# SSH — policy-gated remote access (MCP server)

> SSH — policy-gated remote access is an MCP server that adds cloud and DevOps tools to AI assistants such as Claude Desktop, Claude Code and Cursor. Policy-gated, audited SSH for Linux and Windows hosts: roles, approvals, and an audit log. It has 782 GitHub stars, is released under the MIT license and runs locally with npx -y ssh-mcp.

SSH MCP Server is a security-first Model Context Protocol server that gives LLM agents controlled SSH access to remote hosts — with command classification, policy-based authorization, human-in-the-loop approval, and full audit logging.

## Key facts

| Fact | Value |
|---|---|
| Repository | https://github.com/tufantunc/ssh-mcp |
| GitHub stars | 782 |
| License | MIT |
| Language | TypeScript |
| Transport | stdio |
| Packages | npm: ssh-mcp |
| Remote URL | none |
| Needs API key | yes |
| Official | no |
| Works with | Claude Desktop, Claude Code, Cursor, VS Code |
| Category | Cloud & DevOps |
| Latest release | v2.18.0 (Oct 4, 2026) |
| Last commit | Oct 4, 2026 |
| MCP registry name | io.github.tufantunc/ssh-mcp |

## Install

### Claude Desktop (claude_desktop_config.json)

```json
{
  "mcpServers": {
    "ssh-policy-gated-remote-access": {
      "command": "npx",
      "args": [
        "-y",
        "ssh-mcp"
      ],
      "env": {
        "SSH_MCP_PASSWORD": "your-value",
        "SSH_MCP_PASSPHRASE": "your-value",
        "SSH_MCP_SUDO_PASSWORD": "your-value"
      }
    }
  }
}
```

Settings > Developer > Edit Config. macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\. Restart Claude Desktop afterwards.

### Claude Code

```sh
claude mcp add --env SSH_MCP_PASSWORD=your-value --env SSH_MCP_PASSPHRASE=your-value --env SSH_MCP_SUDO_PASSWORD=your-value --transport stdio ssh-policy-gated-remote-access -- npx -y ssh-mcp
```

### Cursor (.cursor/mcp.json)

```json
{
  "mcpServers": {
    "ssh-policy-gated-remote-access": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "ssh-mcp"
      ],
      "env": {
        "SSH_MCP_PASSWORD": "your-value",
        "SSH_MCP_PASSPHRASE": "your-value",
        "SSH_MCP_SUDO_PASSWORD": "your-value"
      }
    }
  }
}
```

Project file; use ~/.cursor/mcp.json to enable it in every project.

### VS Code (.vscode/mcp.json)

```json
{
  "inputs": [
    {
      "type": "promptString",
      "id": "ssh_mcp_password",
      "description": "SSH_MCP_PASSWORD",
      "password": true
    },
    {
      "type": "promptString",
      "id": "ssh_mcp_passphrase",
      "description": "SSH_MCP_PASSPHRASE",
      "password": true
    },
    {
      "type": "promptString",
      "id": "ssh_mcp_sudo_password",
      "description": "SSH_MCP_SUDO_PASSWORD",
      "password": true
    }
  ],
  "servers": {
    "ssh-policy-gated-remote-access": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "ssh-mcp"
      ],
      "env": {
        "SSH_MCP_PASSWORD": "${input:ssh_mcp_password}",
        "SSH_MCP_PASSPHRASE": "${input:ssh_mcp_passphrase}",
        "SSH_MCP_SUDO_PASSWORD": "${input:ssh_mcp_sudo_password}"
      }
    }
  }
}
```

Config formats checked against the official docs on 2026-10-07.

## Environment variables

- `SSH_MCP_PASSWORD` (secret): Password for the configured profile; a per-profile SSHMCP_PASSWORD takes precedence. Credentials are never accepted as CLI arguments.
- `SSH_MCP_KEY`: Path to the private key file to authenticate with — the path, not the key material. A per-profile SSHMCP_KEY takes precedence.
- `SSH_MCP_PASSPHRASE` (secret): Passphrase for an encrypted private key.
- `SSH_MCP_SUDO_PASSWORD` (secret): Password the sudo tool escalates with, when the policy in force allows the privileged class.

## Tools

- `exec`: read-command
- `sudo-exec`: privileged-command

## Similar MCP servers

- [Worldmonitor](https://appsgit.com/mcp-servers/worldmonitor): Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface. (87,920 stars, AGPL-3.0)
- [Netdata](https://appsgit.com/mcp-servers/netdata): Real-time infrastructure monitoring with metrics, logs, alerts, and ML-based anomaly detection. (80,817 stars, GPL-3.0, needs API key)
- [openstatus](https://appsgit.com/mcp-servers/openstatus): Manage monitors, status pages, incidents and maintenances in your openstatus workspace. (9,171 stars, AGPL-3.0, official)
- [MCP Server Cloudflare](https://appsgit.com/mcp-servers/mcp-server-cloudflare): Model Context Protocol (MCP) is a new, standardized protocol for managing context between large language models (LLMs) and external systems. (4,360 stars, Apache-2.0, official, needs API key)
- [Dagu](https://appsgit.com/mcp-servers/dagu): Self-hostable workflow orchestrator for teams whose main work isn't orchestration. (4,289 stars, GPL-3.0)
- [Azure MCP Server](https://appsgit.com/mcp-servers/azure-mcp-server): All Azure MCP tools to create a seamless connection between AI agents and Azure services. (3,738 stars, MIT, official)

---

Canonical page: https://appsgit.com/mcp-servers/ssh-policy-gated-remote-access
Source: appsgit (https://appsgit.com), the app store for github. Data from the GitHub API, refreshed nightly.
Machine access: JSON API https://appsgit.com/api/v1/apps (OpenAPI: https://appsgit.com/openapi.json), MCP server https://mcp.appsgit.com/mcp, full index https://appsgit.com/llms-full.txt.
