to root cause, approved fix, backup, and live verification.

Is this for you?

If you work on client sites — over SSH or on Cloudflare Pages — yes.

You reach for a terminal, PowerShell, or Claude Code to dig into a client's site over SSH — or the site has no server to log into at all, because it's a static or Jamstack build deployed to Cloudflare Pages from a GitHub repo. The AlmaSEO Workspace is that exact workflow either way, with the client's context and history already attached.

Why not just keep doing it by hand?

The same work — without rebuilding the situation every time.

You can already do most of this across a stack of separate tools. AlmaSEO's difference is that it keeps all of it in one place, attached to the right site.

Doing it by handInside AlmaSEO
PowerShell, a terminal, or a command windowA calm, readable workspace with a persistent client record
Claude Code or another coding agentThe same kind of agent, plus the site's business, search, and agency context — or Claude Code itself, installed onto the server for you and driven from the same window
Explaining the site's SEO situation to the AI every single sessionIt already read the audits, gap analysis, rankings, and link profile before you typed
SSH credentials and hosting toolsSaved connections, controlled access, and team continuity
Search Console, Analytics, Bing, and crawlersA direct bridge from a search signal to the technical investigation
Slack, email, tickets, and private notesOne durable history of decisions, commands, changes, and outcomes
Rebuilding the client report each monthReport-ready evidence of what was actually investigated and done

One workspace, every client

A command center for your whole portfolio.

The AI Agent Workspace isn't one session at a time. Open a tab for every client, work them side by side, and let each tab carry that site's full context on its own — so switching clients is switching tabs, not rebuilding the situation.

  • Open All Connected — load every site with a saved connection in a single click
  • A tab per client, each an independent session with that site's data and history already loaded
  • Split-screen two sites to compare or work them together
  • Reorder tabs by dragging; move between them with Ctrl+T, Ctrl+W, Ctrl+1–9
  • A slow crawl runs in one tab while you work in another — real parallel throughput, not just open windows

This is the line between a tool you open when something breaks and the place you run your technical work all day.

The AI Agent Workspace inside AlmaSEO — three client sites open as tabs (Rapid Flow Plumbing, Carter & Associates Law, PureGlow Skincare) with two in split-screen, the agent diagnosing a traffic drop by pulling Search Console data and inspecting recently changed files
Three clients open at once, two in split-screen — one workspace across the portfolio.

Connect once

Two ways to connect — you pick how the site is hosted.

When you add a site, you choose how AlmaSEO reaches it. Pick SSH for a WordPress or static site on a server you log into. Pick Cloudflare Pages for a site with no server at all — one that deploys to Cloudflare from a GitHub repo. Either way you save the connection once, encrypted at rest, and open the workspace whenever the site needs work.

  • SSH — hostname, port, username, and a password or key on a saved, restricted account; environment-aware from the start for WordPress on Linux and static hosts
  • Cloudflare + GitHub — a Cloudflare API token and, optionally, a GitHub token, owner, and repo; the agent edits source through GitHub and manages the domain through Cloudflare
  • Test the connection before you open the session — no surprises
  • Edit a saved connection whenever the server, token, or repo changes
Open the Workspace →
AlmaSEO's New SSH Connection form — label, hostname or IP, port, username, authentication method, password, and environment set to WordPress (Linux), with Test Connection and Save & Open Workspace actions

Two ways the agent runs

Keep the approval gate, or hand the server to Claude Code.

Connecting decides how AlmaSEO reaches the site. This decides how the agent works once it's there. Every session opens in Remote Agent mode — the agent thinks inside AlmaSEO and sends one command at a time down the SSH connection, where the platform inspects each one and holds anything that changes the site for your approval. Direct Agent mode is the other end of that trade: AlmaSEO installs Claude Code onto the server itself and drives it from the same window, so the agent reads and edits at disk speed instead of a round trip per file. One click in the session header switches between them, mid-conversation, in the same session.

Default

Remote Agent

The agent runs in AlmaSEO and sends each command over SSH.

  • The approval gate applies. The platform classifies every command before it runs — reads go through, anything that changes something stops for an approval card you have to click.
  • Backups and rollback. Files are copied before they're edited, and a change that goes wrong is restored from the backup.
  • Secrets never reach the model. Passwords, keys, and config values are stripped before the AI sees them, before your screen, and before the log.
  • Findings and verification. Each finding lands in the Findings panel, and changes get a checkpoint that Search Console data later judges Passed, Declined, or Stable.
  • Best for client work, on-page fixes, and anything you want a reviewable record of.
Opt-in

Direct Agent

Claude Code, installed on the server, driven from the same window.

  • AlmaSEO installs it for you. A saved SSH connection shows Install Direct; one click installs Claude Code over the connection and the card turns to Direct Ready. You never open a terminal.
  • Disk speed, not network speed. The agent is on the box, so it can sweep a whole theme or plugin directory in the time the remote agent spends opening a handful of files.
  • It can follow a long thread to the end. A remote turn works to a step budget per message; a direct one doesn't have one.
  • Your same Anthropic key. AlmaSEO passes it through to the agent on the server. There's nothing extra to buy.
  • No approval cards — that's the trade. Claude Code holds the shell itself, so AlmaSEO isn't standing between it and the server to gate anything. It edits when it decides to, and there's no backup or rollback behind it. Use it where you'd hand a developer the same access.
  • Best for deep audits, hunting a bug through a codebase, and heavy work on a site you own.

Both modes are the same session — the same window, the same conversation, the same client history, and the same record saved to the site when you're done. Start in Remote, because that's where the guardrails are. Switch to Direct for the jobs where you want a coding agent with the run of the box, and switch back before you touch anything you'd rather approve first.

It already read the reports

Your SEO data walks into the session with you.

This is the whole difference between AlmaSEO's AI Agent Workspace and a coding agent with an SSH key. A terminal opens knowing nothing about the website. The workspace opens having already read everything AlmaSEO has on that client — the audits, the rankings, the gaps, the link profile, the work you logged last month — and it can pull fresh numbers mid-session whenever it needs them.

What it knows before you type

  • Search Console — the queries, clicks, impressions, and positions this site actually has
  • Analytics — users, sessions, engagement, top pages, and where the traffic comes from
  • Content gaps — the topics the site should rank for and doesn't
  • Published articles — what's already been written, so it never suggests a page you have
  • Link profile — the site's authority and referring domains
  • Infrastructure & locations — the stack it's about to work on, and the markets it serves
  • Activity history — what you and your team already did for this client, and when

So the session starts here, not at zero

  • "This page ranks #11 for a query with 2,400 monthly impressions and a 0.9% click rate — the title tag is the problem, not the content."
  • "Traffic to your three highest-converting pages dropped after the last deploy. Here's what changed on the server that week."
  • "You're missing a page for a topic you're already getting impressions on. I can draft it and publish it."
  • "Last time you were here, you noted this host caches hard and needs a purge after every edit — so I'll purge once the change is in."

You never brief it. You never paste a report into a prompt. You ask the question, and the answer already accounts for the client's real numbers.

Suggested fixes

The dashboard doesn't just inform the agent. It hands it the work.

Every analysis in AlmaSEO puts a Send to AI Agent button beside the problems it finds. Click it and the issue crosses into the workspace as its own card, carrying what's wrong, how urgent it is, the URLs and numbers behind it, and fix instructions written for the agent rather than for you. A badge on the client counts what's waiting; one click on a card opens a session already holding all of it. You never re-explain the problem, because the tool that found it already did — and the queue holds what you chose to send, not everything a scan happened to notice.

Five analyses hand work over — 16 kinds of issue in all

  • Technical audit6 kinds of issue
  • SEO Recovery5 kinds of issue
  • First Impression3 kinds of issue
  • Link profile1 kind of issue
  • Local citations1 kind of issue
Suggested fix

No structured data on the homepage

Found by the technical audit, and sent over with its fix already written: check the SEO plugin's settings, then the theme's header.php and functions.php. The agent starts from that instruction, not from your description of the problem — and it can back the file up, apply the change, and verify the markup is live.

Start session →

The session opens pre-loaded. No prompt to write.

This is the line between AlmaSEO and a terminal with an AI in it. Claude Code with an SSH key starts blind — you have to know what's wrong, and explain it, before it can help. AlmaSEO finds the problem first, then hands the agent the diagnosis, the context, and the instructions. The hard part was never running the command. It was knowing which one to run, and why.

What the workspace does

Everything you'd expect from an AI-assisted session — and the context a terminal never has.

One workspace to investigate, fix, and document website work — over SSH, or through Cloudflare and GitHub for serverless sites — with the client's SEO data and history behind every session.

Run a real session

Ask in plain language. It runs the commands.

You describe what you're chasing. The agent decides what to inspect, runs approved commands, and explains what it finds — with the raw terminal one click away.

Natural-language agent

Tell it "why is this site slow?" or "did the last deploy break the canonicals?" The AI agent plans the checks and calls the right commands itself.

Runs on Claude, with your key

The agent is powered by Claude — the AI assistant you already know — using your own API key, validated before the session starts.

Show it, don’t describe it

Drag a screenshot onto the workspace, paste one straight from your clipboard, or attach a file with the paperclip. The agent sees the image — the broken layout, the Search Console graph, the screenshot a client emailed you at nine on a Sunday — instead of working from your description of it. PDFs, error logs, CSV exports, config files and source files go in the same way, and they stay attached to the session when you reopen it later.

Quick-start templates

Open a session straight into a common job — Why is my site slow? · Check error logs · Post-deployment SEO check — from six clickable cards, no typing required.

Clean session activity

Readable steps like "reviewing PHP errors" or "checking active plugins," each with the exact command, raw output, and timestamp expandable underneath.

Command safety & approval

The workspace always shows whether it is reading, proposing, or changing. Anything that alters the site waits for your approval first.

Lays out an investigation plan

For bigger jobs the agent shows you the whole approach up front, then works through it — safe reads run on their own, and anything that changes the site still stops for its own approval.

Updates SEO metadata on approval

With your approval, the agent can rewrite title tags and meta descriptions on live pages — turning a diagnosis into a shipped on-page fix without leaving the session.

Drafts the missing page and publishes it

Spot a gap and have the agent write the page to fill it — a blog post, a service page, or an FAQ — then publish it straight onto the live site on your approval. It records what it published back into the client’s content, so the page is submitted for indexing and shows in their history like anything else you shipped.

Publishes it, even with no CMS to publish into

A site with no WordPress behind it used to mean exporting a file and placing it yourself. The agent has a real shell, so it does what you would do: finds the content directory, reads your existing posts to match their frontmatter exactly, writes the file, commits it on your approval, and checks the build actually deployed. On WordPress it publishes through WP-CLI instead. Either way it records the page back into the content engine, so it gets submitted for indexing rather than sitting on the server unnoticed.

And it keeps reading

Not a blank terminal — a workspace that looks things up.

Knowing the reports is the start. Once the session is open the agent keeps reading — pulling fresh search and analytics numbers when a question needs them, comparing this week against last, and working out for itself what the site is built on and how it is run. Context that is fetched when it matters, not a briefing pasted in at the start.

Pulls fresh numbers mid-session

It doesn't just work from what was loaded at the start. Mid-conversation the agent queries live Search Console, Analytics, content, and link data itself — so a recommendation is grounded in what the site is doing today.

Knows what changed since last week

AlmaSEO records this site's Search Console, Analytics, and Business Profile numbers every night, so the agent doesn't only read today — it compares. "Clicks are down 18% on last week." "Sessions are climbing — 1,240 this week against 980 two weeks ago." "Map views have been sliding all month." The history builds on its own, whether or not anyone opens the dashboard.

WordPress environment detection

It detects the WordPress install, checks the WP-CLI version and install path, and adjusts how it works to match the environment.

Speaks your SEO plugin

Yoast, Rank Math, All in One SEO, or SEOPress — the agent detects which one the site runs and writes the metadata the way that plugin expects, so a title-tag change actually takes instead of silently doing nothing.

It knows the retainer, too

Ask how much of this month's retainer is left and the agent pulls the real number — logged hours, utilization, time remaining. No terminal knows a client's billing. The workspace does.

Thirty-three kinds of data, on demand

Mid-session the agent can pull any of thirty-three AlmaSEO data types — indexing status page by page, Business Profile metrics, citation consistency, tracked competitors, recovery findings, the strategy plan, keyword research, Core Web Vitals, traffic drops, query cannibalization, CTR opportunities, and Google Ads spend among them. One source of truth, not a second silo.

Nothing gets lost

Every session becomes memory the site keeps.

The work doesn't evaporate when you close the window. Findings, decisions, and outcomes stay attached to the right website and flow straight into your records.

Structured session summary

When you end a session, the agent writes a clean recap — what was checked, what it found, what changed, what remains, and the recommended next steps.

Findings panel

Every finding from the session collects in one place — problem, evidence, affected pages, and recommended action — separated from the raw command stream.

Turn a finding into a task

Convert any finding into a tracked task in one click, so the fix doesn't get lost between spotting it and getting it done.

Add your own notes

Annotate a session with your own notes, so the context you know but the terminal doesn't stays attached to the site.

Saved to the client's history

The whole session — conversation, commands, findings, and decisions — is attached to the site, auto-named from your first message, ready to reopen later.

A knowledge base per site

What the agent learns about a site — its quirks, its stack, what broke last time and why — persists between sessions. Every session starts smarter than the last one, instead of from a blank prompt.

Straight into Activity Logs

Export a session into the activity and reporting system it already feeds, so the work counts toward the client record without re-entering anything.

Session to client report

Turn a finished session into a formatted, client-ready report of what was done and why it mattered.

Hand off the work

Generate a ready-to-send handoff from the session — developer instructions and an implementation checklist, a Claude Code prompt to run the fix, or a plain-English explanation for the client.

Resume where you left off

Reconnect to a dropped session and pick up the thread — the history comes back with it.

For sites without a server

Cloudflare Pages and GitHub, driven by the same agent.

Not every client site is a server you SSH into. When a site is a static or Jamstack build that deploys to Cloudflare Pages from a GitHub repo, the workspace connects through the Cloudflare and GitHub APIs instead — and the agent works the same way, with the same approvals and the same client context.

Edits the source through GitHub

The agent reads, browses, edits, creates, and deletes files in the site's GitHub repo — one file, or several in a single atomic commit. Each commit triggers a Cloudflare Pages build, so an approved edit ships itself instead of waiting on a deploy you run by hand.

Watches the deploy land

After a commit it checks the Cloudflare Pages deployment — building, live, or failed — and can retry a failed build. You see the change reach production, not just the repository.

Manages DNS on the Cloudflare zone

List, add, change, or remove DNS records — A, CNAME, TXT, MX and more — on the site's Cloudflare zone. Every change is held for your approval like any other.

Purges the cache when the change is live

Clear Cloudflare's cache the moment an edit ships — everything, specific URLs, by cache tag, or by hostname — so visitors and Google see the new version now instead of a stale copy.

Bulk redirects without a config file

Add and manage 301 and 302 redirects as Cloudflare bulk rules — migrations, consolidations, and tidy-ups handled from the session, not a hand-edited file.

Reads the traffic, sets the env

Pull Cloudflare's own traffic numbers — requests, bandwidth, page views, visitors, cached versus uncached — and get or set the Pages project's environment variables per environment, production or preview.

Same gate, same brain

It's the same workspace, not a second tool. Read-only checks run on their own; anything that changes a file, a DNS record, or a redirect stops for an approval card. And the client's SEO reports, findings, knowledge base, and verification checkpoints are all in the room, exactly as they are over SSH.

Safe on a client's server

Built to be trusted with a live site.

Fast doesn't mean careless. The workspace reduces scope before it skips a control, and nothing meaningful happens without you. Everything in this section describes Remote Agent mode — the default every session opens in. Direct Agent mode trades this gate for raw speed, deliberately, and only once you turn it on.

What is allowed to run at all

The gate is the foundation. It decides, before anything executes, whether the workspace may act on its own or has to come back to you.

The rules live outside the AI

Whether a command needs your approval is not the model's judgment call. The platform inspects every command itself and enforces the answer: read-only commands run, anything that changes something stops for an approval card — no matter what the AI thinks it should be allowed to do. You're not trusting the model to behave. You're trusting a gate it doesn't control. The one exception is Direct Agent mode, where Claude Code runs on the server itself and there is no gate in between — which is why it is opt-in, installed per connection, and off until you ask for it.

Some things it will never auto-run

A short list of catastrophic commands — wiping a disk, dropping a database, a fork bomb — always stops for a high-risk approval, even if you've turned auto-approve on for everything else. No setting lets those through unseen.

Approve exactly what you saw

An approval is bound to the exact command and context on the card. Change a single character, the target file, or the connection, and the approval is void — the workspace asks again instead of running something you never saw.

You know if it's undoable before you say yes

Every approval card tells you up front whether the change can be rolled back. You're never guessing whether "approve" is a decision you can take back.

Around every change it makes

A change is not one moment. There is a before, an after, and a question of whether it actually worked — and the workspace holds all three.

Backs up every file before it changes it

Before the agent edits anything on a live site, it saves a backup of the original. The version you had a minute ago is always one step away.

One-click rollback if something goes wrong

If a change doesn't land the way it should, the agent restores the file from its backup — no scrambling to undo it by hand on a client's server.

Verifies the change is actually live

After an edit, the agent fetches the live HTML and confirms the change is really reflected — not just saved on disk, but showing to Google and visitors.

Then the search data weighs in

Every change gets a checkpoint, and the workspace later pulls fresh Search Console data to show what happened after it — Passed, Declined, or Stable. It keeps two things separate on purpose: whether the change is confirmed live, and whether the rankings moved. Rankings move for a lot of reasons, and the workspace won't pretend your fix was the only one. You get the honest picture instead of a victory lap.

Verify a change, or verify them all

A Verifications tab collects every checkpoint waiting on Search Console data for that client, with a running count of what's pending, ready, passed, and declined. Verify one when you're curious, or clear the ready queue in a click — each comes back Passed, Declined, or Stable, and says so plainly when Google hasn't reported enough yet to call it.

The connection you handed it

Before any of that, the credentials themselves. A saved connection is a standing key to a client's server, and it is treated like one.

Credentials encrypted at rest

Connection details are stored encrypted. You save a connection once and open the workspace from it — no re-entering credentials every session.

Your connections back themselves up

Every time you save, edit, or delete a connection, AlmaSEO writes an encrypted backup and keeps five rolling copies — so a fat-fingered edit or a deleted connection isn't a scramble to remember what the hostname was. You can export the whole set to a file whenever you want, and an import re-checks that every credential still decrypts, skips the ones you already have, and refuses any site you don't have access to. The credentials never leave encrypted form.

Notices if the server changes identity

The workspace pins a server's host key the first time you connect and checks it on every reconnect — if the fingerprint doesn't match, you hear about it before a single command runs.

Session isolation

Credentials, context, and output stay inside the client they belong to. Nothing leaks between the sites you manage.

What you can see, and what you can stop

Supervision is only real if you can watch it and interrupt it. Both, at any point, without waiting for the agent to finish its thought.

Your secrets never reach the AI

Passwords, API keys, and private keys — in files like wp-config.php or .env, or anywhere a secret-shaped value turns up in a command's output — are stripped before the model sees them, before they reach your screen, and before anything is logged.

Kill a command mid-run

A command taking too long, or doing more than you expected? Stop it while it's running — the workspace shuts it down on the server, not just in the chat window.

Full transparency

Exact commands, output, and timestamps are stored for review, so a technical user can inspect everything instead of trusting a black box.

In the agent's own words

"With my client's SEO data, what can you actually do?"

A real answer from a live session — every capability tied to the client's own Search Console and Analytics data, and every one something the workspace can do in the same conversation.

With full access to my client's SEO data in AlmaSEO, what can you do to help them — and what tools let you do it?

Here's the complete answer — what I can do, and what powers it:

📊 1. Analyze their current performance

Tools: GA4 + Google Search Console

  • Pull real traffic — sessions, users, engagement, bounce rate
  • See which pages get traffic and which are invisible
  • Identify the keywords they already rank for, and exactly where they sit
  • Spot traffic drops and tie them to a specific date and cause

🔎 2. Find exactly what's missing

Tools: GSC + content gaps + WordPress file access

  • Keywords they get impressions for but have no page targeting
  • Every service + location combination that should have a page but doesn't
  • Thin content, missing metadata, and duplicate titles

✍️ 3. Create the missing pages — right now

Tool: AlmaSEO Content Engine

  • Write and queue service pages, location pages, FAQs, and posts
  • Targeted to specific keywords pulled from real GSC/GA4 data — not generic
  • Examples for a property-management client:
    • "Property Management Detroit MI"
    • "Single Family Property Management Ferndale"
    • "Multifamily Property Management Oakland County"
    • "How Much Does Property Management Cost in Michigan?"

🏷️ 4. Optimize metadata on live pages — instantly

Tool: WP-CLI via SSH + AIOSEO

  • Rewrite title tags and meta descriptions on the live site
  • Target the exact keywords GSC shows people searching for
  • Fix duplicate titles causing keyword cannibalization
  • No logging into WordPress — I do it from right here

📈 5. Push "almost ranking" keywords to page 1

Tools: GSC + WP-CLI + Content Engine

  • Find every keyword sitting at positions 8–20 — the low-hanging fruit
  • Diagnose what's holding each one back, and fix the metadata on the spot
  • Add supporting content to boost authority — the highest-ROI work in SEO

…and more in the same session: technical WordPress fixes, malware and security scans, and a full local-SEO build-out.

🧰 Tools: GA4 · Search Console · AlmaSEO Content Engine · WP-CLI via SSH · WordPress files

💡 The bottom line: I don't just tell you what's wrong — I fix it, build it, and optimize it in the same conversation. Every action is driven by your client's real data, not guesswork.

Every capability above is live in the workspace today.

What people open it for

The jobs you reach for a terminal to do.

WordPress slowdown

Find what's dragging the site down.

Disk use, debug logs, PHP errors, database size, cache state, active plugins, and recent changes.

Critical WordPress error

Read the log, name the cause.

Identify the failing component, explain the likely cause, and prepare a safe next step.

Indexing or canonical problem

Compare live HTML to what should ship.

Sitemap status, robots directives, canonicals, connected search data, and recent changes side by side.

Redirect or migration issue

Untangle chains, loops, and dead ends.

Redirect behavior and broken destinations, with the affected high-value pages flagged.

Suspicious or injected code

Surface the evidence, honestly.

Indicators, unexpected recent changes, obfuscated code, or altered core files — shown, never waved off.

Post-deployment SEO check

Catch what the deploy changed.

Changes against search-critical templates, metadata, canonicals, schema, and indexability.

Questions

Frequently asked questions

What is the AlmaSEO AI Agent Workspace?
It's an AI agent for the client sites you manage, built into AlmaSEO. It connects to a site the way that site is hosted — over SSH to a WordPress or static server, or through the Cloudflare and GitHub APIs for a site that deploys to Cloudflare Pages. You ask what's wrong in plain language, and the agent runs approved commands, explains what it finds, and saves the whole session to the site's history — with the client's SEO data and context already in the room.
Do I need to know the command line to use it?
No. You describe what you're chasing in plain language and the agent decides which commands to run. The exact commands and raw output are always one click away if you want them, but you never have to type a command yourself.
What can it connect to?
Two kinds of site. Over SSH: WordPress and static sites on a server you log into, using a saved connection with the hostname, port, username, and password or key — it detects the environment and adjusts to match. Or, for a site with no server to SSH into, over the Cloudflare and GitHub APIs: a static or Jamstack site that deploys to Cloudflare Pages from a GitHub repo. You pick which when you add the site.
My site doesn't use SSH — it's on Cloudflare Pages. Can I still use this?
Yes. Choose the Cloudflare Pages connection instead of SSH and give AlmaSEO a Cloudflare API token, plus optionally a GitHub token and repo. The same agent then edits your source through GitHub — each commit auto-deploys via Cloudflare Pages — and manages DNS, cache, redirects, environment variables, and traffic analytics through Cloudflare. Read-only checks run on their own; anything that changes a file, a record, or a redirect still stops for your approval, exactly as it does over SSH.
Is it safe to give AlmaSEO my Cloudflare and GitHub tokens?
Yes, and the same rules that protect the SSH path protect this one. Your Cloudflare API token and GitHub token are encrypted at rest, the same as an SSH credential — you save the connection once and never re-enter it. You decide their scope when you create them: a Cloudflare token limited to the permissions the workspace uses (Pages, DNS, cache, analytics) and a GitHub token limited to the single repo. And the approval gate is identical — reading files, listing DNS records, and checking deployments run on their own, but anything that edits a file, changes a record, purges the cache, or ships a deploy stops for your approval first. The token lets AlmaSEO act on your behalf; it never lets it act without your say-so.
Which AI powers the workspace?
Claude — the AI assistant many people already know — running on your own API key, which is validated before the session starts. You bring the key; AlmaSEO brings the workspace, the context, and the memory.
What is the difference between Remote Agent and Direct Agent mode?

It is where the agent runs, and what that costs you in control. Remote Agent is the default: the agent thinks inside AlmaSEO and sends one command at a time down the SSH connection, so the platform can inspect each one, hold anything that changes the site for your approval, back files up before they are edited, and strip secrets out of what the model sees. That is the mode all the safety guarantees on this page describe.

Direct Agent installs Claude Code onto the server itself — one click on a saved connection, no terminal — and drives it from the same window. The agent is on the box, so it reads and edits at disk speed instead of a round trip per file, and it can follow a long investigation to the end rather than working to a step budget per message. It runs on the same Anthropic API key you already gave AlmaSEO; there is nothing extra to buy.

The trade is the gate. In Direct mode AlmaSEO is not standing between the agent and the server, so there are no approval cards, no file backups, and no rollback — it edits when it decides to. It is off until you install it, per connection, and one click in the session header switches back. Start in Remote, and reach for Direct on the jobs where you would hand a developer the same access.

Why can't I just use Claude Code and PowerShell?
You can — and if you already do, you understand the value. AlmaSEO keeps the client context, search data, commands, decisions, session history, and proof together instead of making you reassemble them from six tools every time. The workflow is the same; the setup and the memory are what change. And if Claude Code is specifically what you want on the box, the workspace will install it there for you and run it as Direct Agent mode — so you get the coding agent you already like, plus the client record it was never going to keep.
Isn't this just a browser terminal?
No. The terminal is only the access layer. AlmaSEO organizes the agent's work into readable activity, findings, approvals, history, and client-specific records — while keeping the exact commands and raw output available for when you want them.
Is it safe to connect my server to AlmaSEO?

Yes — safe access is the foundation this feature is built on, not an afterthought. Because AlmaSEO connects directly to your server to diagnose issues from the inside, we designed it so that nothing can change or damage your site without your explicit approval.

Here's how it works. AlmaSEO reads and investigates freely, but the moment it wants to run anything that could modify a file, alter your database, or send data off your server, it stops and asks you first. You see exactly what it wants to run and why, and it doesn't proceed until you click approve. You're always the final decision-maker — the AI can recommend, but it can't act on anything sensitive on its own.

We also assume the internet is a hostile place, and we built accordingly. Your login credentials are encrypted, and your server's identity is verified on every connection, so AlmaSEO won't be fooled into connecting to an impostor. If we ever read something sensitive like your site's configuration file, the AI can use it to help you, but it's automatically hidden from our activity logs rather than stored in plain text. And because AI assistants can be manipulated by malicious content, AlmaSEO is specifically instructed to treat anything it finds on a server as untrusted — it will never follow hidden instructions buried in a file or a log.

Finally, these protections have been put through repeated adversarial hardening reviews built to break them, and each command AlmaSEO runs is permanently logged, so you have a complete, reviewable record of everything that happened.

All of that describes Remote Agent mode, which is how every session opens. There is a second mode, Direct Agent, that installs Claude Code onto the server and lets it work there without the approval step — faster and deeper, and correspondingly less supervised. It is opt-in per connection and clearly labelled in the session header, so you are never in it without having put yourself there.

Does it change my site on its own?
In Remote Agent mode — the default — no. The workspace always shows whether it's reading, proposing, or changing, and anything that alters the site waits for your approval first. Bigger jobs come back as a multi-command investigation plan you approve before it runs. The exception is Direct Agent mode, which you have to install and switch on yourself: there Claude Code runs on the server and acts without approval cards, which is the whole point of it and the reason it is opt-in.
What stops the AI from deciding to skip its own safety rules?

The AI doesn't enforce them, so it can't skip them. Every command it wants to run is inspected by the platform before it executes, and the platform decides whether it's allowed to run on its own or has to stop and ask you. Read-only commands go through. Anything that modifies a file, touches the database, or reaches off the server comes back to you as an approval card.

That distinction matters. A lot of AI tools ask the model to police itself — the safety rule lives in the prompt, and a clever enough input can talk it out of them. Here, the gate sits outside the model entirely. The AI can be wrong, or confused, or fed a malicious instruction hidden in a log file, and the answer is the same: it still doesn't get to run a destructive command without your click.

On top of that, approval cards tell you whether the change is reversible before you approve it, files are backed up before they're modified, and anything that goes wrong can be rolled back.

One mode is deliberately outside all of this, and we would rather say so than let you find out. Direct Agent mode installs Claude Code onto the server and lets it work there directly — no round trip through AlmaSEO, so nothing for AlmaSEO to gate. It is off until you install it on that specific connection, the session header shows which mode you are in, and one click puts you back in the gated one. Everything above applies to Remote Agent mode, which is where every session starts.

What happens to a session after I close it?
It's saved to the client's site history — the conversation, commands, findings, and decisions — with a structured summary. You can reopen it, turn findings into tasks, export it to your Activity Log, or generate a developer, client, or Claude Code handoff from it.
Can I use it across multiple client sites?
Yes. Each site has its own saved connections, sessions, and memory, and credentials and context never leak between clients — so a portfolio of sites stays organized and isolated.
Will this replace my developer?
No. It speeds up investigation, produces clearer evidence, prepares the work, and handles supported actions — but human technical judgment still matters. It makes your best technical work faster to do and easier to hand off, not a person you remove from the process.
Does this only do SEO?
It's SEO-focused, not SEO-restricted. You can investigate recognizable website and server problems — slow sites, errors, redirects, suspicious files — while AlmaSEO contributes the search and client context a blank terminal doesn't have.
I only manage one site — is it worth it?
For occasional, one-off work, a local session may be all you need. AlmaSEO earns its place when continuity, connected SEO data, repeated investigations, or client reporting matter — and the value compounds the more sites and history you build up.

Open a workspace

Connect a website and start a session.

Point AlmaSEO at a WordPress, static, or Cloudflare Pages site, ask it what's wrong in plain language, and keep every command, finding, and decision attached to the client.

Already using Claude Code, PowerShell, or a terminal over SSH? This is that — cleaner, persistent, and built for SEO and multi-site client work.