Open source · MIT

LetKite Lite

LetKite Lite turns a fleet of Linux hosts into one remote MCP server for Claude, Kimi or GLM. It works over plain SSH, with no agent on the managed machines, and it is free and MIT licensed.

How it works

A small gateway on one server of yours speaks MCP to your AI client and SSH to your machines. Your AI gets one URL; your machines get a public key.

One URL for every client

Add https://your-gateway/mcp as a custom connector in Claude, or as an MCP server in Kimi or GLM. Each client signs in through your own consent page.

Agentless nodes

A node joins with one command. It gets a low-privilege account and the gateway's public key — no daemon, no private key, nothing to update.

Built for fleets

Tag nodes, act on groups, keep long jobs running on the node, follow logs, open persistent shells and forward ports.

Quick start

  1. Install the gateway

    Point a DNS name at the server first. The installer sets up packages, TLS, keys, the service and a self-test.

    git clone https://github.com/letkite/letkite-lite.git && cd letkite-lite
    sudo deploy/install.sh
  2. Connect your AI

    Use the URL the installer printed. In Claude: Settings → Connectors → add a custom connector. In Kimi or GLM, add an MCP server with the same URL. Approve on your sign-in page.

    https://mcp.example.com/mcp
  3. Add nodes

    Run one command on each machine you want to manage. Name and tag it as you go.

    curl -sSf https://mcp.example.com/enroll/install.sh | sudo bash -s -- --alias web-01 --tags prod,hk

Upgrades keep nodes and grants in place, and roll back with one command. See the operations guide and architecture notes for details.

What you get

Everything below is in the open-source edition today.

Learn more: Security

  • OAuth 2.1 sign-in with short-lived tokens and per-client consent
  • Per-node scopes: read, exec and write, set machine by machine
  • Confirmation before reboots, service stops and other risky commands
  • Audit log: one line per call, flushed to disk
  • Detached jobs that survive SSH drops and gateway restarts
  • Enrollment controls: open, approval or off, with keys and IP allowlists
  • Optional egress proxy so nodes leave through one stable IP
  • Upgrade and rollback without re-enrolling anything

When to move to LetKite

LetKite Lite covers Linux servers you can reach over SSH. LetKite adds Windows and macOS, routers and NAS, machines behind NAT, a cloud-managed gateway, folder-level rules, phone approvals and team roles. Everything in Lite carries over.

Pricing · Compare

License

MIT. Use it, change it and ship it, commercially or not. Issues and pull requests are welcome on GitHub.