An agent can connect on its own if it already holds TERMALIN_WEB_TOKEN.Remote endpoint behind a static API key or header. The registry never sees the value; the agent fills the placeholder.
tools.schemasevery tool has an object input schema
pass
tools.annotations14 of 14 tools declare readOnlyHint or destructiveHint
pass
tools.directory_hintsevery tool declares readOnlyHint, destructiveHint, idempotentHint and openWorldHint
pass
tools.token_costabout 2,756 tokens to load every tool
pass
tools.api_dumptools are not a one-to-one API dump
stability25 · weight 15
warn
stability.changes16 tool changes in 30 days
fail
stability.rug_pull2 tools kept their name but changed most of their description in 30 days; review before trusting them
dependenciesn/a · weight 15
n/a
deps.known_vulns, deps.mcp_sdk_version, deps.resolvableno npm or PyPI package
14 tools, about 2,756 tokens to load them all · tool set 49d1e5f45ad0 · tools last changed 2026-10-08 · checked 2026-10-09 23:53 UTC
Tool changes
hosts_listchangeddescription, annotations
before
List the servers reachable through Termalin (your tunnel agents). Returns id, name, whether the server is online, the user commands run as, when it was last seen and its country. Use the id (or the exact name) as 'host' in the other tools.
after · 75% of words in common
List the servers reachable through Termalin (your tunnel agents). Returns id, name, whether the server is online, the user commands run as, when it was last seen, its country, and ownerNote — what the owner wrote about that server for you (what it is, what to leave alone); follow it. Use the id (or the exact name) as 'host' in the other tools.
data_schemaadded
Describe one table of a database on one of your servers: its columns with type, whether they can be empty, default value and primary key. Call it before writing a query against a table you have not seen. Works for postgres, mysql, mariadb and sqlite.
data_tableschangedannotations
data_querychangedannotations
sftp_writechangedannotations
sftp_readchangedannotations
sftp_listchangedannotations
job_listadded
List the recent background jobs on a server (newest first): id, state, start time and the command.
job_stopadded
Stop a background job started with job_start (asks it to terminate, then forces it after two seconds). Does nothing if the job already finished.
job_statusadded
Check a background job started with job_start: whether it is still running or finished (with its exit code), when it started, and the last lines of its output.
Derived from observable signals (official registry feed and our own credential-free probes); no code audit performed. How it is computed.
Endpoints
remote
auth
reachable
uptime 30d
p50
protocol
last ok
https://termal.in/api/v1/mcpstreamable-http
api_key ${TERMALIN_WEB_TOKEN}
yes
95%
520 ms
2025-06-18
2026-10-09
Tools (14)
data_querydestructive
Run a database query on one of your servers — passwordless. It executes the engine's own client on the host over Termalin's keyless tunnel, using the database's local trust (Postgres peer auth via `sudo -u postgres`, MySQL/MariaDB unix-socket via `sudo mysql`, redis-cli, mongosh, sqlite3) — so no database password is needed or stored anywhere. Read-only by default: only SELECT/SHOW-style statements run unless allowWrites is set (full-access keys only). SQL engines return CSV/TSV with a header. For MongoDB pass a shell expression, e.g. db.products.find({}).limit(20).toArray().
data_schemaread-only
Describe one table of a database on one of your servers: its columns with type, whether they can be empty, default value and primary key. Call it before writing a query against a table you have not seen. Works for postgres, mysql, mariadb and sqlite.
data_tablesread-only
List the tables / collections / keys of a database on one of your servers — passwordless, over the same local-client path as data_query.
generate_passwordread-only
Generate a strong random password — handy when creating a user or setting a password on a server. Returns the password only; nothing is stored.
hosts_listread-only
List the servers reachable through Termalin (your tunnel agents). Returns id, name, whether the server is online, the user commands run as, when it was last seen, its country, and ownerNote — what the owner wrote about that server for you (what it is, what to leave alone); follow it. Use the id (or the exact name) as 'host' in the other tools.
job_listread-only
List the recent background jobs on a server (newest first): id, state, start time and the command.
job_startdestructive
Start a long-running shell command on a server in the background and return a job id right away. Use it for anything that can take more than about a minute — package installs, builds, backups, migrations, large downloads. The job keeps running after this call returns and survives the connection closing; its output goes to a log you read with job_status. The command runs from the login user's home directory.
job_statusread-only
Check a background job started with job_start: whether it is still running or finished (with its exit code), when it started, and the last lines of its output.
job_stopdestructive
Stop a background job started with job_start (asks it to terminate, then forces it after two seconds). Does nothing if the job already finished.
sftp_listread-only
List a directory on one of your servers over SFTP. Returns each entry's name, whether it's a directory, size and modified time. Runs keyless over Termalin's tunnel, like ssh_exec.
sftp_readread-only
Read a text file from one of your servers over SFTP and return its contents. Files over 512 KB or non-text (binary) files are refused — use ssh_exec (e.g. sed/tail) for those.
sftp_writedestructive
Create or overwrite a text file on one of your servers over SFTP. 'content' is written as UTF-8. Capped at 512 KB; for binary uploads use a terminal/scp instead.
ssh_execdestructive
Run a single shell command on one of your servers and return its combined output and exit code. Runs keyless over Termalin's tunnel — no SSH key, and the server needs no open inbound port. Each call is a fresh shell (cd does not persist — chain with &&). Keep a call under about 90 seconds: for anything longer (installs, builds, backups) use job_start and check on it with job_status.
ssh_exec_manydestructive
Run the same shell command on several of your servers at once and return each server's output and exit code. Use it to compare or check a fleet (disk space, versions, a service's state) in one call instead of one call per server. Up to 10 servers; the same 90-second limit as ssh_exec applies.