remotify-mcp

Run shell commands on a remote computer through an AI assistant, with every command shown to the person at that computer for approval.

Documentation

Run commands on a remote box without SSH.

Your LLM, CI runner, or terminal pushes a command over HTTPS. The remote needs only curl and bash. The relay holds nothing beyond an idle session buffer.

Install the MCP Try with just curl

remote.example.com: supervised

$ curl -fsSL 'https://relay.remotify.run/r/a1b2...' | bash

remotify: connected [supervised] - polling for commands.

>>> df -h /

Run? [y/N] y

Filesystem Size Used Avail Use% Mounted on

/dev/nvme0n1p2 74G 39G 32G 55% /

<<< done (412 bytes pushed back)

>>> systemctl is-active myapp

Run? [y/N] y

active

<<< done (7 bytes pushed back)

How it works

Three moving parts, one HTTP pipe.

Both sides talk only over HTTPS. Neither has to be online at the same time - the relay holds one pending command and one pending result per session, on disk, until the other side fetches it.

Client

LLM / CI / shell

Pushes commands via
POST /cmd-KEY, reads
output via GET /result-KEY.

▶▶

Relay File-backed queue, 128-bit
session key, 3h idle TTL.
No DB, no worker.

◀◀

Remote

curl + bash

One-liner pasted once,
polls the relay, runs the
command, posts result.

Who uses it

Four everyday situations it fits.

Anywhere a command needs to land on a remote without granting SSH to an LLM or agent - whether because you don't want a long-lived shell credential in autonomous hands, the host accepts no inbound ports, or installing a full agent is overkill.

  • LLM tool calls Let Claude, Cursor, Codex, or Gemini run commands on your actual server instead of pasting output back yourself.
  • CI post-deploy checks Poke at release state on a box your runner can't SSH into.
  • Admin shells behind NAT Outbound HTTPS is all the remote needs - no inbound ports.
  • Headless devices IoT, edge gateways, rescue consoles that can dial out but not in.

MCP install

Plug-and-play MCP for every major LLM host.

Paste one line. Your LLM gains a native remote_exec tool via MCP (Model Context Protocol) - no manual build, no global npm install, no config surgery. The MCP server is fetched on first launch by npx and runs locally on your machine.

claude mcp add -s user remotify -- npx -y remotify-mcp@latest
{ "mcpServers": { "remotify": { "command": "npx", "args": ["-y", "remotify-mcp@latest"] } } }
[mcp_servers.remotify]
command = "npx"
args    = ["-y", "remotify-mcp@latest"]
{ "mcpServers": { "remotify": { "command": "npx", "args": ["-y", "remotify-mcp@latest"] } } }

Windsurf / Continue / Cline / Zed / VS Code MCP

{ "command": "npx", "args": ["-y", "remotify-mcp@latest"] }

Try without installing

Generate a session right here.

Creates a one-time 128-bit key. Paste the listener one-liner on any remote shell, push commands from another terminal. Session is discarded after 3h idle; any activity on the key resets that.

Open source. Data-minimised by design.

This relay is Apache-2.0 open source, so you can audit the wire protocol and the relay yourself. The relay is built on Datensparsamkeit (data minimisation): it keeps the smallest possible footprint for each session and throws it away as soon as it can.

  • **No accounts, no identity.**Session keys are 128-bit random hex. Nothing ties a key to a person, email, or billing record.
  • **Ephemeral session data.**A per-session directory holds the pending command, pending result, and a short push history. Purged on 3h idle or explicit DELETE.
  • **No telemetry from the MCP.**The remotify-mcp package only talks to the relay you point it at. No analytics, no crash reporting.
  • **Ready to use for free, or self-host.**Hit relay.remotify.run directly with zero setup, or run the exact same relay on your own machine with one docker compose up and point MCP hosts there via REMOTIFY_URL.