A modern, security-focused desktop app that pairs a real OpenSSH terminal with a dual-pane file manager, S3 object storage, and Kubernetes exec & debugging — with hardware key and smartcard support built in.
AppImage · .deb · .rpm · Windows installer & portable

Built for sysadmins, DevOps and developers who work across many hosts and clusters, hop through bastions, and authenticate with hardware tokens.
Spawns your system's own ssh — so ~/.ssh/config, agents and aliases just work. Tabs and recursive split panes.
Local disk, SFTP, S3 and pod filesystems side by side. Drag & drop, folder sync, search, chmod and a transfer queue.
Cluster tree from your kubeconfig, container exec, live logs, port-forwarding and kubectl debug ephemeral containers.
AWS, MinIO, NetApp StorageGRID and any S3-compatible endpoint. AWS SSO login, policies, CORS and versioning.
YubiKey, resident FIDO2 keys, PKCS#11, SITHS and Net iD — with an in-app PIN dialog and touch prompts.
ProxyJump, agent forwarding, local / remote / SOCKS tunnels, HTTP & SOCKS proxies, and X11 forwarding with a bundled X server on Windows.
Konsole-style recursive splits, each pane with its own connection picker and isolated session.
Browse container filesystems like a normal folder and attach debug containers without restarting anything.
kubectl debug presets — Netshoot, RHEL support tools, BusyBox, Ubuntu, or your own imageoc login commandDrag between panes, diff and sync folders across any two backends, and edit files in place.
Manage buckets the way you manage folders — with the admin features you actually need.
Open any file from local disk, SFTP, S3 or a pod — and preview Markdown as you write.
Keep every port forward per connection and start or stop them from a single dialog.
Move between machines without rebuilding your connections or your shell environment. Both features are opt-in and off by default.
Back up and sync connection profiles, dotfile pools and settings to your own S3 bucket or SFTP server — there is no sshs3 cloud.
~/.ssh/config in step, so plain ssh <alias> works everywhereKeep .bashrc, .vimrc and friends the same on every server you log in to.
Hardware-first authentication, encrypted-at-rest secrets, and sync that never touches a server we run.
ed25519-sk keys# unlock your card once, connect everywhere ❯ ssh prod-bastion ⚿ Enter PIN for SITHS card ☝ Touch your security key to authenticate alun@prod-bastion in /srv/app ❯ kubectl get pods -n payments NAME READY STATUS api-7c9d4f6b8c 1/1 Running
Grab the latest build for your platform. Every release is published on GitHub.
sshs3 is under active early-stage development — expect rough edges. Found one? Open an issue.