rigout
An MCP server that gives an AI agent a shell and the files on your machine. Start it, give your agent the command it prints, and the agent works there.
Install
pipx install rigout
Or run it without installing: uvx rigout. Needs Python 3.10 or newer.
Use
On the machine the agent should work on, in the folder it should start in:
rigout # this machine only, at http://127.0.0.1:8765/mcp
rigout share # reachable from anywhere, through a Cloudflare tunnel
It prints the URL, a token and the command for Claude Code:
claude mcp add --transport http rigout <url> --header "Authorization: Bearer <token>"
rigout share also copies that command to the clipboard when it can. For other clients:
rigout url --client cursor # or vscode, or raw
A client that starts local servers itself can run rigout stdio instead, with no URL or token.
Tools
| Tool | Does |
|---|---|
run |
Runs a shell command and returns its exit code and output. A command still running after about 50 seconds keeps going as a job. |
process |
Reads a job's output, waits for it, stops it, or lists jobs. |
read |
Reads a text file with line numbers. |
write |
Creates or replaces a file. |
edit |
Replaces an exact piece of text in a file. |
ls |
Lists a folder. |
glob |
Finds files by pattern, such as **/*.py. |
grep |
Searches file contents. Uses ripgrep when it is installed. |
Relative paths and commands start in the workspace: the folder rigout was started in, or
--workspace DIR. The agent is told this, and which shell run uses, when it connects.
Access
Rigout gives the agent the same access you have. There is no list of blocked commands.
Every request needs the token. It is created once, kept in your user state folder, and printed at
each start. Anyone with the URL and the token can run commands as you, so keep the token private.
rigout token --reset replaces it.
rigout share uses a quick tunnel, whose URL changes each start. For a URL that stays the same,
create a named Cloudflare tunnel with a hostname once, then run:
rigout share --tunnel NAME --hostname rigout.example.com
If cloudflared is not installed, rigout downloads it the first time.
Commands
rigout serve [--workspace DIR] [--port 8765] [--host 127.0.0.1]
rigout share [--workspace DIR] [--port 8765] [--tunnel NAME --hostname HOST]
rigout url [--client claude|cursor|vscode|raw]
rigout token [--reset]
rigout stdio [--workspace DIR]
rigout on its own is rigout serve.
License
Apache-2.0
Metadata
Release files for rigout 0.4.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| rigout-0.4.0.tar.gz | 23.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| rigout-0.4.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 50.0 kB
Release files / rigout-0.4.0.tar.gz
| Download URL | rigout-0.4.0.tar.gz |
|---|---|
| Size | 23.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
fa702cd5b1aef4765689e29f0bce153037054a11c04775185fc48ffb2707741a
|
|
BLAKE2b-256 checksum How to use checksums |
2417791fced54cd26d846e64989f8a00a4a3846a52b94015377692259840369e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 15, 2026.
Transparency logRelease files / rigout-0.4.0-py3-none-any.whl
| Download URL | rigout-0.4.0-py3-none-any.whl |
|---|---|
| Size | 26.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
aab52a2aacd4d4f089b089560ebfe5a5e52483b85d330f1fe124ac5bb161dde9
|
|
BLAKE2b-256 checksum How to use checksums |
5eeab6c973df53df383ae5adb2c21d7ed40cb9832ad3d578cea07c9adb979b92
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 15, 2026.
Transparency log