SSH, SFTP and agents that run on your server
Connecting to a server, moving files and running an agent there happen in the same app. The SSH page keeps your saved servers, tabbed sessions and file browser together.
SSH manager
Save servers with groups, tags, colors and notes. Use the SSH agent, a key file or a password stored encrypted in the Keychain.
- ProxyJump chains; local, remote and SOCKS port forwarding.
- Keepalive, agent forwarding and a startup command.
- Import ~/.ssh/config, test connections, tabbed sessions and reconnect.
- Snippets; list, generate and copy keys, and install them with ssh-copy-id.
SFTP and FTP/FTPS
Two-pane browsing (local and server), drag and drop including from Finder or your file manager, upload, download, rename, delete and chmod (SFTP). Edit text files and save them back to the server; transfers show in a progress list.
Agents on the server
When creating an agent, pick a saved SSH server and folder as where it runs. Claude Code or Codex runs on the server with that server’s own CLI login and is managed in AgentVera like a local agent. Running on a server is supported for Cursor and Antigravity too.
Agent access: you set the rules
This part is in the Pro and Team plans; the rest of the SSH manager works on every plan. Turn on “agents can run commands on this server” when editing a server, and agents that take MCP can list your saved servers and run commands on them. Agents never see the connection details or the password; every request goes through a local bridge inside the app that checks the rules and logs it.
- Agent access is off for every server by default; when on, the level defaults to “ask on changes”. The other levels are read-only and unrestricted.
- Allow and deny lists; the deny list starts with commands like rm -rf /, mkfs, dd, shutdown and reboot and applies at every level, even inside a chain.
- Redirects, $(), backticks, sudo, su and doas are never treated as read-only.
- Commands run non-interactively: 120-second timeout by default, 600 at most; output is capped at 60 KB.
- The SSH page keeps a log of agent commands per server: ran, approved, rejected by you, blocked by a rule, or error.
Questions
Which account does a server agent use?
The server CLI’s own login. The CLI needs to be installed and signed in on the server.
Where are passwords stored?
Encrypted in your operating system’s keychain.
Can I use my existing ~/.ssh/config?
Yes. Import it in one go.
Can agents run any command on my server?
No. Agent access is off for every server by default. When you turn it on, you choose the level (read-only, ask on changes, unrestricted) and the allowed or denied commands; the deny list applies at every level.
Related features
Bring your agents to one desk.
Start on the free plan. Download it, add a project folder and open your first agent.