Stateful Windows OpenSSH server operations for Codex with local credential handling.
This MCP server provides stateful Windows OpenSSH server operations for Codex, including local credential handling. It is distributed under the name io.github.cyyprezz/codex-serverops-mcp and is associated with topics spanning codex, control-systems, linux, mcp, python, server, and windows.
🛠️ Key Features
Stateful Windows OpenSSH server operations
Local credential handling for Codex
🚀 Use Cases
Operating selected servers from Codex
Managing SSH interactions where Windows OpenSSH is required
⚡ Developer Benefits
Python package availability (PyPI)
Clear project metadata for integration and tracking (slug/name, topics)
⚠️ Limitations
Readme excerpt is truncated and only partially describes operation scope (“Operate the Linux servers you choose from Co”).
Operate the Linux servers you choose from Codex or Claude Code—through normal conversation,
without installing a ServerOps agent on them.
ServerOps keeps useful Bash state between operations, returns structured evidence, and opens
visible local windows when OpenSSH or sudo needs input. It is for freelancers, agencies, support
teams, project owners, and operators who need reliable server work without living in an SSH
terminal.
Three promises
Easy to start
Thin Codex and Claude Code plugins connect to one shared ServerOps core. A guided local assistant
creates explicit server profiles without putting credentials into chat.
Easy to operate
Ask for an outcome in normal language. ServerOps keeps the working directory and shell environment
in a held Bash session, supports interactive terminal work, and returns bounded, structured
results instead of an uncontrolled wall of terminal text.
Reliable when outcomes matter
Sessions belong to a local broker-owned worker rather than the disposable MCP process. If the
result of a remote mutation is uncertain, ServerOps reports outcome_unknown and never retries it
automatically. Linux permissions, explicit profiles, visible authentication, controlled elevation,
hash preconditions, and a redacted local audit form the trust layer.
See it in action
These are realistic prompts for the eight tools available today:
text
List my ServerOps profiles. Do not connect to a server or change anything.
text
Use the customer-web profile. Start read-only, identify the host and current user, then explain
why the service is unhealthy. Narrow the diagnosis with evidence instead of dumping every log.
text
Open the project profile, enter /srv/my-app, inspect the current Git and Compose state, and keep
the session open so we can continue from the same directory.
text
Read /srv/my-app/.env.example with the structured file tool. Propose a minimal change and show me
the observed SHA-256, but do not apply anything until I approve it.
See the step-by-step reproducible demo for expected evidence and safe boundaries.
Available today
Explicit profiles and a visible local profile assistant.
Broker-owned, stateful Bash sessions with completed-command
and interactive-terminal modes.
Rediscovery after an MCP-client restart when the
optional managed broker task is installed and the broker, worker, and Bash remain alive.
Explicit unknown-outcome errors with no automatic retry of
uncertain mutations.
Bounded structured UTF-8 text operations inside configured
roots, with optional SHA-256 preconditions for edits.
Visible local OpenSSH authentication and host-key decisions,
plus guided sudo and optional root sessions.
Redacted local JSONL audit events without remote output or file
contents.
One eight-tool MCP core with thin Codex and Claude Code wrappers.
Automatic, idempotent local bootstrap on first MCP start.
A native Claude Code marketplace and plugin beside Codex.
No ServerOps agent or daemon installed on the Linux server.
The current runtime is Windows-first and uses Windows OpenSSH to reach Linux. The detailed
tool reference defines the exact operations and schemas.
Codex quickstart
Install the repository marketplace and plugin. The pinned 0.1.1 MCP creates its own local state
on first start; no prior setup command is required:
Start a new Codex task. Do not add a separate user-wide [mcp_servers.serverops] block when using
the plugin. If a previous installer created that alternative block, preview its removal with
serverops-install codex-config --remove, then repeat with --apply only after review. This keeps
profiles and audit data. Begin without contacting a server:
text
List my ServerOps profiles. Do not create, edit, remove, test, or connect to a profile. If no
suitable profile exists, wait for me to provide non-secret suggestions before opening the visible
profile assistant. Credentials and host-key decisions belong only in the local ServerOps window.
Claude Code quickstart
The Claude Code wrapper uses the same pinned 0.1.1 runtime and client-neutral skills:
powershell
claude plugin marketplace add cyyprezz/codex-serverops-mcp
claude plugin install serverops@serverops-claude
If the GitHub shorthand requires an SSH key that is not configured, add the marketplace through
HTTPS instead:
powershell
claude plugin marketplace add https://github.com/cyyprezz/codex-serverops-mcp.git
Start a new Claude Code session (or reload plugins) and use the same safe first prompt.
Automatic local bootstrap
Version 0.1.1 starts without a separate setup command. MCP, broker, setup, check, Doctor, and
update share one idempotent bootstrap that prepares only ServerOps-owned local state: the app,
configuration, runtime, audit, migration, and status paths for the current user.
The bootstrap does not edit Codex or Claude configuration, install a Scheduled Task, create a
profile, contact a server, request administrator rights, or overwrite an unmanaged file. The
visible profile assistant remains the first possible server contact.
The explicit serverops-install setup command remains compatible and idempotent for maintenance
and for previewing the optional broker task; it is no longer a plugin prerequisite.
Optional installer and broker task
The version-pinned installer can check the shared runtime or a client path:
powershell
uvx --from "codex-serverops-mcp==0.1.1" serverops-install check --client core
uvx --from "codex-serverops-mcp==0.1.1" serverops-install doctor --client claude
doctor --client codex also checks the alternative installer-managed user configuration. A
plugin-only Codex installation can therefore warn that this optional block is absent; that warning
does not prove the plugin is broken.
Install the managed current-user broker task only when live sessions must be reliably rediscovered
after an MCP client process restarts. Preview first, then apply explicitly:
The task requests no administrator elevation and stores no password. It does not make sessions
survive a Windows reboot or broker crash; the current broker does not adopt orphaned workers.
Typical workflows
Customer server check
Select the named customer profile, start read-only, confirm target and identity, inspect only the
relevant service evidence, and report facts, hypotheses, gaps, and any changes separately.
Remote project work
Enter a project directory once, retain its shell environment across calls, run bounded commands,
and use structured file reads or preconditioned text edits for configured paths.
Interactive or longer-running work
Use the terminal only when a command genuinely needs interaction, incremental output, interrupt,
resize, or retained terminal state. Completed commands can run for up to the configured maximum of
3600 seconds and return exit code, duration, CWD, and truncation state.
Configured remote files
List, inspect, search, read, hash, write, patch, rename, create, or remove UTF-8 text paths inside a
profile's configured roots. These roots constrain the structured file tools; they do not sandbox
shell commands or replace backups.
Authentication and sudo
Passwords, key passphrases, host-key decisions, and interactive sudo input stay in separate visible
local windows. ServerOps can use existing OpenSSH behavior or guide a controlled key transition.
Sudo remains governed by the server's PAM and sudoers policy.
One-off SSH command or ServerOps?
Need
ssh host "command"
ServerOps
One isolated command
Smallest direct option
Works, but often unnecessary
Keep CWD and shell environment
Reconstruct it each time
Held in one live Bash session
Interactive terminal control
Requires a terminal workflow
Cursor reads, input, interrupt, resize, status
Structured text files
Parse and quote shell output
Bounded results and optional hash preconditions
Authentication prompts
Terminal-owned
Separate visible local windows
Uncertain remote mutation
Operator must reason from transport loss
Explicit unknown-outcome result; no automatic retry
Continue after MCP restart
New SSH command
Rediscoverable with the optional broker task while processes remain alive
ServerOps does not replace SSH. It uses OpenSSH and adds a stateful, structured boundary for AI-led
operations where repeated one-off commands become fragile or difficult to review.
Architecture
flowchart LR
C["Codex plugin"] --> M["Shared ServerOps MCP core"]
A["Claude Code plugin"] --> M
M --> B["Local per-user broker"]
B --> W["One worker per live session"]
W --> S["Windows OpenSSH"]
S --> L["Configured Linux server<br/>Bash + common utilities"]
W -. "visible local prompts" .-> U["Operator"]
M --> F["Local profiles + redacted audit"]
The MCP process exposes eight tools. The broker owns session routing, each worker owns exactly one
SSH/Bash process, and no ServerOps component is installed remotely. See
Architecture and Broker lifecycle.
Requirements and honest limits
Windows 10 or 11, Python 3.12, uv/uvx, and Windows OpenSSH Client for the current release.
An SSH-accessible Linux account with Bash; structured files require the common utilities listed
in Structured remote files.
ServerOps is alpha software. Start with a disposable or non-production account and narrow Linux
permissions.
Stateful means process-held: no durable jobs, resume after reboot, or worker adoption after a
broker crash.
Structured files are bounded UTF-8 text operations, not binary or resumable transfers and not a
transactional filesystem.
allowed_roots constrain only structured file tools. Shell commands retain the SSH user's real
permissions.
ServerOps makes no exactly-once promise. A timeout or connection loss after delivery can leave an
effect unknown and requires read-only verification.
First-class clients today are Codex and Claude Code. Claude Desktop, Cherry Studio, and other
desktop-client onboarding are planned, not shipped.
There is no ServerOpsSetup.exe yet; the public release requires Python 3.12 and uvx.
For support, open a GitHub issue without
credentials, private keys, customer hostnames, or production output. Report vulnerabilities through
SECURITY.md. ServerOps is available under the MIT License.