Features ›

Automation and agents

Point Claude Code, another agent, or your own scripts at Hydra. They use your connections; they never see your passwords; and you can see everything they did.

They name a connection. Hydra holds the password.

A script or agent asks for Bluebird Postgres or web:/var/www. Hydra opens the session with the credential it already holds and returns the result. No response has a field that could carry a password, so there is nothing to leak: that is a property of the shape of the API, not of a check that might be forgotten.

Agents connect over MCP, through Hydra's own signed helper; your scripts use the hydra command. Both are off until you choose, on the welcome screen or in Settings.

hydra ls "bluebird.example web:/var/www/bluebird"
hydra query "Bluebird Postgres" "SELECT status, count(*) FROM orders GROUP BY 1"
hydra get "web:/var/www/config/app.yaml" ~/Downloads/app.yaml
hydra diff "web:/var/www/bluebird" . --patch

Settings › Automation: when agents may use Hydra, the command that adds Hydra to Claude Code, the hydra command, and whether agents may add to the library

Watch it happen

The last part of the ninety-second demo: a terminal runs a query, lists a server and asks for a patch, all through Hydra, and each call lands in the Automation Log as it happens. An agent works the same way over MCP.

Everything is in the log

Every call is recorded: who made it, against which connection, what it touched, how long it took, and how it ended, failures and refusals included. Reads, writes, transfers, queries that change data, and every command run on a server.

The Automation Log: a listing, a patch, a download and an upload, an UPDATE, a download refused because it was outside the allowed folder, and a command refused because the connection does not allow it

The risky things wait for you

Some things an agent can only ask for. Deleting a note, running commands on a server, reaching a folder outside the one automation may use: each becomes a request on the Automation Requests screen, with the agent's reason, and nothing happens until you answer.

  • Per-connection access: read-write, agents read-only, or read-only for everyone
  • A folder boundary for this Mac's disk, defaulting to your home folder
  • Commands on servers only where you switched them on, or approved them for an hour
  • Unknown host keys are never trusted by an agent; you confirm the fingerprint
  • Each program is approved once, by its code signature, and named in the log
Automation Requests: an agent asking to run commands on the web server for an hour, with its reason, and another asking to delete a note

What agents can do

List, read, upload and sync files on any connection; run SQL; compare folders and servers and read the result as a patch; read and write workspace notes; open tabs and drive the window so you can watch; and, where you allow it, run commands. Hydra can also browse a web page for an agent and hand back what is on it.

Try it on your own servers

Fourteen days, everything unlocked, no account required.

Download for macOS