MCP SSH Gateway
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@MCP SSH GatewayList my SSH hosts, then run uname -a on lab."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
MCP SSH Gateway
Use your MCP client to work with several SSH hosts through one local connection. Run diagnostics on a VPS, inspect a NAS or query a Keenetic router by name. Sessions preserve terminal state between calls; long output can be read a page at a time.
For people who already use SSH and want an assistant to help with routine diagnostics and administration. It is not an SSH daemon, a hosted proxy or a replacement for access controls on your servers.
Try it with one host
You need Python 3.11+, an SSH account on a host you control and an MCP client that can launch a local stdio server.
Create a working directory for the gateway configuration and install the published package into an isolated environment. The virtual environment keeps this install separate from other Python tools:
mkdir ssh-gateway && cd ssh-gateway python -m venv .venv # Windows PowerShell: .venv\Scripts\Activate.ps1 # macOS/Linux: source .venv/bin/activate python -m pip install --upgrade pip python -m pip install mcp-ssh-gateway mcp-ssh-gateway --helpThis installs the current release from PyPI and checks that the command is available. Create servers.json in this directory before starting the gateway; without configuration, startup exits with an error. For a disposable launch without a persistent install, use
uvx --from mcp-ssh-gateway mcp-ssh-gateway --help; to use a config file, replace--helpwith--servers-config /absolute/path/to/servers.json.To work on the project source instead, clone it and install development dependencies:
git clone https://github.com/d00mus/MCP-SSH.git && cd MCP-SSH && python -m pip install -r requirements.txtCreate a
servers.jsonin this working directory (replace the address, user and key path with your own):{ "servers": { "lab": { "host": "192.168.1.10", "user": "your-ssh-user", "key_path": "~/.ssh/id_ed25519" } } }Host-key verification is enabled by default and uses the machine’s system host-key store. Ensure the host key is already trusted there, and verify its fingerprint independently before adding it. For password authentication, use
"password": "${LAB_SSH_PASSWORD}"and provideLAB_SSH_PASSWORDto the MCP server process. Do not commit real credentials or yourservers.json. See the security policy.Add this to a client that uses the
mcpServersconfig format. Replace the absolute path: clients do not necessarily start in your working directory.{ "mcpServers": { "ssh-gateway": { "command": "mcp-ssh-gateway", "args": ["--servers-config", "/absolute/path/to/servers.json"] } } }On Windows, point
commandatmcp-ssh-gateway.exein your PythonScriptsdirectory if the client does not resolve it fromPATH, and use escaped backslashes in JSON paths (for exampleC:\\Users\\you\\servers.json).Running the command directly is not an interactive SSH terminal: it communicates with the client over stdio. Restart the MCP client after updating its config.
In the client, ask: “List my SSH hosts, then run
uname -aon lab.” If the host is missing, check the config path and the client's MCP server logs. If SSH fails, check credentials and host-key verification.
Add more hosts under servers in the same file. servers.json.example shows a multi-host configuration; check its host-key and credential choices before copying it. For a clean-directory installation check that does not depend on the repository clone, follow the PyPI smoke-test steps.
Related MCP server: mcp-remote-control
What using it looks like
A Linux host and a router can share one MCP connection. Your client makes calls like these (they are not terminal commands):
server_list() # find configured hosts
run(server="lab", command="df -h") # inspect disk space
run(server="keenetic", command="show interface", shell=false) # router CLIrun returns a session_id; pass it to later calls if you need the same terminal state. Without it an idle session may be reused with unknown state; new_session: true forces a clean session. A command still running after the initial wait (5 seconds by default) reports still_running: true. Use read(session_id="...") for later output, or whenever has_more indicates unread lines. signal(action="ctrl_c") interrupts a stuck command. Non-zero exits report completed_nonzero and exit_status, not silent success.
The file tool can inspect and edit remote files through SFTP (with shell fallback). Review edits and give an assistant only the SSH permissions it needs.
When to use it
Multiple hosts: one MCP server configuration routes calls to named targets. For just one host, this matters less.
Multi-step troubleshooting: persistent sessions keep shell state, while line-based output windows avoid dumping an entire log into the conversation at once.
A Keenetic alongside Linux hosts:
shell: falsesends device CLI commands without a POSIX shell; common pagers such as--More--are handled. Keenetic NDM is a supported use case, but other vendor CLIs are not guaranteed. Keep NDM CLI and Linux shell operations in separate sessions.
Security boundary: read_only and command blacklists are best-effort guardrails against mistakes, not a sandbox. Shell expansion and interpreters can bypass checks on command text. Use restricted SSH users and server-side permissions for sensitive hosts. Host-key verification is on by default; avoid turning it off casually.
The SSH connection originates from the machine running the gateway. This project works with MCP clients that can start a stdio server; it does not add SSH access to a chat app without MCP integration.
Other ways to run it
Docker (build from this clone):
docker build -t mcp-ssh-server .
docker run -i --rm \
-v /absolute/path/to/servers.json:/app/servers.json:ro \
-v /absolute/path/to/your/.ssh:/root/.ssh:ro \
mcp-ssh-server --servers-config /app/servers.jsonUse absolute mount paths and pass required environment variables with -e NAME. This example exposes SSH keys to the container; mount only what it needs. For an MCP client using Docker, set command to docker and put the same run arguments in args.
PyPI / MCP Registry: The package is published as mcp-ssh-gateway and listed in the MCP Registry as io.github.d00mus/mcp-ssh-gateway, so pip install mcp-ssh-gateway and uvx --from mcp-ssh-gateway ... work. See the release process.
Configuration and tools
Each target has an alias,
host,user, optionalport(default 22) and akey_pathorpassword.verify_hostdefaults totrue.passwordandkey_passphrasesupport environment references (${NAME}); missing references fail at startup.The default full profile exposes
server_list,server_add,run,read,signal,file,session_list,session_update,session_closeandlast_command_details.server_addaccepts analiasand only appends new targets.--tool-profile leanexposes six everyday tools for a smaller catalog.Changes to
servers.jsonare checked periodically (every 30 seconds);server_list(reload=true)checks immediately. Unchanged hosts keep their sessions; removing a host or changing its address, login or host-key settings closes that host’s active sessions.--log-output meta(the default) records lifecycle information and command text.fullalso records raw output;offdisables logging. Consider what secrets might appear in commands and output.
For contributions or vulnerabilities, see CONTRIBUTING.md and SECURITY.md.
Development
python -m unittest discover -s tests -t .This server cannot be deployed
Maintenance
Related MCP Connectors
Run commands and read/write files on your servers over Termalin's keyless tunnels (hosted MCP).
Scoped, audited SSH exec, sessions, and SFTP on your saved servers without exposing credentials
Governed MCP gateway: one endpoint for your tools, with credential custody and audit log.
Securely control computers you explicitly pair through files, terminals, processes, screenshots, desktop UI/input, clipboard, browser automation, diagnostics, and document tools.
Related MCP Servers
- AlicenseAqualityBmaintenanceSSH Session MCP fills a gap in the MCP ecosystem by offering a persistent shared SSH PTY runtime, not just stateless command execution. It features browser collaboration, input locking, safe/full execution modes, async command tracking, configurable policy rules, and multi-device profiles. Ideal for remote development, embedded systems, infrastructure workflows, and hardware control scenarios.2337 npm4Apache 2.0
- AlicenseAqualityAmaintenanceManage local/SSH/WinRM remote hosts via MCP, providing tools for exec, filesystem, screen, process, serial console, and configuration.7Apache 2.0
- AlicenseNot gradedqualityBmaintenanceProvides MCP clients with a persistent SSH shell on legacy Unix hosts, including session management, SFTP file transfer, and ClearCase workflow helpers.13,727 npmMIT
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to manage an entire fleet of servers over SSH through MCP, fanning a single intent out across many hosts with target expressions while enforcing a policy engine, approval gates, and tamper-evident audit logs. Supports rolling execution with circuit breakers, cross-host diffing, bulk file transfer, tmux sessions, and YAML workflows.5 npm12AGPL 3.0