Terminal MCP Server
Allows setting up a persistent tunnel using Cloudflare named tunnel for exposing the MCP server with a stable hostname.
Allows setting up a tunnel using ngrok with a reserved domain for a stable tunnel URL to expose the MCP server.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Terminal MCP Serverlist files in the current directory"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Terminal MCP Server
HTTP MCP server that exposes authenticated shell tools so grok.com can run commands on this machine.
Quick start
cd /root/terminal-mcp
cp .env.example .env
# Set TERMINAL_MCP_TOKEN: openssl rand -hex 32
chmod +x scripts/*.sh
./scripts/start.sh
curl http://127.0.0.1:3001/healthRelated MCP server: Remote MCP Server
grok.com setup
Set tunnel mode in
.env:TERMINAL_MCP_TUNNEL_MODE=trueRestart:
./scripts/stop.sh && ./scripts/start.shTunnel:
./scripts/tunnel.sh— copy the URL and setTERMINAL_MCP_TUNNEL_HOSTRestart again after setting tunnel host
Register at grok.com/connectors → Custom:
URL:
https://<tunnel-host>/mcpAuth:
Bearer <TERMINAL_MCP_TOKEN>
Stable tunnel URLs
ngrok paid: reserved domain — set
TERMINAL_MCP_TUNNEL_HOSTonceCloudflare named tunnel: Cloudflare Tunnel docs — persistent hostname
Tools
Tool | Description |
| Run shell command ( |
| Poll background job (supports |
| List all jobs |
| Terminate background job |
| Environment and policy summary |
Resources
terminal://tasks/{task_id}/log— task output log
Security
Configured in config.toml:
mode:blocklist(default),allowlist, orpermissiveCommand blocklist / allowlist
Webhook approval for destructive commands (
[security.webhook])Sanitized child environment (no inherited secrets)
Audit log:
logs/audit.jsonl
systemd
sudo cp deploy/terminal-mcp.service /etc/systemd/system/
sudo systemctl enable --now terminal-mcpTests
.venv/bin/pip install -e ".[dev]"
.venv/bin/pytest -qLocal Grok CLI
grok mcp add terminal --transport http \
--header "Authorization=Bearer ${TERMINAL_MCP_TOKEN}" \
http://127.0.0.1:3001/mcpThis server cannot be deployed
Maintenance
Related MCP Connectors
I run shell commands on your private cloud environment (bash, sh, zsh)
1Operate Linux, macOS and Windows from your LLM. Every action runs through an auditable allowlist.
Remote shell and detached long-running jobs on your own machines — no SSH, open ports or VPN.
Your workspace as agent tools — docs, canvases, slides, sheets, projects, tickets, and a shell.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceEnables AI assistants to securely execute shell commands on local machines through an SSH interface with session management, command execution, and sudo support.1-
- FlicenseNot gradedqualityDmaintenanceEnables AI tools like Claude to interact with a remote machine's file system and shell via a secure HTTPS endpoint. It provides standardized tools for executing shell commands, reading and writing files, and navigating directories.-
- AlicenseNot gradedqualityDmaintenanceEnables executing shell commands on the host system via an MCP tool, with JWT/OAuth authentication and audit logging for secure remote access.1MIT
- AlicenseNot gradedqualityCmaintenanceProvides AI agents with an unrestricted VPS root shell by executing arbitrary shell commands and returning structured results such as exit code, stdout, stderr, timeout, and truncation status.15MIT