1. Home
  2. Products
  3. OpsMaxx

Free Tools · Open source

OpsMaxx

Every server you look after, in one window.

MCP tools for AI agents, each governed separately
28
fleet operations across every server
20+
database engines, through a bastion if needed
5
free, no account, no telemetry, no paid tier
MIT

Overview

OpsMaxx is a Swiss Army knife for sysadmins, infrastructure engineers and DevSecOps engineers. Terminal, SFTP, five database engines, tunnels and VPNs, an encrypted vault and fleet operations live in one desktop app, organised into workspaces per client or environment that share one credential store. Its MCP bridge lets AI agents such as Claude Code work on your servers by name, under allow, ask and deny rules, without ever seeing a credential. Free and open source under MIT, with no account, no telemetry and no paid tier.

How it works

From setup to enforcement

  1. Step 01

    Download and open

    Signed and notarised on macOS (Apple Silicon and Intel), plus Windows and Linux, or install with Homebrew. No sign-up and no licence key.

  2. Step 02

    Bring your servers

    OpsMaxx imports ~/.ssh/config, ProxyJump entries included, so the servers you already reach by name are there on first run.

  3. Step 03

    Organise by workspace

    One workspace per client or environment, each with its own servers, databases, tunnels and secrets, optionally password-locked and exported as one encrypted file.

  4. Step 04

    Connect your agent

    One command pairs Claude Code or Codex with the local MCP bridge. Give the agent a read-only group on staging and an ask-first group on production.

Features

Key features

01

Workspaces

Servers, databases, tunnels, vault entries and agent sessions scoped per client or environment, and an agent cannot see past its workspace.

02

Terminal and SFTP, one connection

GPU-rendered terminal with split panes and search, unlimited jump hosts, and an SFTP browser on the same session, so two-factor is typed once.

03

Five database engines

Query and shell into Postgres, MySQL, SQL Server, MongoDB and Redis, through a bastion when that is the only route.

04

Tunnels, VPN and inspection

Local and remote forwards, SOCKS5, userspace WireGuard with no admin rights, OpenVPN, frp, and a proxy that shows the HTTPS a machine really makes.

05

Encrypted vault

AES-256-GCM store for logins and API keys under a scrypt-derived master password. No MCP tool can read it.

06

Know your fleet

Inventory, configuration drift, capacity trends, security posture (SSH config, sudo rules, ports, firewall), key access and fleet-wide search.

07

Change safely

Patching in waves that stops at the first unhealthy server, fleet-wide commands, cron and timers, rules, verified backups and a change log. Writes are off until you turn them on.

08

Operate containers and databases

Docker, Compose drift, Kubernetes cordon, drain and exec, replication lag, slow queries, multi-server log tailing and runbooks.

09

MCP bridge for AI agents

Agents address servers by friendly name; every tool is ALLOW, ASK or DENY; output is redacted; escalation shells are always refused; every action is audited.

Who it's for

Built for how teams actually work

On call at 3am

An alert fires; the fleet monitor shows which server, the runbook shows what was run the last three times, and the terminal is one click away.

Consulting across clients

One password-protected workspace per client, each with its own servers and secrets, exported to a single encrypted file.

Keeping a platform patched

Patch in waves, watch drift since last week, and read security posture as it actually is on the box.

Working alongside AI agents

Let Claude Code work on staging on its own and wait for your approval on production, with every action in the audit log.

Technical details

Works with your stack

Platforms
macOS (Apple Silicon and Intel, signed and notarised), Windows, Linux; Homebrew cask
Connectivity
SSH with unlimited jump hosts, SFTP, SOCKS5, WireGuard, OpenVPN, frp
Databases
Postgres, MySQL, SQL Server, MongoDB, Redis
Containers
Docker, Docker Compose, Kubernetes
Secrets
Server credentials in the OS keychain; vault in AES-256-GCM with a scrypt-derived master password
MCP clients
Claude Code, Claude Desktop, Codex, Gemini CLI, any MCP client
Agents never receive
SSH passwords, private keys, database credentials, hostnames, IPs or usernames, vault contents, or an interactive root shell
Licence
MIT; no account, no telemetry, no paid tier

Pricing

Plans

Free and open source under MIT. No account, no telemetry, no paid tier.

Everything

Free MIT licence

Every feature, on every platform.

  • No account or licence key
  • No telemetry or analytics
  • No session limits
  • Full source on GitHub

FAQ

Questions teams ask

Is it really free?

Yes. MIT licensed, with no paid tier, no session limit and no subscription. The full source is public.

Does it phone home?

No account, no telemetry, no analytics. Every connection it makes is one you configured, apart from an update check you can switch off.

Can an AI agent do something I did not intend?

Only within the access group you set. Escalation shells are refused for every group, ASK actions wait for your approval, and every action lands in the audit log.

Where are my passwords and keys stored?

Server credentials go in your operating system keychain; the vault is AES-256-GCM under a master password that is never stored. Neither leaves your machine.

Products

More from Cyphlon

See all products →

Book a call

Book a 30-minute call

Pick a time that suits you. We'll talk through what you're building and where your security stands, then suggest where to start.

Logo

Cyphlon

1:1 Consultation Call

30 min Google Meet

An introductory call with our engineers about any engagement: a pentest, continuous testing, managed AppSec, security engineering, agentic AI security or a fractional CISO. We'll ask about your stack, your deadlines and what your customers or auditors expect, and tell you plainly if we're not the right fit.

Logo Cyphlon

Research and tool releases by email

Unsubscribe any time. Privacy Policy

About Us

Cyphlon is a security engineering company. We implement DevSecOps, application security, Zero Trust and supply-chain security, build the products we deploy, and publish our research.

[email protected]

© 2026 Cyphlon LLC · Dubai, United Arab Emirates · Founded 2016

Privacy Policy Terms of Use