Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To connect Claude Code to an MCP server that runs only on a remote SSH host, configure a stdio MCP server whose command is the local ssh client and whose arguments start the MCP process remotely. Use ssh -T so a pseudo-terminal does not interfere with the protocol stream. This is a practical composition of Claude Code’s documented stdio configuration and OpenSSH’s remote-command behavior; Anthropic’s MCP documentation does not provide a dedicated SSH recipe. Check the Claude Code MCP documentation and the OpenBSD ssh(1) manual for the underlying behavior.

Choose the connection method that matches the server

SSH is a route to a machine, not an MCP transport by itself. First find out how the MCP server actually communicates and where it runs. Claude Code documents stdio, HTTP, and SSE configuration; the right option depends on the server’s interface and network reachability.

Server situation Connection path What to account for
The server runs as a command-line process only on the SSH host and speaks MCP over stdin/stdout Launch it remotely through SSH, with local ssh configured as Claude Code’s stdio command Noninteractive SSH authentication, remote command availability, quoting, and clean protocol streams
The server exposes an HTTP or SSE endpoint reachable from your machine Configure Claude Code for that endpoint and its supported transport Exact endpoint URL and path, transport, and authentication
The server exposes HTTP or SSE only on a host reachable through SSH Forward a local port to the remote service, then configure Claude Code for the local endpoint Forwarding direction, local and remote ports, service bind address, endpoint path, and tunnel lifecycle

Use direct HTTP or SSE when the server endpoint is reachable and supported. Use SSH-launched stdio when the remote server is a command-line process. Use a tunnel when an HTTP/SSE service exists on the remote side but needs a network path to your local Claude Code process. The server’s own documentation determines its launch command, URL path, transport support, and authentication requirements.

Prepare SSH and the remote MCP command

  1. Verify SSH access without an interactive prompt. From the same machine and account that runs Claude Code, connect to the intended destination and confirm that authentication completes unattended. Set up an SSH key or agent access as appropriate for your environment.
  2. Test the server command remotely. Run the MCP server’s documented launch command in a noninteractive SSH session. Confirm the executable and required environment variables are available to that remote execution context; a command that works only in an interactive shell may fail when started by Claude Code.
  3. Confirm it speaks stdio MCP. A stdio server must use stdin/stdout for protocol traffic. Keep shell banners, startup messages, and debug output off stdout; direct diagnostics to stderr. Unexpected output can corrupt the stream or prevent Claude Code from establishing the connection.
  4. Use no pseudo-terminal. Add -T to the SSH invocation. OpenSSH documents that this disables pseudo-terminal allocation, which is appropriate when the connection carries a protocol stream rather than an interactive shell.

Configure Claude Code to launch the server over SSH

The following is an illustrative configuration shape. Replace mcp-host and the remote command with values for your SSH configuration and MCP server. The JSON demonstrates the documented pattern of a stdio server with a command and arguments; using ssh this way is an inference from the documented capabilities, not an Anthropic-verified SSH recipe. Validate the current configuration schema and command syntax in the live Claude Code MCP documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
{
  "mcpServers": {
    "remote-tools": {
      "command": "ssh",
      "args": ["-T", "mcp-host", "node /opt/mcp/server.js"]
    }
  }
}

In this example, mcp-host is an SSH destination such as a host alias configured in your SSH settings, and node /opt/mcp/server.js is the remote server command. Replace the Node.js command with the actual launch instruction for your server. Remote shell interpretation and quoting can vary by operating system, shell, and command, so test the exact invocation outside Claude Code first.

Register and inspect the server with the CLI

Claude Code documents claude mcp add for registering a server, claude mcp list and claude mcp get <name> for inspection, and claude mcp remove <name> for removal. Its interactive session also provides /mcp to inspect or manage MCP servers. The exact argument syntax and scope options can change, so check the Claude Code CLI reference before using a command-line example for your installed version.

Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Configuration scope matters: the documentation names local and user scopes and describes project-shared configuration in .mcp.json. Project-scoped servers require user approval before use for security. Choose a scope deliberately, especially when a shared project configuration could cause Claude Code to invoke a remote command on a teammate’s machine.

Connect through an SSH tunnel when the server uses HTTP or SSE

If the MCP server exposes HTTP or SSE rather than stdio, do not try to treat its endpoint as a stdio process. Claude Code documents HTTP and SSE registration, including forms such as claude mcp add --transport http <name> <url> and claude mcp add --transport sse <name> <url>. Check current syntax and server compatibility in the MCP documentation.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When that HTTP/SSE endpoint is accessible only from the SSH host, create an SSH local port forward from your machine to the remote service. Then configure Claude Code to use the corresponding local endpoint with the transport and path the server expects. OpenSSH supports TCP forwarding; the particular forwarding arguments depend on the service’s host and port, so verify the ssh(1) manual and your server’s network configuration rather than assuming a universal command.

  • Confirm the forwarding direction and the local port Claude Code will contact.
  • Confirm the remote host and port where the MCP service listens, and whether it is bound to loopback or another interface.
  • Use the exact URL path and transport supported by the server; HTTP and SSE endpoints are not interchangeable by assumption.
  • Keep the tunnel running for as long as Claude Code needs the endpoint. Decide how your environment will start, monitor, and stop it.
  • Check authentication separately: forwarding provides a network route, not application credentials.

Check that Claude Code can see and use the server

  1. Start or reload Claude Code after registering the server.
  2. Run claude mcp list to see configured servers, or claude mcp get remote-tools to inspect the named entry. In an interactive session, use /mcp.
  3. If the server is project-scoped, respond to any approval prompt before expecting it to be available.
  4. If it appears but fails to connect, test the SSH command or endpoint independently. Separate host access, remote process startup, transport, and authentication issues instead of changing several settings at once.

Troubleshoot common connection failures

Symptom Likely cause What to check or change
The MCP server fails to start SSH authentication blocks, the remote command is unavailable, or required environment variables are missing Test SSH and the exact remote command in a noninteractive terminal using the same local account. Check the remote execution environment and provide required variables through a suitable deployment configuration.
The connection closes immediately The command exits, does not launch an MCP server, or uses a different protocol Confirm the server remains running and that its documented mode speaks MCP over stdio. Test its launch command directly.
Protocol output is garbled or intermittent A pseudo-terminal or extraneous output is contaminating stdin/stdout Use ssh -T; remove shell startup banners and other stdout output from the remote launch path. Send diagnostics to stderr.
Startup waits indefinitely for a password or confirmation SSH is requesting interactive authentication or host confirmation Configure appropriate key or agent access and confirm the host in advance, then test an unattended connection. Do not put secrets directly in shared project configuration.
The forwarded endpoint cannot be reached Wrong forwarding direction or port, service bind-address mismatch, incorrect path, or transport mismatch Verify the local and remote ports, remote listener address, full endpoint path, and whether Claude Code is configured for the server’s actual HTTP or SSE transport.
The server does not appear in Claude Code It may be registered in another scope, not loaded, or awaiting approval Inspect with claude mcp list, claude mcp get <name>, or /mcp. Check the active configuration scope and approve a project server if prompted.

Or skip the browser setup

If your actual goal is to capture website screenshots for an MCP-enabled workflow, ScreenshotNeo offers a screenshot API and MCP server; it is separate from connecting a general-purpose MCP server over SSH. A single GET request can return a PNG, JPEG, WebP, or PDF. For example, with a ScreenshotNeo API key:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo documentation for request options. It can accept cookie/consent banners and remove more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each step can be turned off. Bot checks/CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and responses identify page verdict and billing status in headers. Its MCP server provides take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients.

ScreenshotNeo’s free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Learn about ScreenshotNeo or sign up for the free plan.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Frequently Asked Questions

Does Claude Code have a built-in SSH transport for MCP?

The cited Claude Code documentation describes stdio, HTTP, and SSE configuration, not a separate SSH transport. Running SSH as the command for a stdio server is a practical configuration approach, not a documented SSH-specific recipe.

Best Value
Yubico - YubiKey 5Ci - Multi-Factor authentication (MFA) Security Key and passkey for iPhone/Android/PC, Dual connectors for Lighting/USB-C, FIDO Certified
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Can I use this setup with any MCP server?

Only if the server supports the connection method you configure. The SSH-launched pattern requires a remotely launchable process that speaks MCP over stdin/stdout; an HTTP/SSE server needs its matching endpoint configuration, with a tunnel if necessary.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.