Your AI sees your tunnels. Not your production.

Connect Claude, Cursor or any MCP client to Kestro: your assistant knows what is running, reads the output of the server that just crashed, and opens the tunnels it needs. Production stays closed from the first launch, you have to go and open it yourself, in the app. Everything happens on this Mac: no network port, no connection string to copy anywhere, no account.

macOS 11+ · Windows soon

CodeFileView14:43
Kestro1 tunnel open · 1 service isn’t answering
Filter tunnels⌘FNew tunnel
bastion-prodprodSSHshellbastion.kestro.internalclosed
notes-dbstagingPostgreslocalhost:5432pg-staging.eu-west-1.rdsopen
run-eventsprodMongolocalhost:27017mongo-prod.atlasclosed
⌘K palette↑↓ navigate␣ togglecloses if you click elsewhere
run-tracker , zsh
Applying 2 migrations to shop-staging-db…
20240612_add_orders_index ok
done in 1.4s
run-tracker , zsh
# the exact line is in Settings › AI, ready to copy
Added stdio MCP server kestro

The assistant

Five things an MCP server wired straight to a database does not do.

sortie

It finally reads the output of the server that crashed

This is the real reason to connect an AI, and the one nobody admits: pasting three hundred log lines into a chat means truncating them. Your assistant asks for a program’s output and Kestro hands it over, the dev server, the compose stack, the command that just failed.

prod

Production is closed before you finish reading this

It is the one setting switched off at install, and it sits at the top of the list so you cannot miss it. A tunnel labelled production stays visible in the inventory: your assistant knows it exists and can tell you so, but without its host, its instance or its remote port. Nothing to open, and nothing to copy elsewhere.

jamais

What it can never do, whatever you set

Answer a passphrase a program is waiting for. Type into the terminal of a running program. Run a command you have never read and approved yourself. Open a public port that did not already exist. And change its own permissions: that setting is reachable from the window only, in front of you.

exception

One exception, both ways

“Never production, except that one database” is a sentence everyone needs eventually. It is a checkbox in the tunnel’s settings, and it overrides the general rule. The reverse too: an object you take out of what the AI can see disappears from the inventory, not greyed out, gone.

note

You write down what Kestro cannot guess

Kestro knows a tunnel is called notes-prod and holds a port. It has no idea it is the billing database, that it is restored nightly, that nobody ever writes to it. One sentence in its settings, and your assistant reads it before acting instead of guessing: because guessing, on a database, is precisely what you do not want.

Works with what you already haveSSH · Google Cloud · AWS · Cloudflare · Docker · PostgreSQL · Redis · Git

From a switch to a useful conversation

Three minutes, and nothing to configure twice.

Kestro does not become one more account. The server lives inside the app, the door opens when you switch it on, and it does not exist until you do.

  1. You switch it on

    One toggle in Settings › AI. While it is off the door does not exist: the server cannot connect at all, whatever the settings below say. They stay on screen so you can see what you would be granting before granting it.

  2. You paste one line

    Kestro shows the configuration to paste into your client, and the one-line command for Claude Code. No API key, no token to create, no connection string to write down somewhere: the server talks to the app through a socket in your user directory.

  3. It asks, Kestro decides

    Every action is weighed by the app before it runs: never by the server, which is only a file on your disk. What passes runs; what does not is refused flatly: no window pops up, and no “yes” gets clicked out of fatigue.

  4. And the refusal names the setting

    A refusal is not a wall: it says what blocked and where to lift it, in your language. Your assistant relays it to you word for word, you click, you try again. If you want a record of everything it asked for, a history can be switched on in the settings, it stays on this Mac.

On your machine

Everything stays with you.

Your connections run from your computer to your servers, never through us.

  • No account

    Nothing to create, no password.

  • Your keys stay put

    SSH, Google Cloud, AWS: Kestro uses your own tools, locally.

  • No usage statistics

    We don’t know what you open, or when.

  • One exception

    Your licence renews with us. Nothing else leaves.

And the rest

What your assistant drives existed before it did.

The MCP server is not a separate product: it opens up to your AI what Kestro already holds for you. Same app, same shortcut, same price.

  • Your tunnels

    Postgres on RDS, Redis behind a bastion, a Google VM with no public address. Opened with a switch, with the environment written on the row.

  • Your projects

    The branch, what changed, what is left to push. And the dev server, or the compose stack, started from the row: with its output in the panel.

  • Your services

    Sites, APIs, ports: checked continuously from your machine. The moment one goes down, the menu bar icon changes.

Pricing

You pay once. That’s it.

A tool you open forty times a day shouldn’t send an invoice every month.

Kestro licence

€29.99$29.99£25.99CHF 25.90CA$40.99A$45.99€39.99$39.99£34.99CHF 33.90CA$54.99A$61.99 · Launch offer · upcoming price

1 computer · one-time

  • Every feature of the app, no tiers, no “Pro” edition
  • One year of updates included, then renew if you want to
  • The app stays yours, renewed or not
  • One key, the same on all your computers
  • Switch machines whenever you like, no limit
  • No account to create: the key arrives by email

Or download it for free first →

Refunded within 14 days, no questions asked.

Questions we get

Which assistants can connect?

Any that speak MCP, the open protocol published by Anthropic: Claude Desktop, Claude Code, Cursor, and the list grows every month. Kestro ships an ordinary MCP server, over stdio, launched by your client like any other. Nothing is tied to one editor, and you can connect several to the same app.

Does my data go through your servers?

No, and there is no server of ours in this story. The MCP server is a program shipped inside the app that talks to Kestro through a socket in your user directory, not over the network: a local TCP port would be reachable from any page open in your browser, and we did not want that door. What reaches your AI vendor is what you write to it and what it asks for, exactly as when you paste text into a chat.

What if the AI works around it by typing the command in a terminal?

It can, and we would rather say so. Kestro bounds its own door, not your machine’s shell: an assistant with terminal access can type whatever it likes, including the kestro command. What these settings protect is the door Kestro just opened, and that is already the point, because the real risk is not a malicious assistant, it is one that gets it wrong or that some text it read along the way manipulated. The instructions Kestro gives yours explicitly tell it not to look for a workaround, and to relay the refusal to you.

Can I see what it did while I was looking elsewhere?

Yes, if you switch it on: a history records every action asked for, when, what, on which object, allowed or refused. The refusals are often worth more than the rest: they show what your assistant tried. It is off by default and never leaves this Mac. Kestro keeps no record of what you do, and will not start keeping one unasked.

Can it grant itself permissions it does not have?

No, and it is the one rule in the whole design that is not adjustable. The permission settings are not among what the MCP server may request, nor among what the kestro command may do: they are reachable from the app window only, in front of their owner. An assistant asking you to go and tick a box is doing its job; one ticking it itself would not be.

Does this feature need a subscription or an API key?

No. The MCP server is in the app, like the kestro command: it is not sold separately, asks for no account and calls no service. You pay for Kestro once, and what it does today it will still do in two years, offline included.

Does the trial ask for a card?

No, and it does not ask for an account either. You download it and you get 7 full days. No card is requested until you decide to buy.