Skip to main content

Built-in MCP server: your SSH servers, reachable from Claude Code and Cursor on Mac

SSHive includes a built-in MCP server that lets Claude Code, Cursor, and Claude Desktop interact with your SSH and SFTP sessions, directly from your machine.

MCP Server ActiveCopy-paste setupLocal & Secure
SSHive, Settings / MCP

MCP Server (Model Context Protocol)

Lets AI assistants (Claude, Cursor, Cline…) access active SSH sessions.

Enable MCP server
Starts a local HTTP server on 127.0.0.1
Active
Port
49422
Token Bearer
988ca074-565f-444a-918…
Compatible clients
Claude CodeCursorClaude Desktop

Model Context Protocol, the bridge between AI and your infrastructure

MCP (Model Context Protocol) is an open standard created by Anthropic that allows AI assistants to interact with external tools and data sources. SSHive implements an MCP server that exposes your active SSH and SFTP sessions as tools, so Claude can execute commands, read files, and browse your remote servers without leaving the conversation.

Instant access

No copy-paste, no context switching. Your AI assistant directly queries your servers through SSHive's active sessions.

Local server only

The MCP server listens on 127.0.0.1 only and asks for the Bearer token on every request. No SSHive relay sits in between; what your AI client reads, that client sends to its own model provider.

Copy-paste setup

Enable MCP in Settings, then copy the JSON config into your AI client. Claude Code users can run a single CLI command.

Claude Code, Terminal
claude>List all running Docker containers on my production server
Using SSHive MCP to access session "NMS"…
ssh_execute
session: "NMS"  command: "docker ps --format 'table {{.Names}}\t{{​.Status}}'"
Result
NAMES            STATUS
api-gateway      Up 14 days
web-frontend     Up 14 days
postgres-db      Up 14 days
Your production server has 3 containers running: api-gateway, web-frontend, and postgres-db, all up for 14 days with no issues.

Execute commands through natural language

Ask Claude to check Docker containers, view logs, restart services, or run any command on your remote servers. SSHive's MCP server bridges the conversation to your live SSH sessions.

  • Claude picks the right session automatically from your active connections
  • Full stdout/stderr output returned directly in the conversation
  • Works with any SSH session, no special server-side setup needed

Browse and read remote files with AI

Claude can list directories, read configuration files, and even write files on your remote servers through SSHive's SFTP tools. Perfect for debugging config issues or reviewing logs.

  • List directory contents on any active SFTP session
  • Read remote files, configs, logs, scripts, directly in Claude's context
  • Write files back to the server for quick fixes
Claude Code, SFTP via MCP
claude>Show me the Nginx config for the API
sftp_list
session: "NMS"  path: "/etc/nginx/sites-enabled/"
sftp_read_file
session: "NMS"  path: "/etc/nginx/sites-enabled/api.conf"
server {
    listen 443 ssl;
    server_name api.example.com;
    location / {
        proxy_pass http://127.0.0.1:3000;
    }
}
Your API reverse proxy is configured on api.example.com (port 443) and forwards traffic to localhost:3000. The SSL configuration looks standard.

20 tools for full server access

Each tool maps to a specific SSH or SFTP operation, giving AI assistants precise control over your remote servers. The main ones are below; ssh_list_profiles, ssh_connect and ssh_disconnect only appear if you let the assistant open sessions.

ssh_list_sessions

Lists all active SSH sessions with host, user, port, and connection status.

ssh_execute

Executes a command on a specific SSH session and returns stdout/stderr.

sftp_list

Lists files and directories at a given path on a remote server.

sftp_read_file

Reads the content of a remote file and returns it as text.

sftp_write_file

Writes content to a file on the remote server (in-memory).

sftp_write_file_chunk

Appends base64 chunks (4 MB each) for large files.

sftp_write_from_local_path

Sends a local file straight from disk to the server, with no base64, up to 32 MB per call; above that, sftp_upload_start takes over in the background.

  • ssh_list_profiles
  • ssh_connect
  • ssh_disconnect
  • sftp_edit_file
  • sftp_upload_start
  • sftp_download_start
  • sftp_transfer_status
  • sftp_transfer_cancel
  • sftp_download_to_local_path
  • sftp_mkdir
  • sftp_chmod
  • sftp_rename
  • sftp_delete

What fits in one call, and what streams

Each file tool is built for a size of job:

  • sftp_read_file, sftp_write_file and sftp_edit_file handle UTF-8 text up to 1 MB. Past that, or for a binary file, the assistant switches to the transfer tools.
  • sftp_write_file_chunk writes content that exists only in the conversation, in blocks of up to 4 MB each.
  • sftp_write_from_local_path sends a file straight from your Mac's disk to the server and waits for the transfer to finish, for files up to 32 MB; above that it refuses and points the assistant to sftp_upload_start. sftp_download_to_local_path does the reverse, with no size limit. Either way, the file never passes through the model's context.
  • sftp_upload_start and sftp_download_start move a file of any size in the background and return at once; sftp_transfer_status reports progress and sftp_transfer_cancel stops a transfer. SSHive has to stay open until they finish.

Ready in 3 clicks

Copy the ready-to-paste config into your AI client, or run the one-shot Claude Code CLI command below.

  1. 1

    Open SSHive Settings

    Navigate to Settings > MCP in the SSHive sidebar.

  2. 2

    Enable the MCP server

    Toggle the switch to activate the local MCP server on port 49422. A Bearer token is automatically generated and shown in Settings, you'll paste it into the snippets below.

  3. Paste the config, or run the Claude Code one-liner

    For Claude Desktop, install the SSHive extension in one click, or connect it through npx mcp-remote over SSE. For Cursor and Cline, copy the JSON config and paste it into the client's MCP settings file. For Claude Code (CLI + IDE), copy the claude mcp add command shown in Settings > MCP: it registers SSHive in ~/.claude.json in one step. Restart your client and you're connected.

Claude Code CLI (one-shot command)
claude mcp remove sshive --scope user 2>/dev/null; claude mcp add --transport http --scope user sshive http://127.0.0.1:49422/mcp --header "Authorization:Bearer <your-token>"
Streamable HTTP (Cursor, Cline)
{
  "mcpServers": {
    "sshive": {
      "type": "http",
      "url": "http://127.0.0.1:49422/mcp",
      "headers": {
        "Authorization": "Bearer <your-token>"
      }
    }
  }
}
Claude Desktop without the extension (mcp-remote over SSE)
{
  "mcpServers": {
    "sshive": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "http://127.0.0.1:49422/sse",
        "--header",
        "Authorization:Bearer <your-token>",
        "--transport",
        "sse"
      ]
    }
  }
}
SSE, Server-Sent Events (legacy)
{
  "mcpServers": {
    "sshive": {
      "transport": {
        "type": "sse",
        "url": "http://127.0.0.1:49422/sse",
        "requestHeaders": {
          "Authorization": "Bearer <your-token>"
        }
      }
    }
  }
}

Works with your favorite AI tools

Claude Code

A one-line CLI command: claude mcp add registers SSHive in ~/.claude.json.

Cursor

Paste the JSON snippet into Cursor's MCP settings file, SSHive shows the exact config in Settings.

Claude Desktop

Install the SSHive extension (.mcpb) in one click, or connect through npx mcp-remote over SSE.

Cline

Compatible via manual Streamable HTTP configuration.

Secure by design

The server never puts your sessions on the network: it listens on 127.0.0.1 only, answers only requests that carry its token, and no SSHive server relays anything between your Mac and your servers. That protection stops at what the assistant reads: the client sends it to its model provider, as the next section explains.

Server binds to 127.0.0.1 only, not reachable from the network
Bearer token authentication on every request
Auto-generated cryptographic tokens
No cloud relay, direct local communication
Token regeneration with one click
MCP server can be disabled at any time

Where your data goes when an assistant uses SSHive

  1. 1

    Your AI client calls the server on 127.0.0.1, with the token. Nothing listens on the network.

  2. 2

    SSHive carries out the request through an SSH or SFTP session it holds, from your Mac straight to your server. No SSHive server sits in between.

  3. 3

    The result (command output, file contents, a directory listing) goes back to the AI client.

  4. 4

    The client adds it to the conversation and sends that to its model provider: Anthropic for Claude Code and Claude Desktop, the provider you chose in Cursor.

So the rule is the one you already apply to a chat window: if a file or an output should not reach that provider, do not ask the assistant to read it.

The token, and how to change it

SSHive creates the token when you switch the server on and keeps it in its settings file, settings.json, not in the Keychain. Restarting SSHive does not change it. Any program on this Mac that holds it can call the server, so treat it like a password. To replace it, use "Regenerate" in Settings > MCP: from then on the server refuses the old one, so every client you set up by hand (the Claude Code command, Cursor's JSON, the mcp-remote block, the Claude Desktop extension) needs the new token pasted in.

An assistant in the terminal, free, with your own key

MCP lets an outside assistant work on your sessions. The Mac app also has an assistant of its own, in the SSH terminal: select some output and ask what an error means, or ask a question in plain words. It uses your own API key for Claude, OpenAI, Gemini, or Mistral, or any OpenAI-compatible endpoint, which is how local models served by LM Studio or Ollama fit in. It is part of the free version, on the Mac only. As with MCP, what you send it goes to the provider whose key you entered.

MCP FAQ

What is MCP and why use it with SSH?+
MCP (Model Context Protocol) is an open standard from Anthropic that lets AI assistants such as Claude Code, Cursor and Claude Desktop use outside tools. SSHive runs a local MCP server that makes your open SSH and SFTP sessions usable by the model: you describe what you want, and the assistant runs the commands or reads the files for you.
Are my servers exposed to the internet?+
No. The MCP server listens on 127.0.0.1 (loopback) only, and every request must carry the Bearer token SSHive created when you switched the server on. There is no SSHive relay: SSHive reaches your servers itself, through the SSH sessions you opened. What the AI client reads through it, however, that client sends to its model provider as part of the conversation.
How do I set up Claude Code with SSHive?+
Turn the server on in Settings > MCP, copy the Claude Code command shown there and run it in Terminal: it registers SSHive at user scope, in ~/.claude.json. SSHive does not edit that file itself; an App Store app is not allowed to. claude mcp list then shows sshive as connected. The Claude Code guide goes through it step by step.
Which MCP tools does SSHive expose?+
20 tools: ssh_list_profiles, ssh_connect, ssh_disconnect, ssh_list_sessions, ssh_execute, sftp_list, sftp_read_file, sftp_write_file, sftp_edit_file, sftp_write_file_chunk, sftp_write_from_local_path, sftp_upload_start, sftp_download_start, sftp_transfer_status, sftp_transfer_cancel, sftp_download_to_local_path, sftp_mkdir, sftp_chmod, sftp_rename, sftp_delete. They cover SSH command execution and full SFTP file management (list, read, write, edit, upload, download, mkdir, chmod, rename, delete), including streaming transfers with no base64 overhead and background transfers you can poll or cancel. 3 of them, ssh_list_profiles, ssh_connect, ssh_disconnect, only appear once you turn on "Let the assistant open sessions" in Settings > MCP; without it the assistant sees the other 17.
Does MCP work with Cursor, Claude Desktop and Cline?+
Yes. For Cursor and Cline, paste the Streamable HTTP block from Settings > MCP into the client's MCP file (Cursor guide). For Claude Desktop, install SSHive's extension in one click from the same panel and paste the token when Claude Desktop asks; without the extension, a block runs npx mcp-remote over SSE (Claude Desktop guide). Restart the client if it does not pick the change up.
Does the MCP server send my data to Anthropic?+
SSHive does not: the server runs on your Mac and no SSHive relay sits in the path. But everything the assistant reads through it (command output, file contents, session names) becomes part of its conversation, and the client sends that to its model provider: Anthropic for Claude Code and Claude Desktop, the provider selected in Cursor. Keep out of the assistant's reach what you would not paste into a chat.

Give your AI superpowers

Download SSHive and connect Claude Code, Cursor, or Claude Desktop to your servers in seconds.