SSH — policy-gated remote access
SSH — policy-gated remote access is an MCP server that adds cloud and DevOps tools to AI assistants such as Claude Desktop, Claude Code and Cursor. Policy-gated, audited SSH for Linux and Windows hosts: roles, approvals, and an audit log. It has 782 GitHub stars, is released under the MIT license and runs locally with npx -y ssh-mcp.
- Needs API key
- Cloud & DevOps
- MIT
- Actively maintained
Install SSH — policy-gated remote access
Generated from the server's MCP registry entry. Replace your-value with your own values.
Claude Desktop
{
"mcpServers": {
"ssh-policy-gated-remote-access": {
"command": "npx",
"args": [
"-y",
"ssh-mcp"
],
"env": {
"SSH_MCP_PASSWORD": "your-value",
"SSH_MCP_PASSPHRASE": "your-value",
"SSH_MCP_SUDO_PASSWORD": "your-value"
}
}
}
}Settings > Developer > Edit Config. macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\. Restart Claude Desktop afterwards.
Claude Code
claude mcp add --env SSH_MCP_PASSWORD=your-value --env SSH_MCP_PASSPHRASE=your-value --env SSH_MCP_SUDO_PASSWORD=your-value --transport stdio ssh-policy-gated-remote-access -- npx -y ssh-mcpCursor
{
"mcpServers": {
"ssh-policy-gated-remote-access": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"ssh-mcp"
],
"env": {
"SSH_MCP_PASSWORD": "your-value",
"SSH_MCP_PASSPHRASE": "your-value",
"SSH_MCP_SUDO_PASSWORD": "your-value"
}
}
}
}Project file; use ~/.cursor/mcp.json to enable it in every project.
VS Code
{
"inputs": [
{
"type": "promptString",
"id": "ssh_mcp_password",
"description": "SSH_MCP_PASSWORD",
"password": true
},
{
"type": "promptString",
"id": "ssh_mcp_passphrase",
"description": "SSH_MCP_PASSPHRASE",
"password": true
},
{
"type": "promptString",
"id": "ssh_mcp_sudo_password",
"description": "SSH_MCP_SUDO_PASSWORD",
"password": true
}
],
"servers": {
"ssh-policy-gated-remote-access": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"ssh-mcp"
],
"env": {
"SSH_MCP_PASSWORD": "${input:ssh_mcp_password}",
"SSH_MCP_PASSPHRASE": "${input:ssh_mcp_passphrase}",
"SSH_MCP_SUDO_PASSWORD": "${input:ssh_mcp_sudo_password}"
}
}
}
}Config formats checked against the official docs on Oct 7, 2026: modelcontextprotocol.io (opens in a new tab), code.claude.com (opens in a new tab), cursor.com (opens in a new tab), code.visualstudio.com (opens in a new tab).
Environment variables
Variables the server reads at startup.
| Name | Required | Description |
|---|---|---|
SSH_MCP_PASSWORDsecret | No | Password for the configured profile; a per-profile SSHMCP_PASSWORD takes precedence. Credentials are never accepted as CLI arguments. |
SSH_MCP_KEY | No | Path to the private key file to authenticate with — the path, not the key material. A per-profile SSHMCP_KEY takes precedence. |
SSH_MCP_PASSPHRASEsecret | No | Passphrase for an encrypted private key. |
SSH_MCP_SUDO_PASSWORDsecret | No | Password the sudo tool escalates with, when the policy in force allows the privileged class. |
Tools (2)
Parsed from the Tools section of the README; check the repository for the current list.
execread-command
sudo-execprivileged-command
About SSH — policy-gated remote access
SSH MCP Server is a security-first Model Context Protocol server that gives LLM agents controlled SSH access to remote hosts — with command classification, policy-based authorization, human-in-the-loop approval, and full audit logging.
Similar MCP servers
More cloud & devops MCP servers
Worldmonitor
koala73/worldmonitor
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface.
Cloud & DevOpsTypeScriptNetdata
netdata/netdata
Real-time infrastructure monitoring with metrics, logs, alerts, and ML-based anomaly detection.
Cloud & DevOpsGoopenstatus
openstatusHQ/openstatus
Manage monitors, status pages, incidents and maintenances in your openstatus workspace.
OfficialCloud & DevOpsTypeScriptMCP Server Cloudflare
cloudflare/mcp-server-cloudflare
Model Context Protocol (MCP) is a new, standardized protocol for managing context between large language models (LLMs) and external systems.
OfficialCloud & DevOpsTypeScriptDagu
dagucloud/dagu
Self-hostable workflow orchestrator for teams whose main work isn't orchestration.
Cloud & DevOpsGoAzure MCP Server
microsoft/mcp
All Azure MCP tools to create a seamless connection between AI agents and Azure services.
OfficialCloud & DevOpsC#
What is SSH — policy-gated remote access?
SSH — policy-gated remote access is an MCP server that adds cloud and DevOps tools to AI assistants such as Claude Desktop, Claude Code and Cursor. Policy-gated, audited SSH for Linux and Windows hosts: roles, approvals, and an audit log. It has 782 GitHub stars, is released under the MIT license and runs locally with npx -y ssh-mcp. The source code is at github.com/tufantunc/ssh-mcp.
How do I install the SSH — policy-gated remote access MCP server?
Add the command npx -y ssh-mcp to your MCP client: put it in claude_desktop_config.json for Claude Desktop, run claude mcp add for Claude Code, or add it to .cursor/mcp.json (Cursor) or .vscode/mcp.json (VS Code). The snippets on this page are ready to paste.
Is SSH — policy-gated remote access free?
The server is open source under the MIT license, so running it is free. It needs credentials (SSH_MCP_PASSWORD, SSH_MCP_PASSPHRASE and SSH_MCP_SUDO_PASSWORD) for the service it connects to, which may require a paid account.
Is SSH — policy-gated remote access actively maintained?
The most recent commit was on Oct 4, 2026. The latest release is v2.18.0, published Oct 4, 2026. appsgit only lists MCP servers with a commit in the last six months and re-checks every server daily.