A modern, security-focused desktop app that pairs a real OpenSSH terminal with a dual-pane file manager, S3 object storage, and Kubernetes exec & debugging — with hardware key and smartcard support built in.
AppImage · .deb · .rpm · Windows installer & portable

Built for sysadmins, DevOps and developers who work across many hosts and clusters, hop through bastions, and authenticate with hardware tokens.
Spawns your system's own ssh — so ~/.ssh/config, agents and aliases just work. Tabs, recursive split panes, clickable links, snippets and search.
Local disk, SFTP, S3 buckets and pod filesystems side by side. Drag & drop file transfers directly between SSH servers and S3, folder sync and queue.
File manager docs →Cluster tree from your kubeconfig, container exec, live logs, port-forwarding and kubectl debug ephemeral containers.
AWS, MinIO, Ceph, Cloudflare R2 and any S3-compatible endpoint. Transfer to/from SSH, AWS SSO login, policies, CORS and versioning.
S3 storage docs →Real-time CPU, RAM, disk I/O, iowait and network throughput directly above active terminals. Zero extra logins, zero agent overhead.
Telemetry docs →YubiKey, resident FIDO2 keys, PKCS#11, SITHS and Net iD — with an in-app PIN dialog and touch prompts.
Security docs →ProxyJump, agent forwarding, local / remote / SOCKS tunnels, HTTP & SOCKS proxies, and X11 forwarding with a bundled X server.
Tunnels docs →Branch, change and ahead/behind indicators for local and SFTP folders. One-click pull, clone here, and open in GitHub or GitLab.
Git integration docs →Find your developer SSH keys, register them on GitHub or GitLab, and turn on SSH commit signing with allowed_signers.
Konsole-style recursive splits, each pane with its own connection picker and isolated session.
Monitor system health in real time without third-party agents, extra logins, or terminal clutter.
/proc over existing connections with zero extra password or hardware key promptsiowait disk bottlenecks and cloud hypervisor stealBrowse container filesystems like a normal folder and attach debug containers without restarting anything.
kubectl debug presets — Netshoot, RHEL support tools, BusyBox, Ubuntu, or your own imageoc login commandDrag between panes, diff and sync folders across any two backends, and edit files in place.
Manage buckets the way you manage folders — with the admin features you actually need.
Open any file from local disk, SFTP, S3 or a pod — and preview Markdown as you write.
Keep every port forward per connection and start or stop them from a single dialog.
Move between machines without rebuilding your connections or your shell environment. Both features are opt-in and off by default.
Back up and sync connection profiles, dotfile pools and settings to your own S3 bucket or SFTP server — there is no sshs3 cloud.
~/.ssh/config in step, so plain ssh <alias> works everywhereKeep .bashrc, .vimrc and friends the same on every server you log in to.
Hardware-first authentication, encrypted-at-rest secrets, and sync that never touches a server we run.
ed25519-sk keys# unlock your card once, connect everywhere ❯ ssh prod-bastion ⚿ Enter PIN for SITHS card ☝ Touch your security key to authenticate admin@prod-bastion in /srv/app ❯ kubectl get pods -n payments NAME READY STATUS api-7c9d4f6b8c 1/1 Running
Common questions about SSH, S3 object storage, security keys, and cross-platform workflows.
Yes. sshs3 features a dual-pane file manager where you can open an SSH/SFTP connection on one side and an S3 bucket (or MinIO, Ceph, Cloudflare R2) on the other. You can drag and drop, queue transfers, or synchronize folders directly between your remote servers and object storage without intermediary local downloads. Read more in the file manager guide and S3 storage guide.
sshs3 connects to any standard S3-compatible API. This includes Amazon AWS S3 (with AWS SSO device-flow login for short-lived credentials), MinIO, Ceph, Cloudflare R2, Wasabi, Backblaze B2, and NetApp StorageGRID. You can edit bucket policies, manage CORS, tags, and object versioning directly in the UI.
sshs3 executes your system's native OpenSSH client rather than a third-party reimplementation. This means your existing ~/.ssh/config host aliases, ProxyJump bastions, and ssh-agent just work. Furthermore, it includes first-class support for hardware security keys (FIDO2 / YubiKey) and PKCS#11 smartcards with in-app PIN entry. See the security documentation.
Yes, sshs3 is released under the permissive MIT license. The source code and builds are hosted on GitHub with native packages for Linux (AppImage, .deb, .rpm) and Windows (installer & portable).
Grab the latest build for your platform. Every release is published on GitHub.
sshs3 is under active early-stage development — expect rough edges. Found one? Open an issue.