Reference · MCP tools
MCP tools reference.
Termalin exposes its SSH client as MCP tools an agent can call. There are two surfaces: the local server bundled with the desktop app (termalin-mcp, over stdio) with 22 tools, and the hosted endpoint at https://termal.in/api/v1/mcp with a cloud subset of 8. This page lists every one — its parameters, its limits, and whether it reads or changes state. For the overview and setup, start at the MCP server page.
Which tool on which surface
Six tools share a name across both surfaces (hosts_list, generate_password, ssh_exec, sftp_list, data_query, data_tables); file reads and writes are named differently, and the session, tunnel, live-terminal and database-inspection tools are local only.
| Tool | Local | Hosted | Effect | What it does |
|---|---|---|---|---|
hosts_list | ✓ | ✓ | Reads | List the servers the agent may reach |
generate_password | ✓ | ✓ | Reads | Return a strong random password |
ssh_exec | ✓ | ✓ | Changes | Run one command and return its output |
session_open | ✓ | — | Changes | Open a persistent SSH session |
session_exec | ✓ | — | Changes | Run a command in an open session |
session_close | ✓ | — | Changes | Close a session |
session_list | ✓ | — | Reads | List the agent’s open sessions |
tunnel_open | ✓ | — | Changes | Open a local or SOCKS port forward |
tunnel_close | ✓ | — | Changes | Close a port forward |
tunnel_list | ✓ | — | Reads | List open port forwards |
sftp_list | ✓ | ✓ | Reads | List a directory over SFTP |
sftp_get | ✓ | — | Reads | Read a file over SFTP (local) |
sftp_put | ✓ | — | Changes | Write a file over SFTP (local) |
sftp_read | — | ✓ | Reads | Read a text file over SFTP (hosted) |
sftp_write | — | ✓ | Changes | Write a text file over SFTP (hosted) |
terminal_hosts | ✓ | — | Reads | List saved hosts the agent could open |
terminal_sessions | ✓ | — | Reads | List the user’s open terminal tabs |
terminal_open | ✓ | — | Changes | Open a live terminal tab in the app |
terminal_run | ✓ | — | Changes | Run a command in an open tab |
terminal_run_many | ✓ | — | Changes | Run one command across several tabs |
data_list | ✓ | — | Reads | List the app’s saved database connections |
data_tables | ✓ | ✓ | Reads | List tables / collections / keys |
data_schema | ✓ | — | Reads | Describe one table’s columns |
data_query | ✓ | ✓ | Reads * | Run a query and return rows |
* data_query is read-only by default; a write runs only with a full-access key (hosted) or a connection that grants the agent full access (local).
Servers & passwords
hosts_list local · hosted
List the servers the agent may reach. No parameters. Local: returns id, name, hostname, port, username and auth type — no secrets. Hosted: returns id, name, whether the server is online, and the default login user. Reads.
generate_password local · hosted
Return one strong random password — handy when creating a user or setting a password. Parameter: length (optional, default 20, clamped 8–128). Nothing is stored. Reads.
Running commands
ssh_exec local · hosted
Run a single shell command on a server and return its combined output. Each call is a fresh connection, so cd and shell variables don’t carry between calls — chain with cd /path && cmd. Required: host, command. Hosted adds optional username (defaults to the tunnel’s user, else root) and timeoutSeconds (default 60, up to 300). Honours the host’s agent policy. Changes state.
Persistent sessions local only
session_open local
Open a persistent SSH session and keep it connected, so follow-up commands skip the auth handshake. It is the agent’s own headless connection — no app needed. Required: host. Returns a sessionId. A blocked host refuses. Changes state.
session_exec local
Run a command on an open session and return its output. Each command still runs on a fresh channel, so cwd/env don’t persist. Required: session, command. An allowlist host is re-checked per command. Changes state.
session_close local
Close a persistent session and disconnect it. Required: session. Changes state.
session_list local
List the persistent sessions the agent currently has open. No parameters. Returns sessionId, hostId and host. Reads.
Port forwards local only
tunnel_open local
Open a port forward on an open session. Required: session. type is local (default — a local port that reaches remoteHost:remotePort as the server sees it; needs remoteHost and remotePort) or dynamic (a local SOCKS5 proxy that egresses from the server). localPort optional (0 picks a free one). Returns a tunnelId and the local listenAddr. Allowed on full-access hosts only, so an allowlist host can’t be turned into a pivot. Changes state.
tunnel_close local
Close a port forward. Required: tunnel. Changes state.
tunnel_list local
List the port forwards currently open. No parameters. Returns tunnelId, sessionId, kind, listenAddr and target. Reads.
Files over SFTP
sftp_list local · hosted
List a directory over SFTP. Required: host. Local also requires path and returns name, path, isDir, size, permissions and modified time. Hosted makes path optional (defaults to the login home, .) and adds optional username. Reads.
sftp_get local
Read a file over SFTP. Required: host, path. UTF-8 text comes back as text; binary comes back base64. Capped at 4 MB — MCP results travel into a model’s context, so reads stay modest. The hosted equivalent is sftp_read. Reads.
sftp_put local
Write a file over SFTP, creating or overwriting it. Required: host, path, content. Optional base64 writes decoded binary. Allowed on full-access hosts only. The hosted equivalent is sftp_write. Changes state.
sftp_read hosted
Read a text file over SFTP and return its contents. Required: host, path. Optional username. Files over 512 KB or non-text (binary) files are refused — use ssh_exec (tail, sed) for those. Reads.
sftp_write hosted
Create or overwrite a text file over SFTP. Required: host, path, content (written as UTF-8). Optional username. Capped at 512 KB; for binary uploads use a terminal or scp. Changes state.
The live desktop app local only
These drive the running desktop app through its consent-gated control server. terminal_hosts and terminal_sessions need “Agent in Terminal” enabled; terminal_open, terminal_run and terminal_run_many need the “Let agents run commands” consent.
terminal_hosts local
List the saved hosts the agent could open a session for. No parameters. Returns hostId, name, connectionType, authMethod and canOpenHeadless (false means opening it needs you — a password or a locked key). Reads.
terminal_sessions local
List the terminal tabs you currently have open that the agent can act in. No parameters. Returns tabId, hostId, title, connected and attached. Reads.
terminal_open local
Open a new terminal session for a host on the agent’s own initiative — a background tab in your app that glows so you can see it’s the agent’s. Required: hostId. Hosts needing a password or a locked key open but stay unconnected until you finish. Changes state.
terminal_run local
Run a command in one of your open terminal tabs, as if you typed it; the tab glows while the agent acts. Required: tabId, command. Optional timeoutSeconds (default 120, up to 3600 — set it generously for builds). Returns the captured output. Changes state.
terminal_run_many local
Run the same command across several open tabs at once (mass operations, Ansible-style). Required: tabIds (array), command. Optional timeoutSeconds (default 120, up to 3600). Returns per-session output or error. Changes state.
Databases
The local data tools work the saved “Data” connections in the app (id from data_list) and need the app running and unlocked; they’re off by default and read-only unless a connection grants full access. The hosted data tools work a server’s own database client over the keyless tunnel (host id from hosts_list), using the database’s local trust — no database password is sent or stored.
data_list local
List the saved database connections (PostgreSQL, MySQL/MariaDB, SQLite, SQL Server, ClickHouse, MongoDB, Redis, Elasticsearch, RabbitMQ, Cassandra, Neo4j, InfluxDB). No parameters. Returns each connection’s id, name, engine and whether the agent may write. Reads.
data_tables local · hosted
List the tables / collections / keys of a database. Local: required hostId (from data_list), optional database. Hosted: required host (from hosts_list), optional engine (postgres default, or mysql/mariadb/redis/mongodb/sqlite), database, username. Reads.
data_schema local
Describe one table’s columns (name, type, nullable, primary key). Required: hostId, table. Optional schema, database. Reads.
data_query local · hosted
Run a query and return the rows, in the connection’s own language (SQL, a Redis command, a MongoDB shell expression, Cypher, InfluxQL, and so on). Local: required hostId, query; optional database, maxRows (default 200). Hosted: required host, query; optional engine (postgres default), database, username, allowWrites (full-access keys only), timeoutSeconds (default 60, up to 300). Read-only by default — only SELECT/SHOW-style statements run unless writes are granted.
Connect an agent
Point your client at whichever surface matches where the agent runs — the local server for hosts you export from the app, the hosted endpoint for servers enrolled with a Connector.
- Claude Code —
claude mcp add termalin -- <path>/termalin-mcp - Cursor and Codex — one entry in the client’s MCP config pointing at the same binary
- claude.ai and ChatGPT — the OAuth connector at
termal.in/mcp - Any HTTP client — an API key against
https://termal.in/api/v1/mcp
FAQ
How many MCP tools does Termalin have?
The local server bundled with the desktop app (termalin-mcp, stdio) exposes 22 tools. The hosted HTTP endpoint at https://termal.in/api/v1/mcp — the same one behind the claude.ai and ChatGPT connectors — exposes a cloud subset of 8: hosts_list, ssh_exec, sftp_list, sftp_read, sftp_write, data_query, data_tables and generate_password.
Why does file reading use a different name on each surface?
The local server reads and writes files with sftp_get and sftp_put (a local read is capped at 4 MB and may return base64 for binary). The hosted endpoint uses sftp_read and sftp_write, which are text-only and capped at 512 KB — a small pipe into an agent’s context, not a file-transfer channel. Everything else that shares a name behaves the same on both.
Which tools change state and which only read?
Reads: hosts_list, session_list, tunnel_list, sftp_list, sftp_get, sftp_read, terminal_hosts, terminal_sessions, data_list, data_tables, data_schema, generate_password. Changes: ssh_exec, session_open/exec/close, tunnel_open/close, sftp_put, sftp_write, terminal_open/run/run_many. data_query is read-only by default and only runs a write with full access.
Can the agent run these without my keys or my desktop?
The local tools authenticate through Termalin’s key custodian — no private key is handed to the agent. The hosted tools reach servers enrolled with a keyless Connector using a short-lived certificate, with no desktop app running. See SSH for AI agents for the custody model.