MCP SSH Server
Allows making secure reverse-proxy API requests to Nginx proxies (and other internal services) via the application_api_request tool, without exposing credentials to the AI agent.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@MCP SSH Servercheck disk space on node and tell me if we're running low"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
MCP SSH Server
A production-grade TypeScript MCP server that securely executes arbitrary commands on remote hosts via SSH.
Security Architecture
This project is designed to operate securely on a local network (LAN) behind an Nginx TLS reverse proxy. Authentication is handled natively through Google Identity Services (GSI) via a sleek authentication portal.
Generating an API Key
When the container is running, navigate to its exposed web UI (e.g., http://localhost:3000/login or your reverse proxy domain) in your browser.
Log in securely with your Google Account. If your email matches the ALLOWED_GOOGLE_EMAILS whitelist defined in Doppler, the server will instantly mint a long-lived JWT API Key.
Your MCP clients must then pass this exact string in their Authorization: Bearer <key> headers.
Secure SSH Execution
SSH private keys and connection parameters are managed dynamically via Doppler and fetched asynchronously by a background polling loop every 60 seconds. This allows you to instantly update or invalidate secrets in the Doppler dashboard without ever restarting the container.
To achieve <100ms execution latency, the Node.js server maintains these secrets in memory. When a request is received, the server:
Validates the host identifier against strict alphanumeric constraints (
^[a-zA-Z0-9_-]+$) and theALLOWED_SSH_HOSTSwhitelist.Constructs a tightly scoped, isolated environment containing only the private key and details for that specific requested host, minimizing the blast radius.
Spawns the
scripts/ssh-host.shwrapper, which loads the isolated key directly into a temporaryssh-agentin RAM and utilizes SSH Multiplexing (ControlMaster) to instantly execute the command.
Related MCP server: MCP SSH Orchestrator
Setup
npm installnpm run buildConfigure your local Doppler project:
doppler setup
Doppler Secret Configuration
This server strictly relies on a file-less runtime. Private keys and connection details are never saved to disk. To enable connections to a host, you must define the following three variables in your Doppler dashboard, matching your host identifier.
To connect to an SSH host (for example, with the identifier app-server), define:
APP-SERVER_USER: The SSH username (e.g.,root)APP-SERVER_HOST: The IP Address or Hostname (e.g.,10.0.0.50)APP-SERVER_KEY: The raw RSA/ED25519 private key contents
To prevent unauthorized execution, you must define the ALLOWED_SSH_HOSTS variable in Doppler as a comma-separated whitelist of host identifiers (e.g., app-server,db-server,backup).
Application API Proxy
The MCP Server also natively supports the application_api_request tool, which acts as a secure reverse-proxy for making API requests to internal services without exposing credentials directly to the AI agent.
Variables must follow the strict naming convention: <HOST>_<APP>_<SECRET_TYPE>
For static API key authentication (e.g., typical media stacks), set:
HOST_APP_URL: Base URL (e.g.,http://10.0.0.60:8080) -> Note: Do NOT include a trailing slash!HOST_APP_API_KEY: The static API Key
For stateful applications requiring session logins (e.g., download clients, Nginx proxies), set:
HOST_APP_URL: Base URL (e.g.,http://10.0.0.60:8181) -> Note: Do NOT include a trailing slash!HOST_APP_USERNAME: The web UI usernameHOST_APP_PASSWORD: The web UI password
Deployment
Ensure the container runs behind an Nginx reverse proxy providing HTTPS to encrypt the SSE MCP traffic.
Unraid
Use the provided unraid-template.xml to deploy via Docker to your Unraid host. The template configures the necessary volume mounts and prompts for the DOPPLER_TOKEN.
Linux (Ubuntu)
For a standard Linux host, use Docker Compose. First, copy the example environment file:
cp .env.example .envEdit the .env file to include your DOPPLER_TOKEN. Then, start the container:
docker compose up -dAI Use Disclaimer
Notice: This project, its architecture, and its source code were generated with the assistance of an AI coding agent. While the architecture is designed with security best practices in mind (such as file-less SSH key injection and strict API key validation), you should independently review and verify all security-critical components before using this in a production environment.
License
This project is licensed under the MIT License - see the LICENSE file for details.
This server cannot be deployed
Maintenance
Related MCP Connectors
Scoped, audited SSH exec, sessions, and SFTP on your saved servers without exposing credentials
- emisarOAuthdev.emisar
Let AI operate servers without SSH. Choose actions, approve risky changes, and audit every step.
Operate Linux, macOS and Windows from your LLM. Every action runs through an auditable allowlist.
Remote shell and detached long-running jobs on your own machines — no SSH, open ports or VPN.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables secure remote access operations through SSH, SFTP, rsync, VPN, and tunneling with enterprise-grade policy enforcement and audit logging. Provides AI assistants with secure, policy-driven access to remote systems while maintaining comprehensive audit trails and zero-trust security.1Apache 2.0
- AlicenseBqualityAmaintenanceProvides policy-driven, auditable SSH access to server fleets for AI assistants with zero-trust security controls, command whitelisting, and comprehensive audit logging to safely manage infrastructure.1328Apache 2.0
- AlicenseNot gradedqualityCmaintenanceEnables AI assistants to securely execute SSH commands on remote servers with connection pooling, session isolation, and a web audit panel.4MIT
- FlicenseNot gradedqualityBmaintenanceEnables executing SSH commands on arbitrary hosts using each user's personal SSH key for authentication, and generating new SSH keypairs on request.-