ssh-mcp
ssh-mcp is an MCP server that enables AI assistants to securely execute commands and transfer files on remote servers via SSH. It integrates with your existing ~/.ssh/config for connection details.
list_servers: View all configured SSH servers, optionally filtered by group, showing names, groups, and descriptions.list_groups: View all server groups with their descriptions and member counts.execute: Run a shell command on a single SSH server with configurable timeout, working directory, and optional bypass of dangerous command detection.execute_on_group: Run a shell command in parallel across all servers in a group, with fail-fast mode and per-server timeouts.upload_file: Upload a local file to a remote server via SFTP, with path validation to prevent sensitive file access.download_file: Download a file from a remote server to a local destination via SFTP, with path validation on both ends.
Security & deployment features include dangerous command detection, automatic credential redaction in logs, connection pooling, host key verification, JSON audit logging, and flexible deployment via stdio or HTTP transport (suitable for Docker/network environments).
Supported as a TLS-terminating reverse proxy option for securing HTTP transport deployments in production environments.
Supports Datadog log integration through JSON log format output, allowing structured logging events to be consumed by Datadog's log aggregation platform.
Provides Docker container deployment options with prebuilt images, volume mounting for SSH configuration, and containerized execution environments.
Hosts the project repository and publishes Docker images to GitHub Container Registry for containerized deployments.
Mentioned as a use case for traffic patterns that influenced HTTP keepalive timeout configuration optimizations.
Supported as a TLS-terminating reverse proxy option for securing HTTP transport deployments in production environments.
Built with Python 3.11+ and provides pip installation options, though this is primarily an implementation detail rather than a target service.
Supports Splunk log integration through JSON log format output, allowing structured logging events to be consumed by Splunk's log aggregation platform.
Uses TOML format for server configuration files, defining server groups, descriptions, and organizational structure for SSH infrastructure.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@ssh-mcpcheck the disk usage on all servers in the production group"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
ssh-mcp
SSH MCP server that lets AI assistants execute commands on remote servers.
What is this
ssh-mcp is a Model Context Protocol server that gives AI assistants like Claude direct access to your SSH infrastructure. Once configured, Claude can run commands, transfer files, and query server groups across your fleet without leaving the conversation.
Connection details are read from your existing ~/.ssh/config. No credentials are stored in the MCP configuration.
Related MCP server: SSH MCP Server
Features
Run shell commands on individual servers or across entire groups in parallel
SFTP file upload and download over the existing SSH session
Connection pooling — reuses SSH connections across tool calls
Dangerous command detection — warns before executing destructive operations
Server groups for organizing hosts (production, staging, per-service)
SSH config integration — reads host, port, user, and identity from
~/.ssh/configCustom config path via
SSH_MCP_CONFIGenvironment variabledry_runpreviews — see which server, command, working directory and timeout would be used, without connectingSFTP local-path confinement — every local path stays inside a configured
transfer_rootstdio or streamable-HTTP transport, with bearer-token auth for network deployments
Built-in
ssh-mcp healthchecksubcommand for Docker'sHEALTHCHECKOptional OpenTelemetry tracing via the
otelextra
Quick Start
Install
# Run directly with uvx (no install required)
uvx blc-ssh-mcp
# Or install with pip
pip install blc-ssh-mcpRequires Python 3.11+. Install uv to use uvx.
The PyPI package is
blc-ssh-mcp, notssh-mcp. The namessh-mcpon PyPI belongs to an unrelated project by a different author. Installing it will not give you this server. Releases before 0.6.1 documented the wrong name — if you followed those instructions, uninstallssh-mcpand installblc-ssh-mcp.
Docker
A prebuilt image is published to GitHub Container Registry:
docker pull ghcr.io/blackaxgit/ssh-mcp:latestOr run with Docker Compose:
services:
ssh-mcp:
image: ghcr.io/blackaxgit/ssh-mcp:latest
stdin_open: true
restart: unless-stopped
environment:
SSH_MCP_CONFIG: /config/servers.toml
volumes:
- ./servers.toml:/config/servers.toml:ro
- ~/.ssh:/home/sshmcp/.ssh:roThe image uses a non-root sshmcp user (uid 1000). Mount your SSH keys and config file read-only. compose.yaml in the repo carries a fuller example — it builds from the local Dockerfile rather than pulling the published image, and includes the HTTP-transport service, ulimits and healthcheck guidance omitted above.
Create a config file
mkdir -p ~/.config/ssh-mcp
cp config/servers.example.toml ~/.config/ssh-mcp/servers.tomlEdit ~/.config/ssh-mcp/servers.toml and add your servers. Server names must match Host entries in ~/.ssh/config.
Add to Claude Desktop
Edit ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or the equivalent on your platform:
{
"mcpServers": {
"ssh-mcp": {
"command": "uvx",
"args": ["blc-ssh-mcp"]
}
}
}To use a non-default config path, pass the environment variable:
{
"mcpServers": {
"ssh-mcp": {
"command": "uvx",
"args": ["blc-ssh-mcp"],
"env": {
"SSH_MCP_CONFIG": "/path/to/servers.toml"
}
}
}
}Restart Claude Desktop after editing the config.
Add to Claude Code
If you use Claude Code instead of Claude Desktop, you can set everything up from the terminal:
# 1. Add the MCP server
claude mcp add ssh-mcp -- uvx blc-ssh-mcp
# 2. Create the config directory and copy the example
mkdir -p ~/.config/ssh-mcp
curl -sL https://raw.githubusercontent.com/blackaxgit/ssh-mcp/main/config/servers.example.toml \
> ~/.config/ssh-mcp/servers.toml
# 3. Edit with your servers (server names must match ~/.ssh/config Host entries)
${EDITOR:-nano} ~/.config/ssh-mcp/servers.toml
# 4. Restrict permissions
chmod 600 ~/.config/ssh-mcp/servers.tomlTo use a custom config path:
claude mcp add ssh-mcp -e SSH_MCP_CONFIG=/path/to/servers.toml -- uvx blc-ssh-mcpConfiguration
Environment variables
Variable | Default | Purpose |
| — | Absolute path to a TOML config file. Overrides the default search path. |
|
| Log output format. Set to |
|
| MCP transport. |
|
| Bind address for HTTP transport. Binding to any non-localhost value (e.g. |
|
| TCP port for HTTP transport. |
| — | Shared bearer secret. When set, every request must carry |
| — | Path to a file containing the bearer token (alternative to |
|
| Authentication mode. |
| — | Magic-string escape hatch. Must equal literal |
|
| uvicorn |
|
| uvicorn |
|
| uvicorn |
|
| Set to |
| — | Comma-separated extra Host-header values the SDK's DNS-rebinding protection should permit (e.g. |
|
| Directory SFTP transfers are confined to. Takes precedence over |
|
| Honoured when searching for |
|
| Base directory for the default transfer root. |
|
| For local development / CI only. Set to |
fd exhaustion mitigation: the Docker base image inherits a 1024 fd limit by default. Under sustained burst traffic that can run out quickly. Raise it in your compose file:
ssh-mcp:
# ...
ulimits:
nofile:
soft: 65536
hard: 65536Pair that with the SSH_MCP_HTTP_KEEPALIVE_TIMEOUT / SSH_MCP_HTTP_LIMIT_CONCURRENCY knobs above for a full fix.
Running over HTTP
ssh-mcp exposes the MCP streamable HTTP transport as an alternative to stdio. This lets MCP-aware clients connect over the network instead of launching a subprocess, which is useful for containerized deployments, shared-team servers, or anything that needs to survive a client restart.
WARNING: ssh-mcp serves plain HTTP, not HTTPS. The bearer token is transmitted in cleartext on every request. Deploying on a public IP without a TLS-terminating reverse proxy (Caddy, nginx, Traefik) exposes the token to any network observer — equivalent to publishing a root shell. Always terminate TLS before ssh-mcp reaches the network.
Security first. ssh-mcp runs shell commands on remote servers. Exposing the HTTP endpoint without authentication is equivalent to exposing a root shell. The startup code enforces this:
Binding to
127.0.0.1/localhost/::1without a token is allowed — this matches the single-user workstation model.Binding to ANY other address without
SSH_MCP_HTTP_TOKENraisesRuntimeErrorat startup and the process exits.The MCP SDK's DNS-rebinding protection is enabled by default. Remote clients connecting via a hostname must have it listed in
SSH_MCP_HTTP_ALLOWED_HOSTS.Bearer-token comparison uses
hmac.compare_digestto prevent timing attacks.
Local loopback (no auth needed):
SSH_MCP_TRANSPORT=http ssh-mcp
# → listening on http://127.0.0.1:8000/mcpContainer deployment with bearer auth:
TOKEN=$(openssl rand -hex 32)
docker run -d \
-p 8000:8000 \
-e SSH_MCP_TRANSPORT=http \
-e SSH_MCP_HTTP_HOST=0.0.0.0 \
-e SSH_MCP_HTTP_TOKEN="$TOKEN" \
-e SSH_MCP_HTTP_STATELESS=true \
-e SSH_MCP_HTTP_ALLOWED_HOSTS='ssh-mcp.internal:*' \
-v ~/.ssh:/home/sshmcp/.ssh:ro \
-v ./servers.toml:/config/servers.toml:ro \
-e SSH_MCP_CONFIG=/config/servers.toml \
ghcr.io/blackaxgit/ssh-mcp:latestClients connect with:
Authorization: Bearer <TOKEN>
Host: ssh-mcp.internalFor stateful sessions (default), FastMCP maintains per-client context across requests. For stateless deployments behind a load balancer, set SSH_MCP_HTTP_STATELESS=true — each request is handled independently with no server-side session.
Healthcheck
The Docker image includes a built-in ssh-mcp healthcheck CLI subcommand that
Docker's HEALTHCHECK directive invokes automatically. No inline Python, no
curl, no manual compose surgery required. The subcommand:
Auto-detects the transport via
SSH_MCP_TRANSPORT:stdio mode: verifies the package imports and
servers.tomlparseshttp mode: sends a real MCP
initializeJSON-RPC POST and checks for any non-5xx response
Reads the same auth env vars as the server (
SSH_MCP_HTTP_TOKEN,SSH_MCP_HTTP_TOKEN_FILE,SSH_MCP_HTTP_AUTH) — never logs the tokenExits 0 if healthy, 1 otherwise
Uses Python stdlib only (no
curl/wgetdependency)Applies a 3-second timeout to the HTTP probe. The stdio probe has no timeout of its own and relies on Docker's
--timeout=5s(importing the server costs ~0.3s)
Run manually for debugging:
docker exec ssh-mcp ssh-mcp healthcheck && echo "healthy"Check current status:
docker inspect ssh-mcp --format '{{.State.Health.Status}}'To override the baked-in settings in your compose file:
healthcheck:
test: ["CMD", "ssh-mcp", "healthcheck"]
interval: 15s
timeout: 5s
retries: 3
start_period: 10sTracing (OpenTelemetry)
Tracing is optional and off unless opentelemetry-api is importable:
uv pip install 'ssh-mcp[otel]'The extra installs the API layer only — the SDK and exporter are yours to choose, so ssh-mcp stays lightweight for anyone who does not trace. Install and configure opentelemetry-sdk plus an exporter (OTLP, Jaeger, Tempo) yourself; without an SDK the API is a no-op and nothing is emitted.
Spans produced:
mcp.tool.<name>— one per MCP tool call, taggedmcp.tool.name. Exceptions are recorded withStatusCode.ERROR.ssh.execute,ssh.upload,ssh.download— the SSH/SFTP operation inside the tool call.
Span attributes go through the same credential redaction as the audit log (see Security).
Reverse proxy deployment (auth at the edge)
If your reverse proxy (Caddy, nginx, Traefik, Envoy, Cloudflare Access, etc.) already authenticates requests before they reach ssh-mcp, you can disable the built-in bearer middleware with SSH_MCP_HTTP_AUTH=none. This mode is deliberately hard to enable on a public bind — you must also set a verbose acknowledgement env var:
docker run -d \
--network internal \
-e SSH_MCP_TRANSPORT=http \
-e SSH_MCP_HTTP_HOST=0.0.0.0 \
-e SSH_MCP_HTTP_AUTH=none \
-e SSH_MCP_HTTP_NETWORK_NO_AUTH=I_ACCEPT_RCE_RISK \
-e SSH_MCP_HTTP_ALLOWED_HOSTS='ssh-mcp.internal:*' \
-v ~/.ssh:/home/sshmcp/.ssh:ro \
-v ./servers.toml:/config/servers.toml:ro \
-e SSH_MCP_CONFIG=/config/servers.toml \
ghcr.io/blackaxgit/ssh-mcp:latestWARNING: SSH_MCP_HTTP_AUTH=none + SSH_MCP_HTTP_NETWORK_NO_AUTH=I_ACCEPT_RCE_RISK is a remote code execution surface. The magic-string acknowledgement exists so operators physically type the words "I ACCEPT RCE RISK" before opting in. Every tool call reaches a shell on every managed SSH server. Use this only when:
ssh-mcp is on a private Docker network not reachable from the host's public interface, AND
The reverse proxy fronting it enforces authentication (basic auth, OAuth, mTLS, Cloudflare Access, etc.), AND
You have audit logging on the proxy that's immutable to the ssh-mcp process.
For localhost binds without auth, no acknowledgement is needed — that matches the historical stdio deployment model.
Config file location
Checked in order:
$SSH_MCP_CONFIGenvironment variable$XDG_CONFIG_HOME/ssh-mcp/servers.toml, falling back to~/.config/ssh-mcp/servers.toml(default)config/servers.tomlrelative to the package (development only)
Example servers.toml:
[settings]
ssh_config_path = "~/.ssh/config"
command_timeout = 30 # SSH *connect* timeout in seconds, range 1..3600
max_output_bytes = 51200 # truncate captured output at this many bytes, per stream
max_command_bytes = 65536 # reject longer command strings at the tool boundary (1024..1048576)
connection_idle_timeout = 300 # seconds; eviction scan runs every 60s
known_hosts = true # false removes MITM protection
max_parallel_hosts = 10 # process-wide concurrency cap for group execution (1..100)
[groups]
production = { description = "Production servers" }
staging = { description = "Staging servers" }
[servers.web-prod-01]
description = "Production web server"
groups = ["production"]
[servers.web-staging-01]
description = "Staging web server"
groups = ["staging"]
jump_host = "bastion"
[servers.db-prod-01]
description = "Production database"
groups = ["production"]
user = "dbadmin"Note two things about the timeouts, because the names invite confusion:
command_timeoutis the SSH connection-establishment timeout, not the command execution timeout.Per-command timeout comes from the
timeoutargument ofexecute/execute_on_group(default 30) — unless the server block setstimeout = N, which wins over the caller's argument.
max_parallel_hosts bounds the whole process, not a single call: the semaphore is built once at startup, so concurrent execute_on_group calls share the same budget rather than each getting their own.
Per-server overrides (hostname, port, user, identity_file, jump_host, default_dir, timeout) take precedence over ~/.ssh/config. See config/servers.example.toml for the annotated reference.
Restrict config file permissions to your user:
chmod 600 ~/.config/ssh-mcp/servers.tomlAvailable Tools
Tool | Description |
| List configured servers; optionally filter by group |
| List server groups with member counts |
| Run a shell command on a single server (supports |
| Run a command on all servers in a group (parallel; supports |
| Upload a file to a server via SFTP. Local path is relative to |
| Download a file from a server via SFTP. Local path is relative to |
dry_run=true on either execute tool returns a [DRY RUN] preview of the server, command, working directory, timeout and force flag without opening a connection. Dangerous-command detection still runs, so a rejection can be previewed; if force=true would bypass a match, the preview carries an explicit ⚠️ DANGEROUS banner.
Command strings longer than max_command_bytes (default 65536 encoded UTF-8 bytes) are rejected at the tool boundary, before redaction or dangerous-command matching runs. Single SFTP transfers are capped at 100 MiB: an oversized upload is refused outright, an oversized download only logs a warning (the bytes are already on disk). Use rsync or scp for anything larger.
Security
Dangerous command blocking. ssh-mcp rejects commands that match known destructive patterns unless the tool caller passes force=true:
Recursive deletes of
/,~,$HOME,$USER— combined (rm -rf /) and split (rm -r -f /,rm --recursive --force /) flag forms, in any flag orderfind / -delete,find / -exec rmBlock-device wipes:
shred /dev/*,wipefs /dev/*,blkdiscard /dev/*,sgdisk -Z /dev/*Partition-table destruction:
parted /dev/… mklabel,fdisk /dev/sd*mkfs,dd if=…and the reordereddd of=… if=…formRedirects into a block device or auth database:
> /dev/sd*,> /dev/nvme*,> /dev/hd*,> /etc/{passwd,shadow,gshadow,sudoers}chmod 777 /— flag before or after the mode (chmod -R 777 /,chmod 777 -R /)Fork bombs (spaced and adjacent variants)
Payload-execution wrappers:
base64 -d | bash|sh|zsh|python|perl|ruby,eval "…",python|python3|perl|ruby -c,bash -c
Note the last bullet — it catches ordinary commands too.
bash -c '…',python3 -c '…'andeval …are blocked by default even when entirely benign. Wrap them differently (a script file, a heredoc) or passforce=truefor an audited call.
ASCII control characters (null bytes, newlines, \x01..\x1f, \x7f) are normalized to spaces before matching, so rm\x00-rf / is caught just like rm -rf /. The regex is fuzz-tested with Hypothesis on every CI run.
This is a TRIPWIRE, not a security boundary. The regex catches obvious accidents and shortcut destructive commands. It does NOT defend against a motivated attacker:
The base64/
eval/-cwrappers above are matched literally; any rewrite the regex does not spell out (a different decoder, a temp file,sh <<'EOF') gets throughShell hex escapes (
$'\x72\x6d -rf /') are interpreted AFTER regex matchingUnicode homoglyphs (Cyrillic
р, Greekρ) do not match LatinrIndirection via
$(...)and`...`can hide intent — those are not matched at allIf you need real isolation for untrusted tool callers, sandbox at a lower layer: run ssh-mcp inside a container with a restricted SSH config, use
ForceCommandon the managed servers, or auditforce=falseusage via the structured logs. The dangerous-command filter exists to stop LLM accidents and typos, not adversaries.
The bypass is not recorded in the audit log. Audit records carry server, command, exit_code and duration_ms only; force is emitted solely as an OpenTelemetry span attribute (ssh.force), and therefore only when the optional otel extra is installed and an exporter is configured. A block is logged as a warning on the operational logger, not the audit logger. If you need a paper trail for bypasses, export traces or withhold force=true at the MCP client. Do not grant force=true to untrusted MCP clients.
Credential redaction in logs. ssh-mcp automatically redacts known credential patterns (MySQL -p<pass>, --password=, PGPASSWORD=, Authorization: Bearer, URL basic-auth user:pass@host, plus any env var ending in _PASSWORD, _SECRET, _TOKEN, _KEY, _CREDENTIAL, _PWD) from audit logs and OTel span attributes before they reach stderr or trace backends. The asyncssh internal channel logger is suppressed to WARNING level so it never emits the raw command.
Known limitation: command OUTPUT is NOT redacted. If you run
cat /etc/mysql/my.cnf,env | grep PASSWORD, orkubectl get secret X -o yaml, the stdout/stderr returned to the MCP client will contain plaintext secrets. The redaction pipeline only filters the COMMAND string (what you asked to run), not the OUTPUT (what it printed). Avoid running commands that print secrets via ssh-mcp — pass credentials through env vars, Docker/K8s secrets, or dedicated config files instead.
Local path confinement (new in 0.6.0; versions ≤ 0.5.6 are affected by the flaw it fixes — see CHANGELOG.md). SFTP upload_file and download_file no longer accept arbitrary absolute local paths. Every local path is relative to a configured transfer root and is resolved one component at a time beneath it, refusing a symbolic link at any component:
[settings]
transfer_root = "~/.local/share/ssh-mcp/transfers" # default; honours $XDG_DATA_HOMEOverride with the SSH_MCP_TRANSFER_ROOT environment variable. The directory is created 0700 on demand, must be owned by the user running ssh-mcp, and must not itself be a symlink — ssh-mcp refuses to start a transfer otherwise.
Consequences, all deliberate:
Absolute local paths and
..are rejected. Sub-directories are allowed, but they must already exist.Downloads do not overwrite. An existing destination fails rather than being silently replaced. A failed transfer removes its own partial file.
Remote non-regular files (symlinks, devices, FIFOs) are refused on a best-effort basis. SFTP protocol v3 offers no atomic no-follow open, so a remote server that swaps the file between the check and the open can still win that race; the local destination stays confined regardless.
Remote paths keep the existing sensitive-path denylist — a tripwire, not a boundary, matched as a substring after normalizing
//and./away, case-insensitively. It covers/etc/{shadow,gshadow,passwd,sudoers}and/etc/ssh/ssh_host_*;.ssh/{authorized_keys,id_rsa,id_ed25519,id_ecdsa,id_dsa,identity,config,known_hosts};.aws/{credentials,config},.azure/accesstokens.json,.config/gcloud/{credentials,access_tokens}.db;.kube/config,/etc/kubernetes/{admin,kubelet}.conf,/var/lib/kubelet/pki/;.netrc,.pgpass,.git-credentials,.docker/config.json;/proc/{self,<pid>}/{environ,mem,cmdline,maps,stack,status},/proc/{kcore,kallsyms}; the MySQL / PostgreSQL / MongoDB data directories under/var/lib/; and the Windows SAM / SECURITY hives plus\users\administrator\.ssh\. Public keys are *not** exempt — the old `.pub` carve-out was a string check on a caller-supplied name and was removed.
Prior versions validated the caller's path string against a denylist and then handed that string to asyncssh, which resolved it independently — so anything not enumerated was writable. Confinement replaces enumeration: ssh-mcp opens the local file itself and never lets a caller-supplied path reach the SFTP library.
Migrating from ≤ 0.5.x: replace absolute local paths with names relative to transfer_root, or set transfer_root to the directory you were already using. There is no flag to restore the old behaviour.
Host key verification is on by default (known_hosts = true). Disabling StrictHostKeyChecking in ~/.ssh/config weakens MITM protection and should be avoided in production.
Audit logging. Every tool call is logged to stderr with server, command, exit_code, duration_ms, and (for SFTP) byte counts. SFTP operations emit three-stage events: sftp.upload.start → sftp.upload.complete (or sftp.upload.failed), each tagged with a stable connection_id so a single transfer is grep-correlatable.
For production log aggregation, set SSH_MCP_LOG_FORMAT=json to emit single-line JSON events:
{"event": "sftp.upload.complete bytes=4096 duration_ms=183", "level": "info", "timestamp": "2026-04-08T16:00:11.761575Z", "server": "web-prod-01", "operation": "upload", "local_path": "releases/app.tar.gz", "remote_path": "/var/www/release.tar.gz", "connection_id": "web-prod-01-4242-a3f1c9d2"}When running in Docker, capture stderr with docker logs for the audit trail.
For vulnerability reports, see SECURITY.md. Do not open public GitHub issues for security concerns.
Development
git clone https://github.com/blackaxgit/ssh-mcp.git
cd ssh-mcp
uv sync --locked --extra dev
uv run pytest
uv run ruff check src/ tests/See CONTRIBUTING.md for guidelines on making changes and submitting pull requests.
Changelog
See CHANGELOG.md.
License
Mozilla Public License 2.0. See LICENSE.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityCmaintenanceEnables AI assistants to maintain persistent SSH terminal sessions and transfer files to/from remote servers. Allows stateful command execution, natural language server management, and seamless file operations through SSH connections.Last updated2736MIT
- AlicenseAqualityCmaintenanceEnables AI assistants to securely connect to and manage remote servers via SSH, supporting command execution, file transfers via SFTP, and multi-server management with both password and SSH key authentication.Last updated91312MIT
- AlicenseAqualityCmaintenanceEnables AI assistants to securely execute remote SSH commands, perform file transfers, and monitor system status through a standardized interface. It features robust security controls including command whitelisting, blacklisting, and credential isolation to prevent unauthorized operations.Last updated1044MIT
- Alicense-qualityFmaintenanceEnables AI assistants to execute commands and transfer files on remote servers over SSH connections.Last updated1MIT
Related MCP Connectors
Operate your Linux servers from your LLM. Every action runs through an auditable allowlist.
Let AI operate servers without SSH. Choose actions, approve risky changes, and audit every step.
Connect AI assistants to GitHub - manage repos, issues, PRs, and workflows through natural language.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/blackaxgit/ssh-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server