SSH MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| key | No | Path to private SSH key | |
| host | Yes | Hostname or IP of the Linux or Windows server | |
| port | No | SSH port (default: 22) | 22 |
| user | Yes | SSH username | |
| timeout | No | Command execution timeout in milliseconds (default: 60000ms = 1 minute) | 60000 |
| maxChars | No | Maximum allowed characters for the command input (default: 1000). Use none or 0 to disable the limit. | 1000 |
| password | No | SSH password (or use key for key-based auth) | |
| suPassword | No | Password for su elevation (when you need a persistent root shell) | |
| disableSudo | No | Flag to disable the sudo-exec tool completely. Useful when sudo access is not needed or not available. | |
| sudoPassword | No | Password for sudo elevation (when executing commands with sudo) |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| resources | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list-connectionsA | List all configured SSH profiles and their connection status. Use this to discover available hosts before running commands. |
| list-sessionsB | List active sessions for a given SSH profile. |
| open-sessionA | Open a named session on a remote host. Use type="interactive" for stateful shell (CWD/env persists between commands) or type="background" for long-running processes. |
| close-sessionA | Close a named session. A background session's command is signalled on the host (INT, then TERM, then KILL) before its channel is dropped; an interactive session's shell is ended. The response says so if the command could not be signalled or had not stopped in time. |
| read-session-outputA | Read recent output from a background session (e.g., tail -f logs). |
| read-commandA | Execute a READ-ONLY command from an allowlist (ls, cat, grep, find, stat, df, etc.). This tool does NOT modify the system. Prefer this tool for all read operations. Single-line only: a command containing a line break is refused, so upload a multi-line script with sftp-upload and run it by path. |
| run-commandA | Execute an arbitrary shell command on the remote server. May modify the system. Commands classified destructive or privileged go through the approval gate; approvalPolicy on the profile decides whether that is a prompt, an automatic allow, or a refusal. Single-line only: a command containing a line break is refused, so upload a multi-line script with sftp-upload and run it by path. |
| privileged-commandA | Execute a command with sudo elevation. Goes through the approval gate; approvalPolicy on the profile decides whether that is a prompt, an automatic allow, or a refusal. The sudo password is piped via stdin (never visible in process list). Single-line only: a command containing a line break is refused, so upload a multi-line script with sftp-upload and run it by path. |
| signal-processA | Send a signal (INT, TERM, KILL) to a remote process by PID. |
| sftp-uploadA | Upload a file to the remote server via SFTP (secure file transfer, not shell-based). Replaces an existing file at that path unconditionally — there is no overwrite flag and no way to require a new destination. |
| sftp-downloadB | Download a file from the remote server via SFTP. |
| sftp-listA | List a remote directory over SFTP, with a bounded number of entries and a bounded response size. Read-only. |
| sftp-upload-fileA | Upload a local file to the remote host over SFTP, streaming it without passing the contents through model context. The local file must be inside the transferRoot directory the operator configured; without that setting this tool refuses. Use this for binary or large files; use sftp-upload for short text you already have. |
| sftp-download-fileA | Download a remote file to local disk over SFTP, streaming it without passing the contents through model context. The destination must be inside the transferRoot directory the operator configured; without that setting this tool refuses. Use this for binary or large files; use sftp-download when you need to read the contents. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| connections | List all SSH profiles and their connection status |
TDQS
Scored across 14 tools
Tools are mostly distinct, but sftp-upload and sftp-upload-file (and similarly download) have overlapping purposes; however, their descriptions clearly differentiate by use case (text content vs. streaming files). run-command and privileged-command are also similar but clearly separated by privilege level.
All tools use lowercase hyphenated names, but there are two patterns: verb-first (list-sessions, open-session) and sftp-prefixed (sftp-upload, sftp-download). This is consistent within groups, though not a single uniform verb_noun pattern, making it slightly inconsistent.
14 tools cover a broad range of SSH operations—session management, command execution, file transfer, process signaling—without being excessive. Each tool serves a clear purpose, and the count feels well-scoped for the domain.
The tool set covers most common SSH workflows, but there is a notable gap: open-session creates an interactive/stateful session, yet there is no tool to send commands into that session. This limits the usefulness of interactive sessions and represents a missing lifecycle operation.