Termius MCP
stdio MCP server for Termius Cloud.
Repository: MiaM1ku/termius-mcp.
termius with no arguments is the MCP server. An MCP client starts that
binary with no args. The process speaks newline-delimited JSON-RPC on
stdin/stdout (MCP stdio). It negotiates protocolVersion 2025-11-25 or
2025-06-18 (echoes the client when supported). Login, vault sync, host
lookup, SSH exec, and SFTP file transfer are tools.
termius login signs in from a terminal. Use it for Google SSO, email and
password, and OTP.
This tree talks to Termius desktop 10.0.6 APIs (DeviceToken, SRP / gRPC
login, RNCryptor v3 and Sodium v4/v5, v4/terminal/sync/).
Install
Python 3.9+ is required.
The PyPI name is termius-mcp. The official Termius CLI already uses termius.
After install, the command is still termius.
pip install termius-mcp
On Debian/Ubuntu (PEP 668) use a venv or pipx:
pipx install termius-mcp
From a git clone:
python3 -m venv ~/.local/share/termius-mcp
~/.local/share/termius-mcp/bin/pip install -U pip
~/.local/share/termius-mcp/bin/pip install -e .
ln -sf ~/.local/share/termius-mcp/bin/termius ~/.local/bin/termius
Point the MCP client at that binary. Do not pass mcp or other args.
Do not pass login in the MCP client args list.
Claude / generic (contrib/mcp/termius.mcp.json):
{
"mcpServers": {
"termius": {
"command": "termius",
"args": []
}
}
}
Codex (contrib/mcp/codex.toml, merge into ~/.codex/config.toml):
[mcp_servers.termius]
command = "termius"
args = []
startup_timeout_sec = 30.0
tool_timeout_sec = 60.0
Pi / OMP (~/.omp/agent/mcp.json):
{
"mcpServers": {
"termius": {
"type": "stdio",
"command": "termius",
"args": []
}
}
}
Restart the MCP client after you edit the config. connecting [stdio] is the
handshake. It becomes connected when initialize succeeds. Sign in with
termius login before that, or use the login tools after connect.
Optional environment variables:
| Variable | Purpose |
|---|---|
TERMIUS_VAULT_PASSWORD |
Vault encryption password (preferred over the remember file) |
TERMIUS_SYNC_TTL |
Seconds before the next automatic pull. Default 60. 0 pulls on every read. |
First-time setup
Sign in from a terminal, then start the MCP client.
Terminal login
termius login
The command prompts for google or email when stdin is a TTY.
You can also pass the method:
termius login google
termius login email -u you@example.com
Google:
- Open the printed
https://account.termius.com/sso/desktop?...URL. - Sign in with Google.
- When the page tries to open Termius, copy
termius://app/continue-sso?.... - Paste that URL.
- Enter the vault encryption password from the Termius app. This is not the Google password.
- If 2FA is on, enter the OTP.
Email:
- Enter the Termius email if you did not pass
-u. - Enter the vault / account password.
- If 2FA is on, enter the OTP.
TERMIUS_VAULT_PASSWORD supplies the vault password and skips the prompt.
Default remember writes ~/.termius/vault mode 0600. Pass --no-remember
to skip that file.
Check the session:
termius status
Sign out:
termius logout
MCP tools
After the server is connected, you can also use the tools.
If ~/.termius/config already has a DeviceToken (a previous login):
- Call
status. Expectlogged_in: trueand oftenvault_remembered: false. - Call
syncwith the vault encryption password from the Termius app (not the Google password). Defaultremember=truewrites~/.termius/vaultmode0600. - Call
hosts. Later reads auto-pull when the cache is older thanTERMIUS_SYNC_TTL.
If this machine has never signed in and you are not using termius login:
- Call
status. Expectlogged_in: false. - Google: call
loginwithmethod=google. Open the returned URL. Sign in. When the page tries to open Termius, copytermius://app/continue-sso?.... Calllogin_completewith that URL and the vault encryption password. - Email: call
loginwithmethod=email, username, and the vault password. Addotpif 2FA is on. - Call
hosts.
The process never returns the vault password in a tool result.
Tools
Call status first.
| Tool | Purpose |
|---|---|
status |
Login state, last sync, stale flag, vault remembered, counts. Does not pull. |
login |
method=email with username + password, or method=google to get an SSO URL |
login_complete |
Finish Google SSO with callback_url + vault password |
logout |
Clear the session, remembered password, and local inventory |
sync |
Force a cloud pull now |
hosts |
List hosts (optional query) |
host |
One host + merged SSH settings + ssh_command |
exec |
Run a remote command over SSH |
files |
SFTP list / stat / read / write / get / put / mkdir / rm / rename |
inventory |
kind=groups|identities|keys|snippets |
hosts, host, exec, files, and inventory pull automatically when the
local cache is older than TERMIUS_SYNC_TTL and a vault password is available.
files uses SFTP on the same SSH credentials as exec. get and put copy
between the MCP host filesystem and the remote host. read and write move
file content through the tool result (max 200000 bytes). get and put allow
up to 50 MiB. list defaults path to the SSH login directory.
Local data
After a successful pull, decrypted inventory lives in:
~/.termius/config— DeviceToken, salts,last_synced~/.termius/storage— hosts, groups, identities, keys, snippets (plaintext JSON)~/.termius/ssh_keys/— private key files~/.termius/vault— remembered vault password, if you choseremember
Treat that directory as secret.
Encryption notes
Termius Cloud currently has two personal encryption schemas:
- v3 — per-field RNCryptor (AES-CBC + HMAC). REST login is enough.
- v5 — entity
contentblobs sealed with Argon2id + XChaCha20-Poly1305, plus SRP login.
The server auto-detects ciphertext version (A… = v3, B… = v5). Login uses
gRPC/SRP first (desktop login_v2); REST is only the fallback for accounts
that are not migrated (NOT_MIGRATED). For v5 SRP the vault password is Argon2id-hashed (libsodium interactive,
16-byte salt) and base64-encoded, then proven with Botan SRP-6a
modp/srp/8192 + Blake2b-512. public_data / proof are
uppercase hex without a 0x prefix (Android libtermius strips
Botan's prefix before the gRPC/Socket.IO payload).
Team vaults: sync / auto-pull loads /api/v4/team/vault/keys/, unwraps each encrypted_with key with the personal X25519 keypair (ECDH + HChaCha20 + XChaCha20-Poly1305), and decrypts shared hosts/keys/identities. Entities whose vault key is missing are skipped, not deleted.
License
See LICENSE.
Metadata
Release files for termius-mcp 3.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| termius_mcp-3.0.0.tar.gz | 71.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| termius_mcp-3.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 151.3 kB
Release files / termius_mcp-3.0.0.tar.gz
| Download URL | termius_mcp-3.0.0.tar.gz |
|---|---|
| Size | 71.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a66b4b3148d35073bc722cf501e2dfa6395c6aa22c695492550482593c14f533
|
|
BLAKE2b-256 checksum How to use checksums |
bb05feb29d2f83440dc24a73197e67229a0c652ecff47750cd359383bf1f1011
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.2
|
Release files / termius_mcp-3.0.0-py3-none-any.whl
| Download URL | termius_mcp-3.0.0-py3-none-any.whl |
|---|---|
| Size | 80.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f2263cea401964458f384d61a14425d677092e4db7118059e8801daf45f435cb
|
|
BLAKE2b-256 checksum How to use checksums |
53b132c48cc52c573adcbd3bbe51ebb77188a364a5c39a78c95e870edef6074f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.2
|