libtmux-mcp

Terminal control for AI agents, built on libtmux and FastMCP.

This server maps tmux’s object hierarchy — sessions, windows, panes — into MCP tools. Some tools read state. Some mutate it. Some destroy. The distinction is explicit and enforced.

Warning

Pre-alpha. APIs may change. Feedback welcome.

With uvx installed:

$ claude mcp add tmux -- uvx libtmux-mcp

Quickstart

Install, connect, get a first result. Under 2 minutes.

Quickstart
Tools

Every tool, grouped by intent and safety tier.

Tools
Prompts

Four workflow recipes the client renders for the model.

Prompts
Resources

Snapshot views of the tmux hierarchy via tmux:// URIs.

Resources
Safety tiers

Readonly, mutating, destructive. Know what changes state.

Safety tiers
Client setup

Config blocks for Claude Desktop, Claude Code, Cursor, and others.

MCP Clients

What you can do

Inspect readonly

Read tmux state without changing anything.

list_sessions · capture_pane · capture_since · snapshot_pane · get_pane_info · find_pane_by_position · search_panes · wait_for_text · display_message · call_readonly_tools_batch

Act mutating

Create or modify tmux objects.

create_session · send_keys · send_keys_batch · run_command · paste_text · create_window · split_window · select_pane · select_window · move_window · resize_pane · pipe_pane · set_option · call_mutating_tools_batch

Destroy destructive

Tear down tmux objects. Not reversible.

kill_session · kill_window · kill_pane · kill_server · call_destructive_tools_batch

Example: keep test runs out of persistent history

libtmux-mcp provides best-effort history suppression for Bash, Zsh, and Fish. MCP calls to run_command use lightweight command suppression by default. When you create a new shell, opt into stronger no-disk controls with suppress_persistent_history=true.

Prompt

Create a tmux session called “checks” with best-effort no-disk shell-history controls, run pytest -q in its initial pane, and show me the result.

The agent calls create_session with suppress_persistent_history=true, reuses active_pane_id from the returned SessionInfo, and calls run_command without an override. The same spawn option on create_window, split_window, or respawn_pane applies only to the process that call starts.

These controls reduce history noise; they do not make commands secret. See History suppression for shell-specific behavior, Configuration for the server default, and Safety tiers for other observation surfaces.

Browse all tools →


Mental model

  • Object hierarchy — sessions contain windows, windows contain panes (Concepts)

  • Read vs. mutate — some tools observe, some act, some destroy (Safety tiers)

  • tmux is the source of truth — the server reads from it and writes to it, never caches or abstracts