Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
keyNoPath to private SSH key
hostYesHostname or IP of the Linux or Windows server
portNoSSH port (default: 22)22
userYesSSH username
timeoutNoCommand execution timeout in milliseconds (default: 60000ms = 1 minute)60000
maxCharsNoMaximum allowed characters for the command input (default: 1000). Use none or 0 to disable the limit.1000
passwordNoSSH password (or use key for key-based auth)
suPasswordNoPassword for su elevation (when you need a persistent root shell)
disableSudoNoFlag to disable the sudo-exec tool completely. Useful when sudo access is not needed or not available.
sudoPasswordNoPassword for sudo elevation (when executing commands with sudo)

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}
resources
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
list-connectionsA

List all configured SSH profiles and their connection status. Use this to discover available hosts before running commands.

list-sessionsB

List active sessions for a given SSH profile.

open-sessionA

Open a named session on a remote host. Use type="interactive" for stateful shell (CWD/env persists between commands) or type="background" for long-running processes.

close-sessionA

Close a named session. A background session's command is signalled on the host (INT, then TERM, then KILL) before its channel is dropped; an interactive session's shell is ended. The response says so if the command could not be signalled or had not stopped in time.

read-session-outputA

Read recent output from a background session (e.g., tail -f logs).

read-commandA

Execute a READ-ONLY command from an allowlist (ls, cat, grep, find, stat, df, etc.). This tool does NOT modify the system. Prefer this tool for all read operations.

run-commandA

Execute an arbitrary shell command on the remote server. May modify the system. Commands classified destructive or privileged go through the approval gate; approvalPolicy on the profile decides whether that is a prompt, an automatic allow, or a refusal.

privileged-commandA

Execute a command with sudo elevation. Goes through the approval gate; approvalPolicy on the profile decides whether that is a prompt, an automatic allow, or a refusal. The sudo password is piped via stdin (never visible in process list).

signal-processA

Send a signal (INT, TERM, KILL) to a remote process by PID.

sftp-uploadA

Upload a file to the remote server via SFTP (secure file transfer, not shell-based).

sftp-downloadA

Download a file from the remote server via SFTP.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription
connectionsList all SSH profiles and their connection status

TDQS

A3.7/5.0

Scored across 11 tools

Disambiguation4/5

Most tools are clearly distinct: read-command vs run-command vs privileged-command have clear boundaries (read-only vs arbitrary vs sudo). However, list-connections and list-sessions could be confused; both are about listing, but one lists profiles, the other sessions within a profile. The descriptions help, but the tool names are close.

Naming Consistency3/5

Tool names mix hyphenated (list-connections) and underscore conventions (open_session? Actually all are hyphenated). The naming pattern is verb-noun, e.g., list-connections, open-session, read-session-output, which is consistent. However, sftp-upload and sftp-download use a noun-verb pattern (sftp as noun, upload as verb) which is a minor deviation. Also, 'open-session' vs 'close-session' is symmetric, but 'read-session-output' is longer than others. Overall, mostly consistent but with a few deviations.

Tool Count4/5

11 tools is within the ideal range for an SSH MCP server. Each tool covers a distinct aspect: connection/session management, execution (read/run/privileged), signal, and file transfer. The count feels appropriate, neither sparse nor bloated.

Completeness4/5

The tool surface covers the main lifecycle: connection discovery, session management, command execution with safety tiers, signaling, and file transfer. Minor gaps exist: no explicit tool for listing files (though read-command can do it), no session cleanup aside from close-session, and no sftp directory operations. But agents can work around these with run-command/read-command.

Maintenance

ActivityActive
ResponsivenessResponsive