Free · no account, no subscription

SSH, SFTP, FTPS and RDP on your Mac. One window.

A terminal, a dual-panel file manager and a remote desktop in the same application — with your credentials in an encrypted vault instead of a text file. Every desktop, under 10 MB, nothing to sign up for.

Download macOS · Windows · Linux
The application window: the saved-connection tree on the left, the start screen with four quick actions beside it
8.6 MB
download
18 MB
on disk
1 879
tests, every commit
0
accounts needed

01 — WHAT IT REPLACES

One window instead of three apps and a text file of passwords

Most people arrive here from one of two setups. Both work. Both cost something.

Subscription client
Terminal + FTP app + RDP app
Conchshell
Terminal
Its own emulator
Real PTY
Real PTY, split panes
File transfer
Built in
A second app
Dual panel, same window
Remote desktop
Paid tier
A third app
RDP, same window
Host monitoring
Paid tier
htop, by hand
CPU, net, logs, live
Credential storage
Vault, behind an account
A file on disk
Local encrypted vault
Size on disk
531 MB
Three installs
18 MB
Account
Required
None
None
Price
Subscription
Free
$19 once

Eighteen megabytes, not five hundred

Installed size on macOS. One application that does the work of three, and still the smaller install.

Competitor531 MB
Conchshell 2.10.118 MB

Measured on 3 August 2026, macOS 26.5.2, with `du -sm` on the installed application bundle.

Memory: 286 MB against 1.4 GB

Four SSH sessions to the same host in each client, measured ten minutes after connecting. Counted across the whole process tree, helper processes included — the main process alone is 35 MB, and reporting that number would flatter us by a factor of eight.

Memory
Processes
Competitor — Electron
1 388 MB
15
Conchshell 2.10.1
286 MB
7

Measured 3 August 2026 on macOS 26.5.2, Apple silicon. phys_footprint of the main process plus every process it is responsible for, median of three samples thirty seconds apart. The comparison is with a browser-engine client; natively written clients are lighter than both and are not in scope here.

02 — THE WINDOW

Four surfaces, one process

Everything below is in the free build. There is no other build.

Terminal

A real PTY
xterm.js with WebGL rendering, search and link detection. vim, top and tmux behave the way they do in a terminal, because it is one.
Split panes and tab groups
Split in four directions, drag tabs between groups, nest as deep as the work needs.
Session restore
Reopens the workspace you had and reconnects it on launch.
Ten themes, seven fonts
Colour schemes, background images and transparency.

Files

Dual-panel browser
Local and remote side by side, with drag-and-drop between them.
Transfer queue
Progress, speed, ETA, cancel and retry — for every queued transfer.
Directory sync
Compare two directories, review the differences, then synchronise. Four steps, nothing implicit.
Open in your editor
Edit a remote file in the application you already use; changes go back on save.

Seeing the machine

System monitor
CPU, memory, disk and processes on the remote host, with live charts.
Network monitor
Per-interface bandwidth, latency and the active connection list.
Log viewer
Several sources at once, level filters, regex search and live tail.
Remote desktop
RDP in the same window, or popped out into one of its own.

Getting there, and staying there

Proxies and jump hosts
HTTP CONNECT, SOCKS4, SOCKS4a, SOCKS5 and SSH jump hosts — each with its own credentials.
Every auth method
Password, private key, or an encrypted key with a passphrase. Auto-reconnect when the link drops.
Signed auto-update
Checks at launch; when you choose to install, downloads with progress, installs and relaunches. An unsigned build is refused.

03 — CREDENTIALS

The part that took the longest to build

XCHACHA20-POLY1305 · ARGON2ID

Your passwords are not in a text file

Credentials live in an encrypted vault with independent key slots over one data key. The interface can store a credential and delete it. It cannot read one back, because no command exists that would answer.

HOST · PORT · USER · PROXY · JUMP

A saved password only goes where it was saved for

Each stored credential is bound to its whole route. Point the connection somewhere else and it is refused — even when the request comes from inside the application.

OS-DRAWN CONFIRMATION

Your system approves host keys, not the app

When a server's key changes, the confirmation is drawn by the operating system. A compromised window cannot repaint it, cannot click it, and cannot make a key replacement look like a first connection.

The long version →

04 — MOVING IN

Your connections do not have to be retyped

Switching clients usually means an evening of copying hostnames. It does not here.

01
Import what you have
Connections, folders, profiles and settings come in from a JSON bundle exported by the application.
02
Keys stay where they are
The application references your key files on disk instead of copying them into itself. Your agent keeps working.
03
Passwords move once
Type a password on the first connection, save it to the vault, then delete the text file you were keeping.
04
Leaving is as easy
Connections export back to JSON at any time. Credentials stay in the vault and are not written to the file — you re-enter those, and nothing is held hostage in a format only this application reads.

Free, and it stays free.

No accounts, no subscription, no hidden telemetry — usage statistics are on by default, and one switch turns them off. Everything on this page is free; syncing your connections between machines is a one-time $19.