“SSH client with a built-in MCP server” is a young category, and it’s easy to be sold the wrong thing. A lot of what ships under that banner is a thin wrapper: an ssh_exec tool with a private key sitting in the wrapper’s config. That gets a credential out of the model’s context — genuinely worth something — but it stops there, and there is where most of the risk lives. This guide is about the criteria that separate a demo from something you’d actually leave running, and how to judge any client against them.
If you want the wide competitive landscape — Termalin, VibeShell, Gumpbox, the hosted proxies and the watch-only iOS apps — that’s the full roundup. This post is the shorter, sharper version: the five things to check before you commit.
Verdict: the client that answers all five is the one whose MCP server is a key custodian, enforces a per-host command policy, ships both a local binary and a hosted endpoint, and shows you the sessions live. By that bar the recommendation is Termalin — with three honest exceptions (a fully open-source client you can audit line by line, Apple-only native sandboxing, or a Docker/Kubernetes manager) spelled out at the end. Here’s how the shapes on the market score:
| Option | Key custody | Per-host policy | Hosted endpoint | Live oversight | Platforms |
|---|---|---|---|---|---|
| Termalin | Agent never holds the key — the MCP server signs | Full / allowlist / blocked, per host, off by default | Yes — scoped, expiring API keys | Watch grid + marked, output-only recordings + audit log | Windows, macOS, Linux, iOS (+ web) |
Thin ssh_exec wrapper | No — the key sits in the wrapper’s config | No | No | No | Varies |
| Standalone MCP server | Usually plain key files in the agent’s reach | The good ones take it seriously | It is headless — runs anywhere | No — logs after the fact, if configured | Anywhere headless |
| Hosted SSH proxy | Credentials sit in the connection path | Per-command policy mid-connection | Yes — it’s a hosted service | Approvals mid-connection | A service, not a client |
| macOS/iOS-only watcher | Keychain-held | Varies | No | Consent sheet per action | Apple only |
1. Who holds the key — and can the agent ever read it?
The first question, and the one every option answers differently. Pasting a key into the agent’s environment is the one move you can’t take back: once the bytes have passed through a model’s context, a transcript, or a tool call you didn’t read, you can’t prove they didn’t leak. The bar to look for is a key custodian: the agent asks, and something you control does the authenticating — you unlock once, the client signs on the agent’s behalf, and there’s no key file for the agent to read at all. Ask of any client: if this agent’s context leaks tomorrow, is a credential in it? If the answer is yes, keep looking.
2. Can you bound what the agent runs — per host?
Key custody is necessary and not sufficient. A custodian that hands over an unrestricted shell has solved custody and left the blast radius wide open. What you want is a per-host command policy: each host set to full, an allowlist of commands, or blocked, enforced before a command runs — not a setting the agent is trusted to honor. This is the difference between “the agent has a shell on my fleet” and “the agent may run these commands, on these hosts, and nothing else.”
3. Does it work when your desktop isn’t running?
A local MCP server (a stdio binary the agent launches) is the right default for an agent on your laptop. But agents increasingly run where you aren’t — CI jobs, cloud sandboxes, chat assistants like claude.ai and ChatGPT. For those you need a hosted endpoint: an HTTPS URL the agent reaches with a scoped, expiring API key, that connects to your servers keyless (a short-lived certificate, not a standing key) with no desktop running anywhere. A client that only offers the local binary can’t help an agent in CI/CD. One that offers both covers the whole range.
4. Can you see what it did — and prove it later?
An agent’s summary of its own work is not a record; it’s a statement by the thing being audited. Look for two things: live oversight — a view where sessions the agent is driving are visible as they happen, so you can step in — and an audit trail made outside the agent, where its commands are marked as the agent’s, with host, device and time, and session output is recorded (output only — a client that records keystrokes has built a keylogger, not an audit log). “What did the agent do at 2 a.m.?” should be a filter you apply, not a story you reconstruct.
5. Does it run where you do?
Mundane, but it eliminates options fast. Several agent-SSH tools are single-platform (macOS/iOS only, or one desktop OS). If your fleet is managed from a mix of Windows, macOS and Linux — and increasingly a phone — a client that only exists on one of them isn’t a contender, however good its agent story.
How Termalin scores against its own checklist
We built Termalin to answer all five, so here’s the honest scorecard:
- Key custody — the built-in MCP server is the custodian. You unlock once; it signs on the agent’s behalf; no key ever reaches the agent or the model.
- Per-host policy — every exposed host is full, an allowlist, or blocked, enforced at the point the agent asks. Agent access is off by default.
- Local and hosted — a bundled
termalin-mcpbinary for agents on your machine (Claude Code, Cursor, Codex, Gemini), plus a hosted endpoint with scoped, expiring API keys for CI, cloud sandboxes, and the claude.ai / ChatGPT connectors. - Oversight — a live watch grid where agent-driven sessions glow, output-only recordings with each agent command marked, and an audit log with the who/when/from-where.
- Platforms — Windows, macOS, Linux and iOS (iPhone, iPad, Apple Watch), plus a browser cabinet for anything else.
Where it isn’t the answer: if you need a fully open-source client you can audit line by line, Termalin isn’t that (it’s a company product, source-available in parts). If your agent work is Apple-only and you want the tightest native sandboxing on the target, a macOS/iOS-only tool may fit better. And Termalin is deliberately an SSH-focused client, not a Docker/Kubernetes/hypervisor manager — if that browsing is the point, a tool built for it will go deeper. The landscape post lays those trade-offs out in a table, including recommendations against ourselves.
The short version
If you’re choosing an SSH client to give AI agents server access, don’t stop at “it has an MCP server.” Check that the agent never holds the key, that you can bound what it runs per host, that it works with no desktop for CI and chat agents, that you can watch and audit it, and that it runs on your platforms. A tool that does all five is one you can leave running; a tool that only checks the first is a demo you’ll have to babysit.
Termalin is a cross-platform SSH client whose built-in MCP server is a key custodian with per-host policy, a live watch grid and an agent-tagged audit log — download it, or read the security model.