Skip to content
appsgit

SSH — policy-gated remote access

SSH — policy-gated remote access is an MCP server that adds cloud and DevOps tools to AI assistants such as Claude Desktop, Claude Code and Cursor. Policy-gated, audited SSH for Linux and Windows hosts: roles, approvals, and an audit log. It has 782 GitHub stars, is released under the MIT license and runs locally with npx -y ssh-mcp.

github.com/tufantunc/ssh-mcp (opens in a new tab)

Install SSH — policy-gated remote access

Generated from the server's MCP registry entry. Replace your-value with your own values.

Claude Desktop

claude_desktop_config.json
{
  "mcpServers": {
    "ssh-policy-gated-remote-access": {
      "command": "npx",
      "args": [
        "-y",
        "ssh-mcp"
      ],
      "env": {
        "SSH_MCP_PASSWORD": "your-value",
        "SSH_MCP_PASSPHRASE": "your-value",
        "SSH_MCP_SUDO_PASSWORD": "your-value"
      }
    }
  }
}

Settings > Developer > Edit Config. macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\. Restart Claude Desktop afterwards.

Claude Code

claude mcp add --env SSH_MCP_PASSWORD=your-value --env SSH_MCP_PASSPHRASE=your-value --env SSH_MCP_SUDO_PASSWORD=your-value --transport stdio ssh-policy-gated-remote-access -- npx -y ssh-mcp

Cursor

.cursor/mcp.json
{
  "mcpServers": {
    "ssh-policy-gated-remote-access": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "ssh-mcp"
      ],
      "env": {
        "SSH_MCP_PASSWORD": "your-value",
        "SSH_MCP_PASSPHRASE": "your-value",
        "SSH_MCP_SUDO_PASSWORD": "your-value"
      }
    }
  }
}

Project file; use ~/.cursor/mcp.json to enable it in every project.

VS Code

.vscode/mcp.json
{
  "inputs": [
    {
      "type": "promptString",
      "id": "ssh_mcp_password",
      "description": "SSH_MCP_PASSWORD",
      "password": true
    },
    {
      "type": "promptString",
      "id": "ssh_mcp_passphrase",
      "description": "SSH_MCP_PASSPHRASE",
      "password": true
    },
    {
      "type": "promptString",
      "id": "ssh_mcp_sudo_password",
      "description": "SSH_MCP_SUDO_PASSWORD",
      "password": true
    }
  ],
  "servers": {
    "ssh-policy-gated-remote-access": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "ssh-mcp"
      ],
      "env": {
        "SSH_MCP_PASSWORD": "${input:ssh_mcp_password}",
        "SSH_MCP_PASSPHRASE": "${input:ssh_mcp_passphrase}",
        "SSH_MCP_SUDO_PASSWORD": "${input:ssh_mcp_sudo_password}"
      }
    }
  }
}

Config formats checked against the official docs on Oct 7, 2026: modelcontextprotocol.io (opens in a new tab), code.claude.com (opens in a new tab), cursor.com (opens in a new tab), code.visualstudio.com (opens in a new tab).

Environment variables

Variables the server reads at startup.

NameRequiredDescription
SSH_MCP_PASSWORDsecretNoPassword for the configured profile; a per-profile SSHMCP_PASSWORD takes precedence. Credentials are never accepted as CLI arguments.
SSH_MCP_KEYNoPath to the private key file to authenticate with — the path, not the key material. A per-profile SSHMCP_KEY takes precedence.
SSH_MCP_PASSPHRASEsecretNoPassphrase for an encrypted private key.
SSH_MCP_SUDO_PASSWORDsecretNoPassword the sudo tool escalates with, when the policy in force allows the privileged class.

Tools (2)

Parsed from the Tools section of the README; check the repository for the current list.

  • exec

    read-command

  • sudo-exec

    privileged-command

About SSH — policy-gated remote access

SSH MCP Server is a security-first Model Context Protocol server that gives LLM agents controlled SSH access to remote hosts — with command classification, policy-based authorization, human-in-the-loop approval, and full audit logging.

FAQ

SSH — policy-gated remote access FAQ

Still curious? Email info@appsgit.com.

What is SSH — policy-gated remote access?

SSH — policy-gated remote access is an MCP server that adds cloud and DevOps tools to AI assistants such as Claude Desktop, Claude Code and Cursor. Policy-gated, audited SSH for Linux and Windows hosts: roles, approvals, and an audit log. It has 782 GitHub stars, is released under the MIT license and runs locally with npx -y ssh-mcp. The source code is at github.com/tufantunc/ssh-mcp.

How do I install the SSH — policy-gated remote access MCP server?

Add the command npx -y ssh-mcp to your MCP client: put it in claude_desktop_config.json for Claude Desktop, run claude mcp add for Claude Code, or add it to .cursor/mcp.json (Cursor) or .vscode/mcp.json (VS Code). The snippets on this page are ready to paste.

Is SSH — policy-gated remote access free?

The server is open source under the MIT license, so running it is free. It needs credentials (SSH_MCP_PASSWORD, SSH_MCP_PASSPHRASE and SSH_MCP_SUDO_PASSWORD) for the service it connects to, which may require a paid account.

Is SSH — policy-gated remote access actively maintained?

The most recent commit was on Oct 4, 2026. The latest release is v2.18.0, published Oct 4, 2026. appsgit only lists MCP servers with a commit in the last six months and re-checks every server daily.