NewVersion 1.0 is out

OpenSesh

“Open sesame” for your servers.

An open source, lightweight remote connections client: terminals, SSH, SFTP, S3, tunnels, RDP and VNC in one native app, written in Rust with Qt 6 / QML.

Version 1.0.0, for Windows and Linux. All downloads · User guide

What it is

One app for your terminals and servers

OpenSesh brings your terminals, SSH sessions, files, tunnels and remote desktops into one native desktop app. It runs on Windows and Linux, and it is free software.

It covers the local terminal and its shells, SSH, SFTP and S3, tunnels, telnet, serial ports, mosh, containers, and RDP and VNC remote desktops.

  • Windows 10 and 11

    An installer, a portable zip, or Scoop.

  • Linux

    Packages for Debian 13, Ubuntu 26.04 LTS, Fedora and Arch.

  • Wayland first

    Hyprland, Sway, KDE Plasma 6 and GNOME, plus X11.

  • macOS soon

    Planned, no date yet.

  • GPL-3.0-or-later

    Free and open source software.

Features

What's in version 1.0.0

Everything below is in the current release. Select a screenshot to see it larger.

Local terminal and shells

A fast terminal, with every shell you have

  • GPU rendering, on Windows ConPTY and the Linux PTY.
  • A tab with any shell of this computer: PowerShell 7, Windows PowerShell, cmd, Git Bash, MSYS2, Cygwin and each WSL distribution on Windows, and the shells in /etc/shells on Linux.
  • Profiles and themes, with importers from other terminals.
  • Keyword highlighting, search, and a background image if you like one.

Tabs and panes

Split it, move it, broadcast it

  • Split a tab into panes, and move tabs between windows.
  • Broadcast what you type to several panes at once.
  • Save a layout as a workspace, and bring it back later.

Hosts

Every server, one search away

  • Saved hosts with groups, tags and favorites. Hosts inherit settings from their group.
  • Fuzzy search, and quick connect: type user@host:port, or an address such as rdp://, vnc://, telnet:// or serial://.
  • A command line too: opensesh connect web-01.

SSH

SSH with a built-in client

  • Host key checks with clear cards. Every question (host key, password, code) is asked inside its own pane.
  • Jump hosts, SOCKS and HTTP proxies, and agents: OpenSSH and Pageant.
  • One-time codes, certificates, agent forwarding and reconnection.
  • Remote graphical programs: X11 forwarding, untrusted or trusted, and Waypipe for Wayland programs.

Keychain

Keys and passwords, locked away

  • Identities, passwords and SSH keys in a vault encrypted with XChaCha20-Poly1305.
  • Its key is held by your system keyring, or by an optional master password (Argon2id).
  • Generate keys (Ed25519, ECDSA, RSA), or import them from OpenSSH and PuTTY, and use the keys of the running agents.
  • Install my key adds one of your keys to a server's authorized_keys.

Files: SFTP and S3

Files, side by side

  • Two panes, each this computer, an SFTP host or S3 storage (AWS, MinIO, RustFS and other compatible servers).
  • A side panel that follows the terminal's folder.
  • A transfer queue, with pause and resume for SFTP, and drag and drop.
  • Edit a server's file in your own editor, and share an S3 file with a temporary link.

Tunnels

Tunnels that come back by themselves

  • Local, remote and dynamic (SOCKS5) forwarding.
  • Each tunnel runs on its own connection and reconnects by itself, or runs with a host's terminal sessions.
  • Traffic counters, a warning for tunnels open beyond localhost, and import from ~/.ssh/config.

Remote monitor

See how the server is doing

  • The status bar shows the server's CPU, memory, network and disk, every 3 seconds.
  • Nothing is installed on the server: a small shell loop reads what the system already has, on a separate channel.
  • On Linux (busybox too), FreeBSD and macOS servers.
  • The side panel's Info tab: the system, kernel, CPUs, memory, swap, disks, addresses and logged-in users.

Snippets and recordings

Snippets, macros, safe pastes and recordings

  • Snippets with {{variables}} and passwords from the vault ({{secret:identity}}), in folders and tags. Run them in one terminal or many, from a quick picker (Ctrl+Shift+Space) or their own shortcut.
  • Macros: steps that type, pause and wait for text from the server, and a recorder that turns what you type into one.
  • Paste protection: before a risky paste, OpenSesh shows the text and what it found.
  • Session recordings in asciinema's format, played back in a tab, and a History view.

More protocols

Telnet, serial, mosh and containers

  • Telnet, with a warning that it sends everything in clear.
  • Serial ports: speed, parity, flow control, what Enter sends, local echo, and a hexadecimal view.
  • Mosh, started through the built-in SSH client.
  • Docker and Podman containers and Kubernetes pods, as hosts.

Remote desktops

RDP and VNC, in a tab

  • RDP: NLA, the server's certificate checked and pinned like a host key, a shared clipboard, and a desktop that follows the pane's size.
  • VNC: VeNCrypt, the Tight, ZRLE and Hextile encodings, and a view-only mode.
  • Through jump hosts, and next to your terminals: splits, workspaces and tabs that move between windows.
A remote desktop in a tab. It shows the test server's pattern, not a real desktop.

Import, export and sync

Bring your hosts, keep them in sync

  • Import from MobaXterm, PuTTY, Remmina, CSV files and ~/.ssh/config. What is left out is listed, and so is any command an import would run on this computer.
  • Export an OpenSesh bundle, with the keychain sealed by a password if you want it, or an OpenSSH config file.
  • Keep the settings folder in Git or Syncthing: changes from another computer are merged, record by record, not overwritten. The vault stays on each computer.

Accessibility and details

Easy to read, easy to start

  • A high-contrast theme: text at 7:1, stronger outlines and status colors, and a wider focus ring.
  • Errors in plain words, with a Details button for what the system or a library said.
  • A welcome on first start: import hosts, add one, open a local terminal or quick connect.
  • Closing OpenSesh while terminals, tunnels or transfers still run asks first.

What's next

Planned after 1.0

What comes after 1.0, with no dates yet.

  • macOS

    A Mac app, with Mac shortcuts and menus and a signed .dmg. Planned, no date yet.

    Read the plan
  • More package managers

    winget and the AUR, once the packages are submitted.

  • Signed Windows packages

    The executables, the installer and the uninstaller signed, once there is a certificate.

Download

Download OpenSesh 1.0.0

Released on October 3, 2026. What's new · User guide

Windows 10 and 11

64-bit (x64).

Installer

Installs for your user only, without administrator rights.

OpenSesh-1.0.0-windows-x64-setup.exe

Download OpenSesh-1.0.0-windows-x64-setup.exe

Portable

A zip to unzip anywhere. Your settings stay next to the app, so it runs from a USB stick.

OpenSesh-1.0.0-windows-x64-portable.zip

Download OpenSesh-1.0.0-windows-x64-portable.zip

Scoop

Installs the portable app and keeps it up to date.

scoop install https://github.com/caixax/opensesh/releases/latest/download/opensesh.json
  • The packages aren't signed yet, so Windows SmartScreen may warn the first time you run one.
  • The installer and the portable app bundle Qt and everything else they need.

Linux

64-bit (x86_64). Wayland first, and X11 works too.

One command

It finds your distribution, downloads the right package (the Debian 13 or the Ubuntu 26.04 .deb, the .rpm or the Arch package), checks it against SHA256SUMS.txt and installs it. Run it again to update.

curl -fsSL https://raw.githubusercontent.com/caixax/opensesh/main/install.sh | bash

Or download a package

  • The packages pull Qt from your distribution.
  • Other Debian and Ubuntu releases need a build from source: each .deb asks for the exact Qt of the release it was built on.

macOSComing soon

Planned, no date yet. There is no macOS build to download today.

Read the plan

Check your download

Every release has a SHA256SUMS.txt file that lists every package, the Ubuntu one included. Download it next to your file, then check the file against it.

Linux, in the folder with the download

sha256sum --ignore-missing -c SHA256SUMS.txt

Windows, in PowerShell

Get-FileHash .\OpenSesh-*-setup.exe

Then compare the hash with the file's line in SHA256SUMS.txt.

All downloadsEvery release

Privacy and security

Your servers, your keys, your computer

OpenSesh is local-first. Your data stays on your computer, and your secrets stay encrypted.

  • Zero telemetry

    OpenSesh never connects to the internet on its own. It connects only where you ask it to, and the update check is off until you turn it on.

  • An encrypted vault

    Passwords and SSH keys are encrypted with XChaCha20-Poly1305. The vault's key stays in your system keyring, or behind a master password (Argon2id).

  • Host keys, checked

    A new server key, or an RDP or VNC certificate, is shown to you to check, and nothing is sent before you accept it. A changed SSH key stops the connection until you decide.

  • Readable files

    Settings are TOML files you can read, edit and back up. Secrets never go in them.

  • Paste protection

    Before a risky paste runs, OpenSesh shows you the text and what it found.

Reviewed and fuzzed

Every parser of untrusted input, from quick connect and pastes to ~/.ssh/config, the importers and the sync merge, is fuzzed for an hour every week. Before 1.0, a security review traced each defense of the threat model to its code and a test. It is a review by the project, not an outside audit.

What OpenSesh protects, from whom, how and where it stops; and what the review checked and found.

When a server's key changes, the connection stops and the pane shows both fingerprints.

Principles

How OpenSesh is built

  • Simple by default, powerful when you need it

    Sensible defaults, with the deeper settings there when you look for them.

  • Customizable down to the last terminal pixel

    Fonts, colors, cursor, shortcuts, density, and profiles per host.

  • Keyboard first

    A command palette (Ctrl+Shift+P) and shortcuts you can change.

  • Native and light

    Built with Qt Quick. No web views, and no Electron.

  • Local-first and private

    Readable TOML files, and secrets in an encrypted vault or the system keyring. Zero telemetry, and the update check is opt-in.