vps-ops-mcp
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@vps-ops-mcpcheck health and SSL status for my-vps"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
vps-ops-mcp
Don't give your AI raw root SSH. A safe, structured MCP server that lets Claude (or any MCP client) inspect and operate your VPS — nginx, PM2, SSL, UFW, fail2ban — through typed, allowlisted tools instead of free-form shell access.
Read-only by default. Mutating actions don't even exist unless you opt in with an environment variable.
You: "Is everything OK on my server? Any cert expiring soon?"
Claude → server_health(myvps) → load 0.08, disk 61%, RAM fine
→ ssl_status(myvps) → b2fest.com expires in 71 days ✓
→ security_audit(myvps) → ufw active, root login disabled ✓Why not just an SSH MCP server?
Generic SSH MCP servers hand the model a root shell and hope for the best. This server takes the opposite approach:
Raw SSH MCP | vps-ops-mcp | |
Command surface | anything | fixed command templates only |
User input in commands | interpolated | strict allowlist regex, rejected otherwise |
Credentials | often stored in config | never touched — delegates to your |
Password prompts | can hang |
|
Writes/restarts | always on | off by default, opt-in via env var |
| sure, why not | refused by design |
Related MCP server: mcp-tool-server
Quickstart
Requires Node 18+ and a working ssh <your-host> from your terminal (key-based auth).
Claude Code
claude mcp add vps-ops -- npx -y vps-ops-mcpClaude Desktop / Cursor / any MCP client — add to your MCP config:
{
"mcpServers": {
"vps-ops": {
"command": "npx",
"args": ["-y", "vps-ops-mcp"]
}
}
}Then just ask: "Check the health of myvps" (any alias from your ~/.ssh/config, or user@host).
Enabling mutations (optional)
By default the server is strictly read-only. To enable the two mutating tools (nginx_check_and_reload, pm2_restart):
{
"mcpServers": {
"vps-ops": {
"command": "npx",
"args": ["-y", "vps-ops-mcp"],
"env": { "VPS_OPS_ALLOW_MUTATIONS": "true" }
}
}
}Even then: no free-form commands, nginx -t always runs before a reload, and pm2 restart all is refused.
Tools
Tool | What it does | Needs |
| Lists aliases from your local | nothing (local) |
| Uptime, load, memory, disk, top processes | ssh |
| Enabled nginx sites, PM2 process list, running web services | ssh |
| Cert expiry for every domain found in nginx configs (or one domain) | ssh |
| Tail nginx access/error, PM2 app, or journald unit logs | ssh (some logs: sudo) |
| Listening ports, UFW, fail2ban, sshd hardening, pending security updates, recent logins | ssh (richer with sudo) |
|
| opt-in + sudo |
| Restart one named PM2 app (never | opt-in |
🔒 = only registered when VPS_OPS_ALLOW_MUTATIONS=true.
About sudo
Some checks (ufw, fail2ban, sshd -T) need root. The server always uses sudo -n (non-interactive): if passwordless sudo isn't configured for those commands, the check degrades gracefully and tells you, instead of hanging on a password prompt. You choose how much to allow in /etc/sudoers.d/.
Safety model
No credential handling. We spawn your system
sshbinary. Keys, agents,ProxyJump,known_hosts— all yours, all untouched.Fixed command templates. Remote commands are string constants. There is no
run_commandtool and there never will be one in read-only mode.Allowlist validation. Every user-supplied value (host, app name, domain, unit) must match a strict regex before it goes anywhere near a command line. No escaping heuristics — invalid input is simply rejected.
Bounded output. Every call has a timeout and an output cap, so a runaway
tailcan't flood your context window.Mutations are opt-in and minimal. Two tools, both narrow, both guarded.
Roadmap
site_provision— nginx vhost + certbot + PM2 registration in one guarded flowDocker container inventory & log tools
Caddy support
Multi-server fleet summary (
health across all hosts)Scheduled-check examples (cron + Claude Code headless)
PRs welcome — especially real-world ops workflows this doesn't cover yet.
License
MIT © Azat Akdağ
Available Tools
6 toolslist_hostsList SSH hostsA
Lists host aliases from the local ~/.ssh/config. Purely local — no connection is made. Use one of these aliases as the host argument for the other tools.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries full transparency burden. It discloses that the tool is read-only and local ('purely local — no connection is made'), which is critical for agent safety. It does not specify details like whether it reads all aliases or the output format, but the given context is sufficient.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences: the first states the core functionality, the second provides usage guidance. It is front-loaded, brief, and contains no extraneous words.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The tool has no output schema. The description explains what the tool does and its side effects (none), but does not specify the output format (e.g., array of alias strings). For a simple list tool, this is adequate but could be more complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has no parameters (coverage 100%), and the description adds no parameter information. Following the rule that high schema coverage defaults to 3, and since there are no parameters to explain, this score is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description explicitly states the tool lists host aliases from the local ~/.ssh/config and emphasizes it is purely local with no connection made. This clearly identifies the resource and action, distinguishing it from sibling tools that likely involve remote operations.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description advises using the aliases from this tool as the 'host' argument for other tools, providing clear context for when to use it. It lacks explicit when-not-to-use guidance or comparisons with specific siblings, but the intent is clear.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_sitesList hosted sites & appsA
Read-only inventory of what a server hosts: enabled nginx sites (domains, ports, upstreams), PM2 process list, and running web-related systemd services.
| Name | Required | Description | Default |
|---|---|---|---|
| host | Yes | SSH host alias from ~/.ssh/config, or user@hostname |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description declares it read-only, which is a key behavioral trait. However, without annotations, it could detail authorization needs or response format. The offered detail is good but not exhaustive.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Single, well-structured sentence front-loads the read-only nature and lists components precisely. No unnecessary words.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The description covers the tool's domain and scope adequately, given no output schema. Could mention response structure or limits, but sufficient for understanding.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The description does not add meaning beyond the input schema; the parameter 'host' is fully described in the schema. Baseline 3 applies due to high schema coverage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states it lists hosted sites and apps, specifying nginx sites, PM2 processes, and systemd services. It distinguishes from sibling tools like list_hosts and server_health by focusing on inventory.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage for inspecting server hosting, but does not explicitly state when to avoid using it or contrast with alternatives. Context from sibling tools suggests differentiation, but lacking explicit guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
read_logsRead server logsA
Read-only tail of common logs: nginx access/error, a PM2 app, or a systemd unit's journal. name is required for pm2 (app name) and journal (unit name).
| Name | Required | Description | Default |
|---|---|---|---|
| host | Yes | SSH host alias from ~/.ssh/config, or user@hostname | |
| name | No | PM2 app name or systemd unit name (required for pm2/journal) | |
| lines | No | Number of lines to tail (10–500, default 100) | |
| source | Yes | Which log to read |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description must fully disclose behavior. It states 'Read-only tail' (non-destructive) and lists sources, but does not mention rate limits, authentication requirements, or error handling. The absence of annotations places a higher burden, but the description covers the essential behavior.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences, no redundant information. The purpose is stated first, followed by a critical parameter dependency. Efficient and well-structured.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple read-only log tail tool, the description covers source types and parameter constraints. The only minor gap is the lack of output format description (e.g., returns raw log lines), but this is not critical given the context.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, baseline 3. The description adds value by clarifying that `name` is conditionally required (for pm2 and journal), which is not enforced by the schema. This additional constraint helps the agent correctly invoke the tool.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Description clearly states 'Read-only tail of common logs' and lists specific log types (nginx, PM2, systemd), distinguishing it from sibling tools that cover hosts, sites, security, health, and SSL status.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Provides clear context for using the tool to read logs, and specifies that `name` is required for pm2 and journal sources. No explicit when-not-to-use or alternatives are mentioned, but given sibling tools are unrelated, this is sufficient.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
security_auditSecurity auditA
Read-only security posture check: listening ports, UFW firewall rules, fail2ban jails, sshd hardening flags (root login / password auth), pending security updates, recent logins. Sub-checks that need passwordless sudo degrade gracefully with a note.
| Name | Required | Description | Default |
|---|---|---|---|
| host | Yes | SSH host alias from ~/.ssh/config, or user@hostname |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description discloses that the operation is read-only and that sub-checks requiring passwordless sudo will 'degrade gracefully with a note'. This adds valuable behavioral context beyond the input schema, especially since no annotations are provided.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is concise with two sentences, no extraneous information, and front-loads the purpose. Every sentence adds value.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool has one parameter and no output schema, the description covers the main functionality and important behavior (degradation). It lists the checks performed, which helps an agent infer output structure. Slightly less complete if the output format is needed, but adequate.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema already fully describes the single 'host' parameter with its format. The description does not add additional semantic meaning beyond this, so a baseline score of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states it is a 'Read-only security posture check' and enumerates specific areas checked (listening ports, UFW, fail2ban, sshd, updates, logins), making its purpose unambiguous and distinct from sibling tools.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage for security checks but does not explicitly state when to use this tool versus alternatives like server_health or ssl_status. It mentions graceful degradation for missing sudo, which gives some context but lacks clear when-to-use / when-not-to-use guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
server_healthServer health checkA
Read-only snapshot of a server: uptime, load average, memory, disk usage, and the top processes by CPU and memory.
| Name | Required | Description | Default |
|---|---|---|---|
| host | Yes | SSH host alias from ~/.ssh/config, or user@hostname |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description states 'Read-only snapshot', indicating no side effects, and lists the data returned. However, with no annotations, it fails to disclose authentication requirements, potential performance impact, or error conditions, so transparency is adequate but not thorough.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single concise sentence that efficiently conveys the tool's purpose and contents. It is front-loaded with 'Read-only snapshot' and avoids unnecessary words, though a slightly more structured presentation (e.g., list) could improve scannability.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
No output schema is present, so the description must explain return values. It lists key data points (uptime, load, memory, disk, top processes), which is fairly complete for a health check. It lacks error handling details but is otherwise sufficient for the tool's simplicity.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has one parameter 'host' with a clear description. The tool description does not add additional meaning beyond the schema's description. Since schema coverage is 100%, baseline score of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool provides a read-only snapshot of server health including uptime, load average, memory, disk usage, and top processes. It is specific about the resource (server health) and the action (snapshot), and the listed content distinguishes it from sibling tools like list_hosts or read_logs.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage for monitoring server health but does not explicitly state when to use versus alternatives like security_audit or ssl_status. No guidance on when not to use or prerequisites (e.g., SSH access) is provided.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
ssl_statusSSL certificate statusA
Checks TLS certificate expiry dates. Without domain, auto-discovers domains from the server's nginx configs and checks each one (max 20). Read-only; runs openssl s_client on the server itself, so it also works for internal-only DNS.
| Name | Required | Description | Default |
|---|---|---|---|
| host | Yes | SSH host alias from ~/.ssh/config, or user@hostname | |
| domain | No | Check a single specific domain instead of auto-discovering |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations provided, so description carries full burden. It discloses read-only operation via openssl s_client, server-side execution, and auto-discovery limit of 20 domains. Could mention output format.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences, front-loaded with purpose, every word earns its place. No wasted verbiage.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Good given no output schema, but lacks description of output format (list of domains with expiry dates? any warnings?). Adequate but could be more complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage 100% (baseline 3). Description clarifies 'host' as SSH alias and 'domain' as override for auto-discovery, adding meaning beyond schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states it checks TLS certificate expiry dates, specifies auto-discovery vs explicit domain, and is distinct from sibling tools like security_audit or server_health.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Describes when to use with/without domain, mentions internal DNS capability, but doesn't explicitly compare to sibling security_audit or state when not to use.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
6 tool updates
v0.1.0- First observed
list_hosts - First observed
list_sites - First observed
read_logs - First observed
security_audit - First observed
server_health - First observed
ssl_status
TDQS
Scored across 6 tools
Each tool has a clearly distinct purpose: listing SSH hosts, inventorying sites, reading logs, security auditing, health checks, and SSL status. There is no overlap in functionality.
All tool names use snake_case and follow a predictable pattern, though not all are verb_noun (e.g., security_audit, server_health, ssl_status are noun_noun). Overall consistent and readable.
Six tools is a well-scoped set for a VPS monitoring server, covering essential inspection operations without unnecessary bloat.
The tool set covers major inspection needs for a VPS (hosts, sites, logs, security, health, SSL). Missing action-oriented tools (e.g., restart, deploy), but the read-only focus is intentional and well-covered.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Nifty's MCP server — exposes tasks, projects, messages, and files as tools for AI agents.
- emisarOAuthdev.emisar
Let AI operate servers without SSH. Choose actions, approve risky changes, and audit every step.
Remote MCP server for supportsheep: run AI interviews and manage support content for your blog.
MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceA security-first MCP server that gives AI assistants controlled, safe access to manage remote servers via SSH with whitelisted operations and no generic command execution.MIT
- AlicenseNot gradedqualityCmaintenanceA secure, production-grade MCP server that provides filesystem operations, AST math evaluation, and system diagnostics for LLM agents.MIT

masaro-infra-mcpofficial
FlicenseNot gradedqualityCmaintenanceA secure MCP server providing read-only tools to interact with Cloudflare, Coolify, and other infrastructure services, enabling AI clients to safely diagnose and validate environments.-- AlicenseNot gradedqualityDmaintenanceA safe, configurable MCP server enabling AI agents to sync, deploy, diagnose, and compare remote servers via structured tools like rsync and SSH.525MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Akdag94/vps-ops-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server