MCP server for secure SSH command execution on remote Linux systems. It allows MCP clients (like Claude Desktop) to execute commands on configured SSH hosts.
Important
This MCP server provides direct SSH access to remote systems. When enabled, it can execute commands on any configured SSH host.
- Only configure trusted SSH connections
- Use key-based authentication when possible
- Review SSH timeout and connection settings
- Consider security implications of remote access
See Configuration for more details.
- SSH Remote Execution: Execute commands on remote Linux systems via SSH
- Connection Management: Automatic connection pooling and reconnection
- Authentication Support: Both password and private key authentication
- Simple API: Just two tools -
ssh_executeandssh_disconnect - Configurable: Define multiple SSH connections with custom settings
npx mcp-sshnpm install -g mcp-sshAdd this to your claude_desktop_config.json:
{
"mcpServers": {
"ssh": {
"command": "npx",
"args": ["-y", "mcp-ssh"]
}
}
}For use with a specific config file:
{
"mcpServers": {
"ssh": {
"command": "npx",
"args": [
"-y",
"mcp-ssh",
"--config",
"/path/to/your/config.json"
]
}
}
}The server requires a configuration file to define SSH connections.
- Create a configuration file:
npx mcp-ssh --init-config ~/.mcp-ssh/config.json-
Edit the configuration file to add your SSH connections
-
Update your Claude Desktop configuration to use the config file
{
"ssh": {
"enabled": true,
"defaultTimeout": 30,
"maxConcurrentSessions": 5,
"keepaliveInterval": 10000,
"keepaliveCountMax": 3,
"readyTimeout": 20000,
"connections": {
"my-server": {
"host": "192.168.1.100",
"port": 22,
"username": "myuser",
"password": "mypassword"
},
"production": {
"host": "prod.example.com",
"port": 22,
"username": "deploy",
"privateKeyPath": "/home/user/.ssh/id_rsa"
}
}
}
}enabled(boolean): Must betruefor the server to functiondefaultTimeout(number): Default command execution timeout in seconds (default: 30)maxConcurrentSessions(number): Maximum concurrent SSH sessions (default: 5)keepaliveInterval(number): Keepalive packet interval in milliseconds (default: 10000)keepaliveCountMax(number): Maximum keepalive failures before disconnect (default: 3)readyTimeout(number): Connection establishment timeout in milliseconds (default: 20000)
Each connection in the connections object has:
host(string, required): Hostname or IP addressport(number, required): SSH port (default: 22)username(string, required): SSH usernamepassword(string, optional): Password for authenticationprivateKeyPath(string, optional): Path to private key filekeepaliveInterval(number, optional): Override global keepalive intervalkeepaliveCountMax(number, optional): Override global keepalive countreadyTimeout(number, optional): Override global ready timeout
Note: You must provide either password or privateKeyPath for authentication.
The server looks for configuration in these locations (in order):
- Path specified by
--configflag ./config.jsonin current directory~/.mcp-ssh/config.jsonin user's home directory
Execute a command on a remote system via SSH.
Input:
connectionId(string): ID of the SSH connection to usecommand(string): Command to execute
Returns: Command output as text, or error message if execution fails
Example:
{
"connectionId": "my-server",
"command": "ls -la /var/log"
}Disconnect from an SSH server.
Input:
connectionId(string): ID of the SSH connection to disconnect
Returns: Confirmation message
Example:
{
"connectionId": "my-server"
}- Authentication: Store private keys securely and use appropriate file permissions (600)
- Network Security: Use SSH keys instead of passwords when possible
- Connection Limits: Configure appropriate timeouts and connection limits
- Host Verification: The server currently does not verify host keys (accepts any host)
- Command Execution: All commands are executed with the privileges of the SSH user
git clone https://github.com/your-username/mcp-ssh.git
cd mcp-ssh
npm install
npm run buildnpm testnpm run watchThis project is licensed under the MIT License - see the LICENSE file for details.