# add_ssh_key

Register a new SSH public key with policy checks.

Agent View of the PolicyLayer registry record for `add_ssh_key`. HTML page: https://policylayer.com/tools/bhayanak-ssh-mcp-server/add-ssh-key

## Facts

- Tool: `add_ssh_key`
- Server: SSH MCP Server (`bhayanak/ssh-mcp-server`) — https://policylayer.com/tools/bhayanak-ssh-mcp-server.md
- Homepage: https://github.com/bhayanak/ssh-mcp-server
- Risk category: Write (Medium risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Rate-limited

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "add_ssh_key",
    "arguments": {}
  }
}
```

## Why add_ssh_key is rated Medium

Adding SSH keys modifies the authentication system and grants access, but the operation is reversible (keys can be removed). It falls under Write rather than Execute because it's not running commands or scripts. However, severity is high because misconfigured SSH key additions could grant unauthorized access to remote systems. The 'policy checks' mention suggests some safeguards exist, preventing critical rating.

From the tool's own definition: "Tool name 'add_ssh_key' and description 'Register a new SSH public key with policy checks' indicate creation/modification of SSH authentication credentials. This is a write operation that creates new security material."

## Use case

AI agents use add_ssh_key to create or update resources in SSH MCP Server, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your SSH MCP Server environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches SSH MCP Server:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "add_ssh_key": {
      "limits": [
        {
          "counter": "add_ssh_key_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on SSH MCP Server (22)

- `cancel_background_job` — Destructive — https://policylayer.com/tools/bhayanak-ssh-mcp-server/cancel-background-job.md
- `remove_ssh_key` — Destructive — https://policylayer.com/tools/bhayanak-ssh-mcp-server/remove-ssh-key.md
- `revoke_cert` — Destructive — https://policylayer.com/tools/bhayanak-ssh-mcp-server/revoke-cert.md
- `sftp_delete` — Destructive — https://policylayer.com/tools/bhayanak-ssh-mcp-server/sftp-delete.md
- `approve_request` — Execute — https://policylayer.com/tools/bhayanak-ssh-mcp-server/approve-request.md
- `request_approval` — Execute — https://policylayer.com/tools/bhayanak-ssh-mcp-server/request-approval.md
- `run_ssh_command` — Execute — https://policylayer.com/tools/bhayanak-ssh-mcp-server/run-ssh-command.md
- `run_ssh_command_background` — Execute — https://policylayer.com/tools/bhayanak-ssh-mcp-server/run-ssh-command-background.md
- `ssh_connect` — Execute — https://policylayer.com/tools/bhayanak-ssh-mcp-server/ssh-connect.md
- `get_audit_logs` — Read — https://policylayer.com/tools/bhayanak-ssh-mcp-server/get-audit-logs.md
- `get_host_facts` — Read — https://policylayer.com/tools/bhayanak-ssh-mcp-server/get-host-facts.md
- `list_background_jobs` — Read — https://policylayer.com/tools/bhayanak-ssh-mcp-server/list-background-jobs.md
- `list_hosts` — Read — https://policylayer.com/tools/bhayanak-ssh-mcp-server/list-hosts.md
- `list_pending_approvals` — Read — https://policylayer.com/tools/bhayanak-ssh-mcp-server/list-pending-approvals.md
- `list_templates` — Read — https://policylayer.com/tools/bhayanak-ssh-mcp-server/list-templates.md
- `poll_background_job` — Read — https://policylayer.com/tools/bhayanak-ssh-mcp-server/poll-background-job.md
- `sftp_list_directory` — Read — https://policylayer.com/tools/bhayanak-ssh-mcp-server/sftp-list-directory.md
- `ssh_list_sessions` — Read — https://policylayer.com/tools/bhayanak-ssh-mcp-server/ssh-list-sessions.md
- `ssh_session_ping` — Read — https://policylayer.com/tools/bhayanak-ssh-mcp-server/ssh-session-ping.md
- `issue_cert` — Write — https://policylayer.com/tools/bhayanak-ssh-mcp-server/issue-cert.md
- `ssh_disconnect` — Write — https://policylayer.com/tools/bhayanak-ssh-mcp-server/ssh-disconnect.md
- `transfer_file` — Write — https://policylayer.com/tools/bhayanak-ssh-mcp-server/transfer-file.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=bhayanak-ssh-mcp-server · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/bhayanak-ssh-mcp-server
