Choose your path. The setup is completely different for each.
GitHub Actions, CI/CD, scheduled jobs. PR-anchored sessions with OIDC auth.
Claude Code, Cursor, or any agent that makes tool calls. Real-time approvals.
Add your MCP endpoint to Claude Code. Everything else depends on this being live.
Your MCP endpoint:
In Claude Code: Settings β MCP Servers β Add server β paste the URL above.
Select everything that applies. You can add more later.
Connect to servers via opkssh
CommunityDeploy, scale, restart pods
CommunityPostgreSQL or MySQL β JIT credentials
ProSTS credentials scoped per session
Coming soonWorkers, DNS, R2
Coming soonEphemeral auth keys
Coming soonRun this on your server once:
This adds REMIT as a trusted OIDC issuer in your sshd_config. You only do this once per host.
View full setup guide βThe name is how you'll reference this host in policies: ssh:my-vps:exec
remit-community.keyflux.io/oidc
deploy, TTL 60s
Generated from your setup. Good defaults β edit anytime.
workspace: my-startup Β· saved as remit.yaml
Staging is auto-approved. Production requires your click. Secrets are blocked permanently.
Copy this into Claude Code and watch the audit trail update in real time.