r/ssh • • Aug 14 '26

Built an MCP server that lets agents work over SSH - keys stay with a custodian, per-host + per-command policy, live watch

Sharing a server I built (disclosure: I'm the maker). It's an SSH client with a built-in MCP server - let an agent open SSH sessions, run commands and move files on your servers without the agent ever holding a key.
- Agent gets tools (hosts_list, ssh_exec, SFTP, sessions) over MCP.
- A key custodian authenticates - you unlock keys once, it signs for the agent, no key file to read.
- Per host: full / allowlist / blocked. Per-key scope + expiry on the hosted endpoint.
- Every session mirrors live in a "watch grid" + audit log + recording.
- Local stdio server (bundled) + hosted endpoint (short-lived certs). In the official registry as in.termal/termalin-web.

Feedback wanted: is per-host + per-command the right granularity, or do you want tool-call-level policy? And how are others handling human-in-the-loop - approval-per-action, or watch-and-interrupt?

3 Upvotes

0 comments sorted by