Full browser SSH terminal
A real xterm in a tab: 256 colours, resizing, scrollback, and every control sequence. vim, tmux, and htop behave exactly as they do locally.
Open a full audited terminal in a browser tab, move files over SFTP, and reach Windows desktops over RDP. Keys stay encrypted in one vault, access is granted per host, and every session is recorded. Nothing to install — on any operating system.
No agents to install · AES-256 encrypted vault · Every session audited
Eight capabilities that usually take six tools — behind one login, one policy, one audit trail.
A real xterm in a tab: 256 colours, resizing, scrollback, and every control sequence. vim, tmux, and htop behave exactly as they do locally.
Browse, upload, download, and edit remote files on the same host, with per-user permission checks on every operation.
Launch Windows desktops through controlled gateway sessions — policy-bound and recorded alongside your shell sessions.
Keys and passwords sealed with AES-256-GCM. Members connect through a credential without ever being shown the secret.
Keep reviewed one-liners and runbooks next to the hosts they belong to, so routine work stays consistent.
Ask about a stubborn systemd unit or an Onshell setting and get a practical answer, without leaving the console.
Five roles from Owner to Auditor. Developers reach staging, auditors read the trail, production stays locked down.
Every session, transfer, and admin change recorded with actor, IP, and timestamp. Retention follows your plan.
Four steps, no agents, and nothing to install on the machine you're sitting at.
Add each server's address, port, and username once. No agent to deploy — anything you can already reach over SSH works as-is.
Paste keys or passwords into the encrypted vault and attach them to hosts. Nobody has to keep a copy on their laptop again.
Assign roles and per-host access. Members sign in with email, Google, or a 2FA-protected account.
Open terminals, move files, and launch desktops from any machine with a browser — every action audited.
One genuinely useful free tier for solo operators, then per-workspace pricing for teams — not per seat.
Everything you need to replace a desktop SSH client, for one person.
For small teams sharing servers. Billed per workspace, not per seat.
For growing DevOps organisations that need governance and scale.
Need more than 50 users or custom retention? Talk to us about Enterprise instead.
More than 50 users, custom audit retention, SSO enforcement, data-residency requirements, or a security review to get through? We'll size it with you.
Private keys scattered across every laptop
Keys live encrypted in one vault. The gateway injects them; members never hold the material.
Offboarding means hunting for who had which key
Revoke one membership. Access to every host disappears with it, and the audit log shows what they touched.
Nobody can answer "who ran that on Tuesday?"
Every session, transfer, and permission change is recorded with actor, IP, and timestamp.
New engineers lose a day to SSH config
They sign in and see the hosts they're allowed to reach. Setup time is a single invite.
Everything you need to know about running remote access from the browser.
Onshell.cloud is a browser-based SSH client for teams. Register your servers once, store their keys and passwords in an encrypted vault, then open full audited terminals, SFTP file browsers, or RDP desktops from any browser tab — with per-host permissions and a complete audit trail, and nothing to install.
Free forever for one person. No credit card, no agents to deploy, no config to copy around.