Agents and automation

Letting Claude Code and other agents use your connections, and keeping them in bounds.

More questions: General · Agents and automation · Settings

Can AI coding agents like Claude Code use Hydra?

Yes, if you let them. Hydra speaks MCP, the protocol coding agents use for tools, so an agent can list your connections, browse and transfer files, run queries and more, through the connections you have already set up.

The agent never gets your passwords. Hydra holds the credentials and does the connecting, and the agent only sees results. Every call it makes, including the ones that fail, is recorded in the Automation Log.

Is it on by default?

No. The welcome screens ask, under External Agent Access, and skipping that screen leaves it off. You can change the answer at any time in Settings › Automation.

What is the difference between Always, While Hydra is Open and Never?

Always: agents can use Hydra at any time. If Hydra is not running when an agent calls, its helper starts it in the background.

While Hydra is Open: agents can use Hydra only while you have it open. The helper never starts it; an agent that calls while Hydra is closed is told so and nothing happens.

Never: agents, and the hydra command in your terminal, cannot use Hydra at all.

To be precise about the middle one: it means Hydra's own helper will not start the app. It is not a lock against every program on your Mac, since anything that can already run programs could open Hydra itself. Once Hydra is running, each program still has to be allowed by you (see below).

How do I connect Claude Code?

Choose Always or While Hydra is Open, then click Copy Claude Code Command on the welcome screen, or Copy Add Command in Settings › Automation › Connect an Agent. Paste the line into a terminal. It looks like this:

claude mcp add -s user hydra -- "/Applications/HydraDevStudio.app/Contents/MacOS/hydra" mcp

The next time Claude Code starts a session, Hydra asks whether to allow it. Say yes once and it is remembered.

Does it work with MCP clients other than Claude Code?

Yes. Any client that can run a local MCP server can use the same helper: the command is the hydra file inside the app, with the argument mcp. Clients that connect to a URL instead can use the HTTP address and access token in Settings › Automation › Advanced.

The App Store version does not include the helper (the App Store does not allow it), so there the HTTP address is the way in.

Why does Hydra ask me to move it to the Applications folder first?

The command you paste into Claude Code, and the hydra command if you install it, point at where the app is on disk. If you run Hydra from Downloads and move it later, both stop working. Hydra notices when it is not in an Applications folder and asks you to move it before giving you the command.

Do I need to install the hydra command?

Not for agents. They use the helper inside the app directly. The hydra command is for your own terminal: hydra sync, hydra query, hydra put and so on.

Installing it puts a link at /usr/local/bin/hydra. That folder is often not writable by your account, so macOS may ask for an administrator password. It is optional, and it is never installed as a side effect of anything else.

What an agent can and cannot do

Can an agent see my passwords?

No. Nothing an agent can call returns a password, key or token for a connection. The credential is attached inside Hydra when it connects, and it never crosses to the agent.

The one deliberate exception is a workspace secret (an API token, say) that you tick as Readable by automation. Only those can be fetched by an agent, by name, and each fetch is logged.

Which programs can connect?

Only ones you allow. The first time a program connects, Hydra shows its name, where it is, and who signed it, and asks. The answer is remembered and listed in Settings › Automation › Programs Allowed to Use Hydra, where you can switch it off or forget it.

Programs are recognised by their code signature, so an update keeps its answer. Claude Code is asked about by name, even though it talks to Hydra through Hydra's own helper: Hydra looks past the helper to the program that started it.

Can I stop an agent from changing a database or server?

Yes, per connection. In the connection editor, Access has three settings:

Read and write (the default): changes are allowed from the window and from automation.

Agents read-only: automation can only read (SELECTs, listings, downloads). Anything that would change data is refused and logged, and you can still write from the window yourself.

Read-only: nothing changes data through the connection, from the window or from automation.

Can an agent run commands on my server?

Only on an SSH or SFTP connection where you have turned on Allow automation to run commands in the connection editor. It is off by default, it can only be switched on in that editor (no agent can change it), and it also needs Access to be Read and write.

Each command is recorded in the Automation Log, and its full output is kept on your Mac in ~/Library/Logs/Hydra Dev Studio/Commands.

Can an agent add or delete connections?

Adding connections, workspaces, credentials and secrets needs Allow adding to the library in Settings › Automation, which is off by default. Even with it on, an agent cannot read a secret back.

Removing a connection, workspace, credential, tunnel or secret is never done by an agent. It can only file a request, which appears under Automation Requests in the sidebar for you to approve or decline. (Deleting files on a server is different: that is an ordinary file operation, allowed or refused by the connection's Access setting.)

Can an agent read or write files on my Mac?

Within limits. Limit automation to a folder is on by default and set to your home folder, and some places are always refused whatever the folder is: ~/.ssh, ~/.aws, ~/.gnupg, your keychains and Hydra's own data. A link that points outside the folder is judged by where it actually leads, not by its name.

In the App Store version the macOS sandbox does this job instead: Hydra can only reach folders you have granted in Settings › Folders.

What happens if an agent connects to a server Hydra has not seen before?

Hydra will not trust a new SSH host key or certificate on an agent's behalf. The agent is told the fingerprint and asked to have you confirm it, either in Hydra's window or with hydra trust in a terminal. Keys already in your ~/.ssh/known_hosts are trusted without asking.

How do I see what an agent did?

Open Automation Log in the sidebar (or Show Automation Log at the bottom of Settings › Automation). It lists every call: which program made it, what it did, to which connection, when, and whether it worked.

What is the hidden web page?

Agents can open a web page Hydra keeps out of sight, click and type in it, and read what it shows, for example to check a deploy or read a dashboard. It keeps its own cookies and logins, separate from your browsers, and Clear Web Data… in Settings › Automation signs it out of everything.

By default it only opens public websites. Local and private addresses (localhost, 192.168.x and so on) need Allow private and local addresses. Every page it visits is in the Automation Log.

Can agents on another computer use Hydra?

Only if you turn on Allow other devices on your network under Settings › Automation › Advanced. It is off by default. When on, Hydra opens a second, encrypted listener, and each device needs its own client token, which you create there and can switch off or delete at any time.

Still deciding?

Point it at your own servers for fourteen days. No account required.

Download for macOS