Kelrik Terminal puts your hosts, keys, tunnels and files in one calm, tactile workspace. It connects straight from your device to your servers, and your vault is end-to-end encrypted on every device.
3 months of Pro freeNo card requiredZero telemetry
Kelrik Terminal · desktop · the agent stream shown is a version 2 preview
Rust SSH engine
XChaCha20-Poly1305 vault
Argon2id keys
Strict host-key checking
YubiKey & FIDO keys
Termius import
What's inside
Everything a serious SSH client needs. Nothing it doesn't.
Every control is a key you can feel. When something is on, it is pressed in and lit. When it's off, it gets out of your way.
Hosts that inherit, like they should
Nest groups for production, staging and dev, and set the user, port, key or jump host once on the group. Every host below picks it up. Mark a group Production and Kelrik guards it: a red badge, a confirmation before risky runs, and no surprises.
Tabs and split panes
Split right or down, focus, maximize and close. Panes regrid as you open them, and the terminal resizes once, cleanly.
Tunnels with real switches
Local, remote and dynamic SOCKS forwards with live state. Flip one on and watch it open, or see why it didn't.
SFTP, two panes
Drag files between your machine and the server, with a transfer bar and safe uploads that only replace a file once it has fully arrived.
Keys done properly
ssh-agent, Ed25519 and RSA keys, passphrases, and hardware keys: YubiKey and FIDO sk- keys. Changed host keys are flagged, never silently accepted.
Bring everything with you
Import your ~/.ssh/config (with Include, jump hosts and forwards) or your whole Termius library: hosts, groups, identities, snippets and themes.
Commands as blocks
Each command and its output becomes a card with its exit status, so long sessions stay readable. It uses a tiny shell hook, never on Production hosts.
Snippets on many hosts
Save the commands you type every week and run one on a whole group at once, with a tab per host. Production asks first.
Made for touch, too
On iPhone and iPad: an extra-keys row with sticky Ctrl and Alt, finger scrolling with momentum, long-press menus, and touch selection with Copy and Paste.
Yours to tune
Kelrik Light and Dark plus 45 popular terminal themes, Nerd Font icons with any font, and rebindable shortcuts with a Termius preset.
A lock on the vault
An optional passcode when Kelrik opens, plus a Lock key. Secrets stay in the system keychain, never in plain files.
Take the tour
Press a key. The workspace makes room.
The rail works like the app's: each key turns a pane on or off, and the space always goes to what's on.
Everything on
Hosts on the left, your sessions in the middle, health, tunnels and activity on the right.
Design renders. Health, Runbooks and the agent come in version 2.
Security
Your servers are none of our business.
Kelrik connects from your device straight to your servers. When you sync, everything is encrypted before it leaves the device, with keys only you hold.
Your passwordTyped on your device. Never sent anywhere.
Device
↓ ARGON2ID · 64 MB · 3 PASSES
Master keyDerived on your device, and it stays there.
Device
↓ HKDF-SHA256 SPLITS IT IN TWO
Auth key → serverProves it's you. Stored only as an Argon2 hash.
Server
Wrap keyLocks your random 256-bit vault key.
Device
↓ XCHACHA20-POLY1305
Hosts, keys, passwords, snippetsThe server stores ciphertext and nothing else.
Ciphertext
Direct connections
The desktop and mobile apps open SSH themselves. Your sessions never pass through Kelrik's servers.
Strict host keys
Every host key is checked against your known hosts. A changed key stops the connection and tells you why. Nothing is skipped silently.
Keychain for secrets
On Mac and iOS your vault key lives in the system Keychain. Nothing secret is logged or written in plain text.
The web app, disclosed
Browsers can't open SSH, so web sessions run through Kelrik's gateway using the same Rust engine. It's labeled in the app, and it can't reach private networks.
No telemetry
No analytics in the app and no tracking on this site. Your server list lives in your encrypted vault, where we can't read it.
Integrations
Know the moment your server needs you.
Give each host its own notify key. When a job ends, a deploy fails, or Claude Code or Codex is waiting on you, Kelrik posts it where you already are.
Slack
Microsoft Teams
Discord
Telegram
ntfy push
Signed webhooks
KelrikApp · 14:02
🟠 Claude Code needs youClaude needs your permission to use BashKelrik · prod-api-1 · api
KelrikApp · 14:09
🟢 Codex finishedAll 214 tests pass. The migration is ready for review.Kelrik · ci-runner-1 · web
KelrikApp · 14:31
🔴 Failed: make deployexit 2 after 94sKelrik · stg-api
$ kn -- make deploy
Ready for Claude Code and Codex
Paste one block into their settings and get pinged when they finish or ask for permission, even with the laptop closed.
One curl away
Cron jobs, CI, backups, monitoring: anything that can make an HTTPS request can notify you. Plain text, JSON or form fields.
Careful with your data
Webhook URLs and bot tokens are stored encrypted. The log keeps titles and results, never the message text. Revoke a key in one click.
Not your vault. The Mac, iPhone and iPad apps connect from your device straight to your servers, and when you sync, hosts, keys and passwords are encrypted on your device first, so Kelrik's server stores only ciphertext it can't read.
The one exception is the web app: its sessions pass through Kelrik's gateway, which records the host and port you connect to (not what you type or see).
What happens if I forget my password?
Your password is what encrypts your vault, so nobody, including us, can reset it and get your data back. That's the point of end-to-end encryption.
Your devices keep their own copy of your vault, so you won't lose your hosts and keys. But the account itself can't be recovered without the password. Changing a password needs the current one. Keep it in a password manager.
How does the web app connect over SSH?
Browsers can't open raw TCP connections, so web sessions run through Kelrik's WebSocket gateway, which runs the same Rust SSH engine as the apps. The app says so when you use it. The gateway only connects to public hosts, never to private or internal networks.
I use Termius. Can I switch without starting over?
Yes. On the Mac, Import from Termius reads your local Termius data, read-only, and brings over hosts, groups, identities, snippets and themes. Run it again later and it updates instead of duplicating.
Which platforms can I use today?
The web app is open to everyone with an account. The Mac, iPhone and iPad apps are in private beta. Windows and Linux builds are in progress. One Kelrik account works everywhere.
What does the trial include, and what happens after?
Every new account gets three months of Pro: sync, the web app and integrations. When it ends, your account stays on Free, and everything on your devices keeps working locally. Nothing is deleted.
How do integrations work, and what do they see?
You connect where messages should go (Slack, Microsoft Teams, Discord, Telegram, ntfy or your own webhook) and create a notify key for each host or tool. Anything that sends that key's URL a message, from a cron job to Claude Code, gets it delivered within a second or two.
To deliver a message, Kelrik's server has to read it, so integrations aren't end-to-end encrypted like your vault. Webhook URLs and bot tokens are stored encrypted, and the delivery log keeps only titles and results, never the text.
Can I delete my account?
Any time, from your account page. Your encrypted vault, devices and sessions are deleted from the server immediately.
Ready when you are
Your servers deserve a better terminal.
Create your Kelrik account in seconds. Your keys are made on this device, right in your browser.