termal.in

Agent-native SSH

Give your AI agent SSH access — without handing over your keys.

Your coding agent — Claude Code, Cursor, or anything that speaks MCP — can work on your servers through Termalin: tail a log, edit a config, restart a service, deploy. A key custodian signs every connection so keys never touch disk, you watch each session live, and every agent action is marked in the recording.

Unlike single-platform or desktop-bound alternatives, Termalin runs on Windows, macOS and Linux — and its hosted MCP endpoint lets agents in CI or cloud sandboxes reach your servers with no desktop running at all. See the full landscape comparison.

Free tier · 14-day Pro trial · Windows, macOS & Linux

01  /  the safe way in

Agents do the server work now. Give them a safe way in.

The usual setup hands the agent a raw shell and a private key and hopes for the best. Termalin is the layer it connects through instead: an SSH client with a built-in MCP server over the hosts you choose, and a key custodian in the middle. No other SSH client ships this — see how the clients compare →

  • Key custodian. Unlock once; Termalin signs on the agent's behalf — no ssh-add, no key on disk, nothing handed to the model.
  • Per-host consent & policy. Agent access is off by default; you pick which hosts it may reach, set each one to full, an allowlist of commands, or blocked, and letting it type into your live sessions is a separate toggle again.
  • Everything on the record. Every agent command is marked in the session recording, mirrored to your screen live, and written to the audit log.

02  /  how it works

Three steps from download to a working agent.

1

Pick the hosts

Install Termalin, add your servers, and choose which ones agents may reach in Settings → MCP. Access is off until you turn it on.

2

Point your agent at it

Register the bundled MCP server with your agent — with Claude Code that's one line: claude mcp add termalin -- <path>/termalin-mcp. Any MCP client config works.

3

Watch it work

The agent opens its own sessions — a glowing tab you can watch — or, on Pro, steps into a session you already have open. Take the keyboard any time.

The full tool list, config snippets and both connection modes are on the MCP page →

03  /  you stay in the loop

Watch every session live — and rewind it later.

Every agent session mirrors to your screen. The watch grid shows each open session as a live tile, and sessions an agent is driving glow — so you always know what's running where. Recordings put commands, output and agent actions on a scrubbable timeline with markers, and they capture output only — never your keystrokes, so typed secrets don't leak. Behind it all sits an audit log of every host connection, file operation and agent command.

04  /  no app running

Agents can work your servers even when your machine is off.

Create an API key in the web cabinet and point any agent at Termalin's hosted MCP endpoint — it runs commands and reads or writes files on your tunnelled servers even when nothing is open on your machine. It authenticates with a short-lived certificate, so no key is handed out; keys can be scoped to specific servers, set to a command policy (full, an allowlist, or read-only), given an expiry and revoked any time, and hosted runs are rate-limited and time-boxed per key.

Questions

How can an AI agent SSH into my servers safely?

Through Termalin's built-in MCP server. The agent runs commands and reads or writes files over SSH and SFTP, while a key custodian signs every connection — no private key is written to disk or handed to the model. Agent access is off by default, and you choose which hosts it may reach. Technical deep-dive →

Which AI agents work with Termalin?

Any agent that speaks the Model Context Protocol — Claude Code, Cursor and other MCP clients. Point it at the bundled termalin-mcp binary, or at the hosted MCP endpoint with an API key when nothing is running on your machine.

Can I see what the agent is doing?

Yes — every agent session mirrors to your screen. In the watch grid each open session is a live tile, and sessions an agent is driving glow. Each agent action is marked in the session recording and written to the audit log, so you can rewind any run later. See all features →

Does the agent ever get my SSH keys?

No. Locally, Termalin's key agent signs on the agent's behalf — no ssh-add, no key on disk. The hosted endpoint authenticates to your tunnelled servers with a short-lived certificate, so no key is handed out there either. API keys can be scoped to specific servers, set to a command policy (full, an allowlist, or read-only), given an expiry and revoked any time. More on security →

Is agent access free?

The Free tier includes the MCP agent — it can open its own sessions, with no host limits. Letting an agent step into your live session is part of Pro at $8/mo billed yearly ($10 monthly). Every new account starts with a 14-day Pro trial — no card required. See pricing →

Put an agent on your servers — safely.

Download Termalin, pick the hosts your agent may reach, and watch it work. The Free tier has no host limits, and new accounts get Pro free for 14 days.

Free tier · 14-day Pro trial · compare clients · pricing