An SSH client built for AI agents
Plain ssh is made for a person at a terminal. Called once per tool call, it hangs on prompts, forgets every cd, and needs your passwords. xssh keeps connections and shells alive between calls, reports every state in one fixed line, and keeps secrets with you.
Install xssh: read https://xssh.io/llms.txt and follow it.
> irm https://xssh.io/install.ps1 | iex$ xssh session run w -- 'sudo apt-get upgrade' Do you want to continue? [Y/n] [xssh w waiting prompt=confirm] $ xssh session send w y --enter Setting up nginx (1.24.0-2ubuntu7.5) … [xssh w done exit=0] $ xssh session run w -- pwd /srv/app [xssh w done exit=0]
Your agent stops hanging on prompts
The same job, two ways. Bracketed lines are xssh's real status format.
$ ssh deploy@web1 'sudo apt-get upgrade' [sudo] password for deploy: … 120 s, no output …
The tool call times out at the password prompt. The agent retries, or asks you to paste the password into the chat.
$ xssh session run w -- 'sudo apt-get upgrade' Do you want to continue? [Y/n] [xssh w waiting prompt=confirm] $ xssh session send w y --enter [xssh w done exit=0]
sudo is answered from the keyring. The confirm prompt is reported and answered; the shell keeps its state for the next call.
One command, one exact result
Output is terse, ANSI-free and ends with an exit code or a next step. Built to be read by a model.
xssh host list- Saved servers with notes, tags, OS and last success.
xssh exec H -- cmd- Run on one host, a list, or @tag in parallel. Remote exit code returned as-is.
xssh session run N -- cmd- A shell that keeps cwd, env and running programs across calls. --persist survives drops.
xssh session send N …- Answer prompts; drive REPLs and full-screen apps: vim, top, a remote Claude Code.
xssh job start H -- cmd- Work that outlives tool timeouts and disconnects. Wait, tail, kill.
xssh file edit H PATH- Exact replacement, atomic, with backup. Refuses if the file changed meanwhile.
xssh cp SRC… DST- rsync-like copy local↔host and host↔host. Skips unchanged files, resumes large ones.
xssh forward add H -L …- -L, -R and SOCKS5 forwards held by the daemon.
xssh status | diag | logs H- Health snapshot, findings with the next command, journald or file logs.
xssh host trust H- A changed host key stops everything until a human confirms the fingerprint.
Six states. Never a guess.
Every session reply ends with one line in a fixed format. [xssh NAME STATE exit=CODE prompt=KIND]
- done
[xssh w done exit=0]Finished. Real exit code; cwd and env kept. - waiting
[xssh w waiting prompt=confirm]A prompt is open: password, confirm, input, repl, pager, shell. Answer with session send. - running
[xssh w running]Still producing output. Read again or wait. - quiet
[xssh w quiet]Running, silent. Wait with a timeout or check the screen. - tui
[xssh w tui]A full-screen app owns the terminal. The reply is the screen, selection marked. - disconnected
[xssh w disconnected]Connection dropped (exit 69). Persistent sessions reattach.
Secrets stay with you
Agents get capabilities, not credentials.
- Passwords and passphrases live in the OS keyring (Credential Manager, Keychain, Secret Service).
- You type them in a terminal or desktop dialog. Never in the chat.
- sudo prompts are filled from the keyring; output never contains the value.
- {secret:NAME} puts stored secrets into files and commands; replies show ***.
- A changed host key is never bypassed automatically.
$ xssh file edit db /srv/app/.env --old 'DB_PASS=old' --new 'DB_PASS={secret:dbpw}' --secrets edited /srv/app/.env (1 replacement) 12 DB_PASS=*** $ xssh host set-password db → you type it in a dialog; the agent never sees it
Install
Windows x64 today. Remote hosts: anything with a POSIX shell.
Tell your agent
It reads llms.txt, installs xssh, and installs its own skill.
Install xssh: read https://xssh.io/llms.txt and follow it.Or install it yourself
One PowerShell line, or unzip anywhere: the folder is the installation.
> irm https://xssh.io/install.ps1 | iexStore passwords
For servers without keys you type the password once. The agent only uses the alias.
> xssh host add web1 --host 10.0.0.5 --user deploy --ask-password
Skill installs for Claude Code · Codex · Gemini CLI · GitHub Copilot · Cursor · OpenCode · Windsurf · Amp · Qwen Code · Kiro · Trae · Roo Code · ~/.agents (Cline…)