Claude Code + SSH through SSHive's MCP server
By Lucas Russo, developer of SSHive · Updated
Let Claude Code run commands on your servers, read remote files and check what is really deployed, through SSHive's local MCP server. One command to paste, no relay in between.
claude in your terminal, plus extensions for VS Code and JetBrains IDEs. It writes and refactors code well, but on its own it cannot see what runs on your servers. SSHive's built-in MCP server gives it that view on the Mac: every SSH and SFTP session open in SSHive becomes something Claude can use, over the connection SSHive already made, jump host chain included if the profile has one. Claude never receives your passwords or keys; SSHive does the connecting.
The server listens on 127.0.0.1 only. Claude Code proves who it is with a Bearer token that SSHive creates when you switch the server on and keeps until you regenerate it. Nothing relays the traffic: Claude Code talks to SSHive on your Mac, and SSHive talks to your servers. What Claude reads through those sessions does become part of the conversation, which Claude Code sends to Anthropic like the rest of your prompts. MCP is a Pro feature, and only the Mac app has it.Set up Claude Code with SSHive in 4 steps
- 1
Turn on the MCP server in SSHive
In SSHive on your Mac, open Settings > MCP and turn on "Enable MCP server". SSHive creates the Bearer token at that moment and starts listening on
http://127.0.0.1:49422/mcp(49422 is the default port). MCP is part of Pro. - 2
Copy the
claude mcp addcommand and run itThe same panel shows a command for Claude Code with your real token already in it; the one below has
<your-token>in its place. Paste it into Terminal. It first removes any oldersshiveentry, then registers SSHive at user scope, which Claude Code keeps in~/.claude.jsonand offers in every project. SSHive does not edit that file for you: an App Store app is not allowed to write another app's configuration.Copy thisclaude mcp remove sshive --scope user 2>/dev/null; claude mcp add --transport http --scope user sshive http://127.0.0.1:49422/mcp --header "Authorization:Bearer <your-token>"
- 3
Check that Claude Code sees SSHive
Run
claude mcp list:sshiveshould show as connected, and/mcpinside a Claude Code session says the same. SSHive offers 20 tools, described on the MCP page. The 3 tools that list your profiles and open or close sessions appear only once you turn on "Let the assistant open sessions" in Settings > MCP; until then Claude Code sees 17. - 4
Open the sessions Claude should see
Claude works on the sessions connected in SSHive. Open the prod, staging or database profiles you want it to reach; it finds them with
ssh_list_sessionsand runs commands withssh_execute. Close a session and Claude loses it, unless you let the assistant open sessions itself. Each command Claude runs, and each file it reads, writes, moves or deletes, appears in SSHive as a notification naming the tool and the command or path, so you can follow what Claude does.
What to ask Claude Code once connected
"Run df -h on the prod session and flag any volume above 80%."
Claude calls ssh_list_sessions to find prod, runs df -h through ssh_execute, reads the Use% column and names each volume past 80% with its mount point.
"Read the nginx config on staging and tell me which sites it serves."
Claude calls sftp_list on /etc/nginx/sites-enabled/, then sftp_read_file on each entry, and summarizes the server blocks and the domains they answer for.
"My deploy script just failed on prod. Check /var/log/deploy.log and tell me what went wrong."
Claude reads the log with sftp_read_file, or its last lines with tail through ssh_execute if it is over 1 MB, finds the failing step, compares it with the last successful run and gives the likely cause in plain words.
Why pair Claude Code with SSHive specifically
docker ps output back and forth, summarize log files for it and copy config blocks one screen at a time. With SSHive's server, Claude calls the tool, gets the live output, reasons over it and suggests a fix, and you stop translating between two terminals.
What sets this setup apart:
• It reuses the sessions you already have open. Handing Claude raw SSH credentials would put them in the model's context. SSHive gives it your authenticated sessions instead: Claude sees what the commands do, never the key.
• Nobody relays your SSH traffic. An SSH bridge hosted in the cloud would route the model's access through someone else's servers. SSHive's server listens on 127.0.0.1 and reaches your servers directly from your Mac. The only thing that leaves is what Claude reads, inside the conversation sent to Anthropic.
• One server for several clients. MCP is an open protocol, so the same SSHive server also works with Cursor and Claude Desktop, each set up once. For a whole working day on the Mac, from per-project profiles to deploy snippets, see the developer SSH workflow.Frequently asked questions
Does Claude see my SSH private keys?+
ssh_execute on a connected session, but no tool hands it a key or a password.Where does the traffic go?+
127.0.0.1 and refuses any request without the token. Between SSHive and your servers, over the SSH sessions SSHive opened, with no third party relaying them. What does leave the Mac is what Claude reads through those sessions: it goes into the conversation that Claude Code sends to Anthropic.Can Claude write files on my servers?+
sftp_write_file, sftp_edit_file, sftp_write_file_chunk and sftp_write_from_local_path write, and sftp_delete deletes. Whether Claude Code asks you before each call depends on your Claude Code permission settings. On the SSHive side, the assistant only works on sessions you opened, unless you turn on "Let the assistant open sessions".How do I change the token?+
sshive entry before adding the new one. Restarting SSHive, on the other hand, keeps the token as it is.Why is MCP on the Mac only?+
Other clients and related pages
Cursor + SSH through SSHive's MCP server
The AI code editor built on VS Code
Claude Desktop + SSH through SSHive's MCP server
Anthropic's desktop app for chatting with Claude
Try SSHive Free for macOS
Get the all-in-one SSH, SFTP, RDP and VNC client for Mac. Free download, no signup required.
Download SSHive Free