PluginBench
MCP Server
Maintained
MIT

io.github.amol21p/interactive-terminal MCP Server

io.github.amol21p/interactive-terminal

Give AI agents real interactive terminal sessions — REPLs, SSH, databases, Docker with PTY support and 7-layer security.

What is the io.github.amol21p/interactive-terminal MCP server?

The mcp-interactive-terminal MCP server gives AI agents (Claude Code, Cursor, Windsurf) real interactive terminal sessions with PTY support. It enables running REPLs, SSH, database clients, and any interactive CLI with clean text output, smart completion detection, and comprehensive security controls.

This server bridges the gap between AI agents and interactive command-line tools. Instead of being limited to one-shot shell commands, agents can now maintain persistent terminal sessions, run Python/Node/Rails REPLs, connect to databases, SSH into servers, and interact with Docker containers. It uses node-pty for clean terminal emulation (exactly what a human would see) and includes 7 layers of security including dangerous command confirmation, input pattern detection, and optional sandboxing.

How to install io.github.amol21p/interactive-terminal

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • MCP_TERMINAL_MAX_SESSIONS

    Maximum concurrent sessions

  • MCP_TERMINAL_SANDBOX

    Enable OS-level kernel sandboxing

  • MCP_TERMINAL_REDACT_SECRETS

    Redact AWS keys, tokens, private keys in output

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "interactive-terminal": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-interactive-terminal"
      ],
      "env": {
        "MCP_TERMINAL_MAX_SESSIONS": "<YOUR_MCP_TERMINAL_MAX_SESSIONS>",
        "MCP_TERMINAL_SANDBOX": "<YOUR_MCP_TERMINAL_SANDBOX>",
        "MCP_TERMINAL_REDACT_SECRETS": "<YOUR_MCP_TERMINAL_REDACT_SECRETS>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • create_session — Spawn an interactive process (bash, python3, psql, ssh, etc.) with configurable command, arguments, working directory, environment variables, and terminal dimensions.
  • send_command — Send input to a session and get output with completion detection, timeout control, and output truncation. Dangerous commands are blocked unless confirmed via confirm_dangerous_command.
  • read_output — Read the current terminal screen of a session (read-only, safe to auto-approve).
  • list_sessions — List all active sessions with their IDs, names, commands, PIDs, and alive status (read-only, safe to auto-approve).
  • close_session — Terminate a session and kill its process.
  • send_control — Send control characters like ctrl+c, ctrl+d, tab, arrow keys, and other keyboard inputs to a session.
  • confirm_dangerous_command — Two-step safety confirmation for dangerous patterns (rm -rf, DROP TABLE, curl|bash, etc.). Agent must provide justification before execution.

Use cases

  • Run Python/Node/Ruby REPLs and test code interactively
  • Connect to PostgreSQL, MySQL, or other databases and execute queries
  • SSH into remote servers and run administrative commands
  • Execute Rails console for staging/production environments
  • Run Docker containers and inspect logs or shell into running containers
  • Use interactive CLI tools like vim, htop, or git interactively

io.github.amol21p/interactive-terminal MCP server FAQ

What is mcp-interactive-terminal?

It's an MCP server that gives AI agents like Claude Code and Cursor the ability to run real interactive terminal sessions. Unlike one-shot shell commands, it maintains persistent PTY sessions for REPLs, SSH, databases, and any interactive CLI.

Is it free?

Yes, mcp-interactive-terminal is open-source under the MIT license and free to use.

How do I install it in Cursor?

Go to Settings > MCP Servers, click Add Server, and enter the configuration with command 'npx' and args ['-y', 'mcp-interactive-terminal']. For Claude Code, run: claude mcp add terminal -- npx -y mcp-interactive-terminal

Does it require authentication?

No authentication is required for the server itself. However, the commands you run (like SSH or database connections) may require their own credentials, which you provide through the terminal session.

What security features does it have?

It includes 7 security layers: MCP tool annotations, confirmation flow for dangerous commands, input pattern detection (blocks rm -rf, DROP TABLE, etc.), command blocklist/allowlist, optional OS-level sandboxing, secret redaction, and resource limits.

What if node-pty fails to compile?

The server automatically falls back to pipe mode, which still supports interactive sessions but without full terminal emulation. To enable PTY mode, install build tools (xcode-select on macOS, build-essential on Ubuntu).

README (reference)

Source of truth, from the repository.

mcp-interactive-terminal

npm version License: MIT Node.js >= 18

MCP server that gives AI agents (Claude Code, Cursor, Windsurf, etc.) real interactive terminal sessions. Run REPLs, SSH, database clients, and any interactive CLI — with clean text output, smart completion detection, and 7-layer security.

Why This Exists

AI coding agents can't handle interactive commands. There's no PTY, no stdin streaming. You can't run rails console, python, psql, ssh, or any REPL through them. This MCP server fixes that.

AI Agent (Claude Code, Cursor, etc.)
    ↕  MCP (JSON-RPC over stdio)
mcp-interactive-terminal
    ↕  node-pty + xterm-headless
Interactive Process (rails console, python, psql, ssh, bash...)
    ↕
Clean text output (exactly what a human would see)

Install

Claude Code

claude mcp add terminal -- npx -y mcp-interactive-terminal

That's it. The server is now available. Ask Claude to "open a python REPL and calculate 2**100".

Cursor

Go to Settings > MCP Servers, click Add Server, and enter:

{
  "mcpServers": {
    "terminal": {
      "command": "npx",
      "args": ["-y", "mcp-interactive-terminal"]
    }
  }
}

Windsurf

Add to your MCP configuration:

{
  "mcpServers": {
    "terminal": {
      "command": "npx",
      "args": ["-y", "mcp-interactive-terminal"]
    }
  }
}

VS Code (GitHub Copilot)

Add to your .vscode/mcp.json:

{
  "servers": {
    "terminal": {
      "command": "npx",
      "args": ["-y", "mcp-interactive-terminal"]
    }
  }
}

Any MCP Client

The server communicates over stdio using the Model Context Protocol. Any MCP-compatible client can use it with the same npx -y mcp-interactive-terminal command.

Real-World Examples

Rails Console

You: "Open rails console for staging and check the user count"

Agent creates session → bash
Agent sends: cd /path/to/app && rails console -e staging
Agent sends: User.count
Agent returns: 1,847,293

Python REPL

You: "Open python and test my sorting algorithm"

Agent creates session → python3
Agent sends: def quicksort(arr): ...
Agent sends: quicksort([3, 1, 4, 1, 5, 9])
Agent returns: [1, 1, 3, 4, 5, 9]

Database Client

You: "Connect to postgres and show me the largest tables"

Agent creates session → psql -U myuser mydb
Agent sends: SELECT tablename, pg_size_pretty(pg_total_relation_size(tablename::text)) ...
Agent returns: formatted table of results

SSH

You: "SSH into the staging server and check disk usage"

Agent creates session → ssh user@staging.example.com
Agent sends: df -h
Agent returns: disk usage table

Docker

You: "Open a shell in my running container and check the logs"

Agent creates session → docker exec -it my-container bash
Agent sends: tail -100 /var/log/app.log
Agent returns: last 100 log lines

Node.js REPL

You: "Open node and test the date parsing logic"

Agent creates session → node
Agent sends: new Date('2024-02-29').toISOString()
Agent returns: 2024-02-29T00:00:00.000Z

Tools

The server exposes 7 MCP tools:

create_session — Spawn an interactive process

{ "command": "python3", "name": "my-python", "cwd": "/project" }
→ { "session_id": "a1b2c3d4", "name": "my-python", "pid": 12345 }
ParameterRequiredDefaultDescription
commandYes—Command to run (bash, python3, psql, ssh, etc.)
argsNo[]Command arguments
nameNoautoHuman-readable session name
cwdNoserver cwdWorking directory
envNo{}Additional environment variables
colsNo120Terminal columns
rowsNo40Terminal rows

send_command — Send input and get output

{ "session_id": "a1b2c3d4", "input": "1 + 1" }
→ { "output": "2", "is_complete": true, "is_alive": true }
ParameterRequiredDefaultDescription
session_idYes—Target session
inputYes—Command/input to send (newline appended automatically)
timeout_msNo5000Max wait time for output
max_output_charsNo20000Truncate output beyond this

Dangerous commands (rm -rf, DROP TABLE, curl|bash, etc.) are blocked — the agent must use confirm_dangerous_command first.

read_output — Read terminal screen (read-only)

{ "session_id": "a1b2c3d4" }
→ { "output": ">>> ", "is_alive": true }

Safe to auto-approve — this only reads, never sends input.

list_sessions — List active sessions (read-only)

→ [{ "session_id": "a1b2c3d4", "name": "my-python", "command": "python3", "pid": 12345, "is_alive": true }]

Safe to auto-approve.

close_session — Kill a session

{ "session_id": "a1b2c3d4" }
→ { "success": true }

send_control — Send control characters

{ "session_id": "a1b2c3d4", "control": "ctrl+c" }
→ { "output": "^C\n>>>" }

Supported: ctrl+c, ctrl+d, ctrl+z, ctrl+l, ctrl+r, tab, escape, up, down, left, right, enter, backspace, delete, home, end, and more.

confirm_dangerous_command — Two-step safety confirmation

{ "session_id": "a1b2c3d4", "input": "rm -rf /tmp/old", "justification": "Cleaning up stale temp files from failed build" }
→ { "output": "...", "is_complete": true, "is_alive": true }

Required when send_command detects a dangerous pattern. The agent must explain why the command is necessary. This is a separate tool — even if send_command is auto-approved, this requires its own permission.

How It Works

Two Terminal Modes

PTY mode (default) — uses node-pty + @xterm/headless (the same terminal emulator as VS Code):

  • Clean output — the AI sees exactly what a human would see on screen
  • Cursor positioning, progress bars, \r overwrites all render correctly
  • Full keyboard: arrow keys, tab completion, ctrl+c/d/z, home/end
  • Terminal resize, TUI apps (vim, htop, top), 256-color, 1000-line scrollback

Pipe mode (automatic fallback) — activates when node-pty can't load (e.g., in sandboxed environments):

  • Interactive sessions still work via child_process.spawn with auto-injected flags (python -u -i, bash -i, etc.)
  • ANSI codes stripped, control keys still work
  • No terminal emulation, but covers the basics

The mode is selected automatically — PTY is tried first, pipe mode kicks in if it fails.

What the AI sees: PTY vs Pipe

ScenarioPTY modePipe mode
printf "\rProgress: 3/3"Progress: 3/3Progress: 1/3Progress: 2/3Progress: 3/3
ANSI colorsStripped cleanlyStripped via regex
vim, htop, topReadable screenGarbled
Arrow keys, tab completionWorksWorks
Terminal resizeWorksNo-op

Smart "Command Done" Detection

Instead of blindly waiting a fixed time, the server uses a layered strategy:

  1. Process exit — if the process died, command is done
  2. Prompt detection — auto-detects the session's prompt at startup (bash $, python >>>, psql #, etc.), watches for it to reappear
  3. Output settling — no new output for 300ms = probably done
  4. Timeout — always returns after timeout_ms with is_complete: false

Security

Seven-layer defense-in-depth:

LayerWhat It DoesDefault
MCP Tool AnnotationsreadOnlyHint/destructiveHint on each toolAlways on
Confirmation FlowDangerous patterns require confirm_dangerous_commandAlways on
Input Pattern DetectionDetect rm -rf, DROP TABLE, curl|bash, etc.Always on
Command Blocklist/AllowlistBlock/allow specific commandsConfigurable
OS-Level SandboxKernel-level process sandboxing via @anthropic-ai/sandbox-runtimeOff (opt-in)
Secret RedactionRedact AWS keys, tokens, private keys in outputOff (opt-in)
Resource LimitsMax sessions, output cap, idle timeout, audit loggingAlways on

Recommended Permissions

Only auto-approve the read-only tools:

{
  "permissions": {
    "allow": [
      "mcp__terminal__list_sessions",
      "mcp__terminal__read_output"
    ]
  }
}

This way send_command, create_session, and especially confirm_dangerous_command always require human approval.

Configuration

All settings via environment variables. Pass them in your MCP config:

{
  "mcpServers": {
    "terminal": {
      "command": "npx",
      "args": ["-y", "mcp-interactive-terminal"],
      "env": {
        "MCP_TERMINAL_ALLOWED_COMMANDS": "bash,python3,node,psql",
        "MCP_TERMINAL_REDACT_SECRETS": "true",
        "MCP_TERMINAL_IDLE_TIMEOUT": "300000"
      }
    }
  }
}
VariableDefaultDescription
MCP_TERMINAL_MAX_SESSIONS10Max concurrent sessions
MCP_TERMINAL_MAX_OUTPUT20000Max output chars per read
MCP_TERMINAL_DEFAULT_TIMEOUT5000Default wait timeout (ms)
MCP_TERMINAL_BLOCKED_COMMANDS—Comma-separated blocklist
MCP_TERMINAL_ALLOWED_COMMANDS—Comma-separated allowlist (if set, only these are allowed)
MCP_TERMINAL_ALLOWED_PATHS—Comma-separated paths sessions can access
MCP_TERMINAL_REDACT_SECRETSfalseRedact AWS keys, tokens, private keys in output
MCP_TERMINAL_LOG_INPUTSfalseLog all inputs to stderr (for debugging)
MCP_TERMINAL_IDLE_TIMEOUT1800000Auto-close idle sessions (ms, default 30min, 0 = disabled)
MCP_TERMINAL_DANGER_DETECTIONtrueEnable dangerous command confirmation flow
MCP_TERMINAL_AUDIT_LOG—Path to JSON audit log file
MCP_TERMINAL_SANDBOXfalseEnable OS-level kernel sandboxing
MCP_TERMINAL_SANDBOX_ALLOW_WRITE/tmpWritable paths in sandbox mode
MCP_TERMINAL_SANDBOX_ALLOW_NETWORK*Allowed network domains in sandbox

Troubleshooting

"Tools not showing up" / Server fails silently

MCP servers that fail to start often show no error in the client. Check:

# Test the server directly:
npx -y mcp-interactive-terminal

# You should see "[mcp-terminal] Starting MCP Interactive Terminal Server" on stderr.
# If you see an error, that's what's failing.

Node.js version too old

The server requires Node.js >= 18. If you see errors about unsupported syntax or missing APIs:

node --version  # Must be >= 18

# If using nvm:
nvm install 18 && nvm use 18

# If using volta:
volta install node@18

For nvm/volta/fnm users: npx may use a different Node version than your shell. Use an absolute path:

{
  "mcpServers": {
    "terminal": {
      "command": "/Users/you/.nvm/versions/node/v22.0.0/bin/npx",
      "args": ["-y", "mcp-interactive-terminal"]
    }
  }
}

Find your path with: which npx

node-pty compilation errors

node-pty is a native module that requires build tools. If it fails to compile, the server automatically falls back to pipe mode — interactive sessions still work, just without terminal emulation.

If you want full PTY support:

# macOS:
xcode-select --install

# Ubuntu/Debian:
sudo apt-get install -y make python3 build-essential

# RHEL/Fedora:
sudo yum install -y make python3 gcc gcc-c++

Session dies immediately

Some commands need to be run inside a shell rather than directly:

# Instead of:  create_session({ command: "rails console -e staging" })
# Do this:     create_session({ command: "bash" })
#              send_command({ input: "rails console -e staging" })

This is because create_session runs the command directly (like exec), not through a shell. Spawning bash first gives you a full shell environment.

Output looks garbled

If output contains escape codes or looks wrong, you're likely in pipe mode (node-pty failed to load). Check the server logs for "falling back to pipe mode". Install build tools (see above) to enable PTY mode.

Timeout too short for long-running commands

Increase the timeout per-command:

{ "session_id": "...", "input": "bundle install", "timeout_ms": 60000 }

Or globally via environment variable:

{ "env": { "MCP_TERMINAL_DEFAULT_TIMEOUT": "30000" } }

Comparison with Alternatives

Featuremcp-interactive-terminalApp-specific terminal serversGeneric shell MCP servers
Cross-platformYesOften single-app onlyVaries
Clean output (xterm-headless)YesNo (screen scrape)No (raw PTY dump)
Smart completion detection4-layer algorithmNoBasic timeout
Security layers7 (confirmation flow, sandbox, redaction, etc.)NoneBasic
Dangerous command confirmationYes (separate tool)NoNo
MCP tool annotationsYesNoNo
Background sessionsYesNo (uses active tab)Yes
Focused API7 tools2-3 tools15-20+ tools (scope creep)
Installnpx -y (zero-config)Requires specific appVaries

Development

git clone https://github.com/amol21p/mcp-interactive-terminal.git
cd mcp-interactive-terminal
npm install
npm run build
npm test

Test with MCP Inspector:

npx @modelcontextprotocol/inspector dist/index.js

License

MIT

Related MCP servers

Upscale images to print-ready files (TIFF/PNG/JPG) via PrintScale.

0
JavaScript
MIT
View repository →

MCP connector for human-reviewed manufacturing tasks through MadeForAI hosted fulfillment.

1
TypeScript
MIT
View repository →
TATalamus logo

Talamus

Active

Local-first, source-grounded memory that survives AI agent sessions.

3
Python
Apache-2.0
View repository →

Generate invoice, receipt, and report PDFs from structured JSON via a single API call.

View repository →

Free open-source resume builder with AI integration and multiple export formats.

41k
TypeScript
MIT
View repository →

Search and book real photographers on Kadro (Iran) on a user's behalf, ending with a payment link.

0
TypeScript
MIT
View repository →