# in.termal/termalin-web

> Run commands and read/write files on your servers over Termalin's keyless tunnels (hosted MCP).

- name: in.termal/termalin-web
- version: 1.0.0
- connection class: R1 (autonomous)
- trust: 79/100 flags: no-repository
- quality: 75/100 (good)
- owner: not claimed
- descriptor: https://api.protogrid.dev/v1/servers/in.termal%2Ftermalin-web
- tools: https://api.protogrid.dev/v1/servers/in.termal%2Ftermalin-web/tools

**An agent can connect on its own if it already holds `TERMALIN_WEB_TOKEN`.** Remote endpoint behind a static API key or header. The registry never sees the value; the agent fills the placeholder.

## Connection (mcpServers)

```json
{
  "mcpServers": {
    "termalin-web": {
      "type": "http",
      "url": "https://termal.in/api/v1/mcp",
      "headers": {
        "Authorization": "Bearer ${TERMALIN_WEB_TOKEN}"
      }
    }
  }
}
```

Placeholders to fill: `${TERMALIN_WEB_TOKEN}`.

## Trust

- hygiene: 80
- liveness: 98
- freshness: 85
- provenance: 55
- drivers: +dns-namespace +website +reachable +uptime-95% ~updated-66d-ago -no-repository
- Derived from observable signals (official registry feed and our own credential-free probes); no code audit performed.

## Quality 75/100 (good)

### protocol: 75 (weight 25)

- warn `protocol.modern`: newest supported version is 2025-06-18; 2026-07-28 not supported, older versions are deprecated until 2027-07-28
- n/a `protocol.stateless`: only applies to 2026-07-28 servers
- pass `protocol.transport`: streamable HTTP
- n/a `protocol.list_ttl`: only applies to 2026-07-28 servers

### authorization: n/a (weight 15)

- n/a `auth.prm`, `auth.as_metadata`, `auth.cimd`: no remote uses OAuth
- n/a `auth.secret_in_url`: no templated URL

### tool hygiene: 100 (weight 30)

- pass `tools.descriptions`: every tool has a description
- pass `tools.description_length`: descriptions are concise
- pass `tools.schemas`: every tool has an object input schema
- pass `tools.annotations`: 14 of 14 tools declare readOnlyHint or destructiveHint
- pass `tools.directory_hints`: every tool declares readOnlyHint, destructiveHint, idempotentHint and openWorldHint
- pass `tools.token_cost`: about 2,756 tokens to load every tool
- pass `tools.api_dump`: tools are not a one-to-one API dump

### stability: 25 (weight 15)

- warn `stability.changes`: 16 tool changes in 30 days
- fail `stability.rug_pull`: 2 tools kept their name but changed most of their description in 30 days; review before trusting them

### dependencies: n/a (weight 15)

- n/a `deps.known_vulns`, `deps.mcp_sdk_version`, `deps.resolvable`: no npm or PyPI package

- tools: 14, about 2,756 tokens to load them all
- tool set hash: 49d1e5f45ad048721cdbb4799efec1ef
- tools last changed: 2026-10-08T01:00:34.405Z
- badge: [![protogrid quality](https://protogrid.dev/badge/in.termal/termalin-web.svg)](https://protogrid.dev/servers/in.termal/termalin-web)
- Checks run on what our credential-free, read-only probes observe; tools are never called and no code audit is performed.

### Tool changes

- 2026-10-08 `hosts_list` changed (description, annotations)
  - before: List the servers reachable through Termalin (your tunnel agents). Returns id, name, whether the server is online, the user commands run as, when it was last seen and its country. Use the id (or the exact name) as 'host' in the other tools.
  - after: List the servers reachable through Termalin (your tunnel agents). Returns id, name, whether the server is online, the user commands run as, when it was last seen, its country, and ownerNote — what the owner wrote about that server for you (what it is, what to leave alone); follow it. Use the id (or the exact name) as 'host' in the other tools.
- 2026-10-06 `data_schema` added
  - Describe one table of a database on one of your servers: its columns with type, whether they can be empty, default value and primary key. Call it before writing a query against a table you have not seen. Works for postgres, mysql, mariadb and sqlite.
- 2026-10-06 `data_tables` changed (annotations)
- 2026-10-06 `data_query` changed (annotations)
- 2026-10-06 `sftp_write` changed (annotations)
- 2026-10-06 `sftp_read` changed (annotations)
- 2026-10-06 `sftp_list` changed (annotations)
- 2026-10-06 `job_list` added
  - List the recent background jobs on a server (newest first): id, state, start time and the command.
- 2026-10-06 `job_stop` added
  - Stop a background job started with job_start (asks it to terminate, then forces it after two seconds). Does nothing if the job already finished.
- 2026-10-06 `job_status` added
  - Check a background job started with job_start: whether it is still running or finished (with its exit code), when it started, and the last lines of its output.

Full history: https://api.protogrid.dev/v1/servers/in.termal%2Ftermalin-web/changes

## Remotes

- https://termal.in/api/v1/mcp (streamable-http, auth api_key ${TERMALIN_WEB_TOKEN}, reachable true, uptime30d 0.94666666)

## Packages

_none_

## Tools (14)

- `data_query`: Run a database query on one of your servers — passwordless. It executes the engine's own client on the host over Termalin's keyless tunnel, using the database's local trust (Postgres peer auth via `sudo -u postgres`, MySQL/MariaDB unix-socket via `sudo mysql`, redis-cli, mongosh, sqlite3) — so no database password is needed or stored anywhere. Read-only by default: only SELECT/SHOW-style statements run unless allowWrites is set (full-access keys only). SQL engines return CSV/TSV with a header. For MongoDB pass a shell expression, e.g. db.products.find({}).limit(20).toArray().
- `data_schema`: Describe one table of a database on one of your servers: its columns with type, whether they can be empty, default value and primary key. Call it before writing a query against a table you have not seen. Works for postgres, mysql, mariadb and sqlite.
- `data_tables`: List the tables / collections / keys of a database on one of your servers — passwordless, over the same local-client path as data_query.
- `generate_password`: Generate a strong random password — handy when creating a user or setting a password on a server. Returns the password only; nothing is stored.
- `hosts_list`: List the servers reachable through Termalin (your tunnel agents). Returns id, name, whether the server is online, the user commands run as, when it was last seen, its country, and ownerNote — what the owner wrote about that server for you (what it is, what to leave alone); follow it. Use the id (or the exact name) as 'host' in the other tools.
- `job_list`: List the recent background jobs on a server (newest first): id, state, start time and the command.
- `job_start`: Start a long-running shell command on a server in the background and return a job id right away. Use it for anything that can take more than about a minute — package installs, builds, backups, migrations, large downloads. The job keeps running after this call returns and survives the connection closing; its output goes to a log you read with job_status. The command runs from the login user's home directory.
- `job_status`: Check a background job started with job_start: whether it is still running or finished (with its exit code), when it started, and the last lines of its output.
- `job_stop`: Stop a background job started with job_start (asks it to terminate, then forces it after two seconds). Does nothing if the job already finished.
- `sftp_list`: List a directory on one of your servers over SFTP. Returns each entry's name, whether it's a directory, size and modified time. Runs keyless over Termalin's tunnel, like ssh_exec.
- `sftp_read`: Read a text file from one of your servers over SFTP and return its contents. Files over 512 KB or non-text (binary) files are refused — use ssh_exec (e.g. sed/tail) for those.
- `sftp_write`: Create or overwrite a text file on one of your servers over SFTP. 'content' is written as UTF-8. Capped at 512 KB; for binary uploads use a terminal/scp instead.
- `ssh_exec`: Run a single shell command on one of your servers and return its combined output and exit code. Runs keyless over Termalin's tunnel — no SSH key, and the server needs no open inbound port. Each call is a fresh shell (cd does not persist — chain with &&). Keep a call under about 90 seconds: for anything longer (installs, builds, backups) use job_start and check on it with job_status.
- `ssh_exec_many`: Run the same shell command on several of your servers at once and return each server's output and exit code. Use it to compare or check a fleet (disk space, versions, a service's state) in one call instead of one call per server. Up to 10 servers; the same 90-second limit as ssh_exec applies.
