Skip to main content
macOS only · Pro
Anthropic's coding assistant, in the terminal and the IDE

Claude Code + SSH through SSHive's MCP server

By Lucas Russo, developer of SSHive · Updated

Let Claude Code run commands on your servers, read remote files and check what is really deployed, through SSHive's local MCP server. One command to paste, no relay in between.

Claude Code is Anthropic's coding assistant: claude in your terminal, plus extensions for VS Code and JetBrains IDEs. It writes and refactors code well, but on its own it cannot see what runs on your servers. SSHive's built-in MCP server gives it that view on the Mac: every SSH and SFTP session open in SSHive becomes something Claude can use, over the connection SSHive already made, jump host chain included if the profile has one. Claude never receives your passwords or keys; SSHive does the connecting. The server listens on 127.0.0.1 only. Claude Code proves who it is with a Bearer token that SSHive creates when you switch the server on and keeps until you regenerate it. Nothing relays the traffic: Claude Code talks to SSHive on your Mac, and SSHive talks to your servers. What Claude reads through those sessions does become part of the conversation, which Claude Code sends to Anthropic like the rest of your prompts. MCP is a Pro feature, and only the Mac app has it.

Set up Claude Code with SSHive in 4 steps

  1. 1

    Turn on the MCP server in SSHive

    In SSHive on your Mac, open Settings > MCP and turn on "Enable MCP server". SSHive creates the Bearer token at that moment and starts listening on http://127.0.0.1:49422/mcp (49422 is the default port). MCP is part of Pro.

  2. 2

    Copy the claude mcp add command and run it

    The same panel shows a command for Claude Code with your real token already in it; the one below has <your-token> in its place. Paste it into Terminal. It first removes any older sshive entry, then registers SSHive at user scope, which Claude Code keeps in ~/.claude.json and offers in every project. SSHive does not edit that file for you: an App Store app is not allowed to write another app's configuration.

    Copy this
    claude mcp remove sshive --scope user 2>/dev/null; claude mcp add --transport http --scope user sshive http://127.0.0.1:49422/mcp --header "Authorization:Bearer <your-token>"
  3. 3

    Check that Claude Code sees SSHive

    Run claude mcp list: sshive should show as connected, and /mcp inside a Claude Code session says the same. SSHive offers 20 tools, described on the MCP page. The 3 tools that list your profiles and open or close sessions appear only once you turn on "Let the assistant open sessions" in Settings > MCP; until then Claude Code sees 17.

  4. 4

    Open the sessions Claude should see

    Claude works on the sessions connected in SSHive. Open the prod, staging or database profiles you want it to reach; it finds them with ssh_list_sessions and runs commands with ssh_execute. Close a session and Claude loses it, unless you let the assistant open sessions itself. Each command Claude runs, and each file it reads, writes, moves or deletes, appears in SSHive as a notification naming the tool and the command or path, so you can follow what Claude does.

What to ask Claude Code once connected

You ask

"Run df -h on the prod session and flag any volume above 80%."

What happens

Claude calls ssh_list_sessions to find prod, runs df -h through ssh_execute, reads the Use% column and names each volume past 80% with its mount point.

You ask

"Read the nginx config on staging and tell me which sites it serves."

What happens

Claude calls sftp_list on /etc/nginx/sites-enabled/, then sftp_read_file on each entry, and summarizes the server blocks and the domains they answer for.

You ask

"My deploy script just failed on prod. Check /var/log/deploy.log and tell me what went wrong."

What happens

Claude reads the log with sftp_read_file, or its last lines with tail through ssh_execute if it is over 1 MB, finds the failing step, compares it with the last successful run and gives the likely cause in plain words.

Why pair Claude Code with SSHive specifically

Claude Code does its best work with real context. Without MCP you paste docker ps output back and forth, summarize log files for it and copy config blocks one screen at a time. With SSHive's server, Claude calls the tool, gets the live output, reasons over it and suggests a fix, and you stop translating between two terminals. What sets this setup apart: • It reuses the sessions you already have open. Handing Claude raw SSH credentials would put them in the model's context. SSHive gives it your authenticated sessions instead: Claude sees what the commands do, never the key. • Nobody relays your SSH traffic. An SSH bridge hosted in the cloud would route the model's access through someone else's servers. SSHive's server listens on 127.0.0.1 and reaches your servers directly from your Mac. The only thing that leaves is what Claude reads, inside the conversation sent to Anthropic. • One server for several clients. MCP is an open protocol, so the same SSHive server also works with Cursor and Claude Desktop, each set up once. For a whole working day on the Mac, from per-project profiles to deploy snippets, see the developer SSH workflow.

Frequently asked questions

Does Claude see my SSH private keys?+
No. The MCP server gives Claude the sessions, not the credentials. Your passwords, keys and passphrases stay in SSHive, encrypted with a key kept in the macOS Keychain. Claude can run ssh_execute on a connected session, but no tool hands it a key or a password.
Where does the traffic go?+
Between Claude Code and SSHive, over your Mac's loopback interface: the server listens on 127.0.0.1 and refuses any request without the token. Between SSHive and your servers, over the SSH sessions SSHive opened, with no third party relaying them. What does leave the Mac is what Claude reads through those sessions: it goes into the conversation that Claude Code sends to Anthropic.
Can Claude write files on my servers?+
Yes. sftp_write_file, sftp_edit_file, sftp_write_file_chunk and sftp_write_from_local_path write, and sftp_delete deletes. Whether Claude Code asks you before each call depends on your Claude Code permission settings. On the SSHive side, the assistant only works on sessions you opened, unless you turn on "Let the assistant open sessions".
How do I change the token?+
In Settings > MCP, use "Regenerate" and confirm. The old token stops working, including in the command you ran earlier. Copy the new command from the same panel and run it again: it removes the old sshive entry before adding the new one. Restarting SSHive, on the other hand, keeps the token as it is.
Why is MCP on the Mac only?+
An MCP client has to reach the server whenever it calls a tool, so the server must keep running, and iOS suspends apps in the background. The MCP server therefore lives in the Mac app only. The iPhone and iPad app still covers SSH, SFTP, RDP, VNC, VPN, tunnels and network tools; broadcast, like MCP, stays on the Mac.

Other clients and related pages

Try SSHive Free for macOS

Get the all-in-one SSH, SFTP, RDP and VNC client for Mac. Free download, no signup required.

Download SSHive Free