Model Context Protocol server for comprehensive SSH operations. Stateless architecture, Docker-ready
1.8K
A Model Context Protocol server for comprehensive SSH operations
Developed by XNet Inc. | Project Lead: Joshua S. Doucette
SSH MCP Server exposes comprehensive SSH functionality to AI assistants through the Model Context Protocol (MCP). It provides a stateless, production-ready solution for remote system management, file transfers, and secure tunneling.
Version: 0.2.0 (Stateless Design)
License: MIT
Repository: https://github.com/XNet-NGO/ssh-mcp-server
npm install @xnet-ngo/ssh-mcp-server
# From GitHub Container Registry (recommended)
docker pull ghcr.io/xnet-ngo/ssh-mcp-server:0.2.0
# Or use latest
docker pull ghcr.io/xnet-ngo/ssh-mcp-server:latest
Add to your MCP configuration:
{
"mcpServers": {
"ssh": {
"command": "docker",
"args": [
"run", "--rm", "-i",
"-v", "~/.ssh:/root/.ssh:ro",
"ghcr.io/xnet-ngo/ssh-mcp-server:0.2.0"
]
}
}
}
The SSH MCP Server uses a stateless wrapper-first approach, designed for ephemeral container environments:
// Session IDs are self-contained
sessionId = base64(JSON.stringify({
host: "example.com",
port: 22,
username: "user",
privateKey: "...", // or keyPath
config: { strictHostKeyChecking: false }
}))
Benefits:
docker run --rmssh-mcp-server/
├── src/
│ ├── core/ # Core functionality
│ │ ├── ConnectionManager.ts # Session management
│ │ ├── SSHWrapper.ts # SSH command wrapper
│ │ └── types.ts # Type definitions
│ ├── tools/ # MCP tool implementations
│ │ ├── ConnectionTools.ts # Connect/disconnect
│ │ ├── CommandExecutionTools.ts # Execute commands
│ │ ├── FileTransferTools.ts # SFTP operations
│ │ ├── KeyManagementTools.ts # Key operations
│ │ ├── PortForwardingTools.ts # SSH tunnels
│ │ └── ConfigurationTools.ts # SSH config
│ ├── mcp/ # MCP server setup
│ └── server.ts # Main entry point
├── tests/ # Test suite
├── docs/ # Documentation
│ ├── AI_USAGE_GUIDE.md # AI assistant guide
│ └── QUICK_REFERENCE.md # Quick reference
└── Dockerfile.ssh # Docker image
ssh_connect - Establish SSH connectionssh_disconnect - Close connectionssh_list_sessions - List active sessionsssh_execute - Execute remote commandssftp_upload - Upload filessftp_download - Download filessftp_list - List directory contentssftp_delete - Delete remote filesssh_keygen - Generate SSH key pairsssh_list_keys - List available keysssh_fingerprint - Get key fingerprintssh_port_forward - Create SSH tunnelssh_close_forward - Close tunnelssh_get_config - Get SSH configurationssh_set_option - Set SSH option// Connect
const conn = await ssh_connect({
host: "example.com",
username: "user",
privateKeyBase64: keyBase64,
config: { strictHostKeyChecking: false }
});
// Execute command
const result = await ssh_execute({
sessionId: conn.sessionId,
command: "uptime"
});
console.log(result.stdout);
// Output: 08:08:15 up 1 day, 1:43, 2 users, load average: 0.00, 0.00, 0.00
// Upload file
await sftp_upload({
sessionId: conn.sessionId,
localPath: "/local/config.json",
remotePath: "/etc/app/config.json"
});
// Download file
await sftp_download({
sessionId: conn.sessionId,
remotePath: "/var/log/app.log",
localPath: "/tmp/app.log"
});
// Create local forward
await ssh_port_forward({
sessionId: conn.sessionId,
type: "local",
localPort: 8080,
remoteHost: "localhost",
remotePort: 80
});
// Now access http://localhost:8080 to reach remote port 80
This server is optimized for use with Docker MCP Gateway:
{
"mcpServers": {
"MCP_DOCKER": {
"command": "docker",
"args": [
"mcp", "gateway", "run",
"--servers=ssh-mcp-server"
],
"autoApprove": ["*"]
}
}
}
Note: When using Docker MCP Gateway, use base64-encoded private keys to bypass secret detection:
const keyBase64 = Buffer.from(privateKeyContent).toString('base64');
# Clone repository
git clone https://github.com/XNet-NGO/ssh-mcp-server.git
cd ssh-mcp-server
# Install dependencies
npm install
# Build
npm run build
# Run tests
npm test
# Run in development
npm run dev
# Run all tests
npm test
# Run with coverage
npm run test:coverage
# Run in watch mode
npm run test:watch
# Lint code
npm run lint
# Format code
npm run format
# Build image
docker build -f Dockerfile.ssh -t ghcr.io/xnet-ngo/ssh-mcp-server:0.2.0 .
# Run container
docker run --rm -i \
-v ~/.ssh:/root/.ssh:ro \
ghcr.io/xnet-ngo/ssh-mcp-server:0.2.0
When using Docker MCP Gateway, private keys must be base64-encoded to bypass secret detection. Note: Base64 is NOT encryption - use only in trusted environments.
Permission denied (publickey)
~/.ssh/authorized_keysHost key verification failed
strictHostKeyChecking: false in configConnection timeout
connectTimeout in configSee Usage Guide for more troubleshooting tips.
We welcome contributions! Please see CONTRIBUTING.md for guidelines.
This project is licensed under the MIT License - see the LICENSE file for details.
Copyright (c) 2026 XNet Inc.
Copyright (c) 2026 Joshua S. Doucette
This project builds upon:
See CONTRIBUTORS.md for full attribution.
XNet Inc. is a non-governmental organization focused on developing open-source tools and infrastructure for secure communications and remote system management.
Website: https://xnet.ngo
GitHub: https://github.com/XNet-NGO
Project: SSH MCP Server
Version: 0.2.0
Copyright: © 2026 XNet Inc., Joshua S. Doucette
License: MIT
Repository: https://github.com/XNet-NGO/ssh-mcp-server
Content type
Image
Digest
sha256:e5b37ac9a…
Size
52.8 MB
Last updated
9 months ago
docker pull xnetadmin/openssh-mcp