Kelrik Terminal · Vault E2E
Early access · Mac · iPhone · iPad · Web

The SSH client that feels like hardware.

Kelrik Terminal puts your hosts, keys, tunnels and files in one calm, tactile workspace. It connects straight from your device to your servers, and your vault is end-to-end encrypted on every device.

3 months of Pro free No card required Zero telemetry
Kelrik Terminal on the desktop: a host list grouped into production, staging and dev, three terminal panes, live health, tunnels and an activity log.

Kelrik Terminal · desktop · the agent stream shown is a version 2 preview

  • Rust SSH engine
  • XChaCha20-Poly1305 vault
  • Argon2id keys
  • Strict host-key checking
  • YubiKey & FIDO keys
  • Termius import
What's inside

Everything a serious SSH client needs.
Nothing it doesn't.

Every control is a key you can feel. When something is on, it is pressed in and lit. When it's off, it gets out of your way.

Hosts that inherit, like they should

Nest groups for production, staging and dev, and set the user, port, key or jump host once on the group. Every host below picks it up. Mark a group Production and Kelrik guards it: a red badge, a confirmation before risky runs, and no surprises.

Tabs and split panes

Split right or down, focus, maximize and close. Panes regrid as you open them, and the terminal resizes once, cleanly.

Tunnels with real switches

Local, remote and dynamic SOCKS forwards with live state. Flip one on and watch it open, or see why it didn't.

SFTP, two panes

Drag files between your machine and the server, with a transfer bar and safe uploads that only replace a file once it has fully arrived.

Keys done properly

ssh-agent, Ed25519 and RSA keys, passphrases, and hardware keys: YubiKey and FIDO sk- keys. Changed host keys are flagged, never silently accepted.

Bring everything with you

Import your ~/.ssh/config (with Include, jump hosts and forwards) or your whole Termius library: hosts, groups, identities, snippets and themes.

Commands as blocks

Each command and its output becomes a card with its exit status, so long sessions stay readable. It uses a tiny shell hook, never on Production hosts.

Snippets on many hosts

Save the commands you type every week and run one on a whole group at once, with a tab per host. Production asks first.

Made for touch, too

On iPhone and iPad: an extra-keys row with sticky Ctrl and Alt, finger scrolling with momentum, long-press menus, and touch selection with Copy and Paste.

Yours to tune

Kelrik Light and Dark plus 45 popular terminal themes, Nerd Font icons with any font, and rebindable shortcuts with a Termius preset.

A lock on the vault

An optional passcode when Kelrik opens, plus a Lock key. Secrets stay in the system keychain, never in plain files.

Take the tour

Press a key. The workspace makes room.

The rail works like the app's: each key turns a pane on or off, and the space always goes to what's on.

Everything on

Hosts on the left, your sessions in the middle, health, tunnels and activity on the right.

Design renders. Health, Runbooks and the agent come in version 2.

Security

Your servers are none of our business.

Kelrik connects from your device straight to your servers. When you sync, everything is encrypted before it leaves the device, with keys only you hold.

Your passwordTyped on your device. Never sent anywhere.
Device
↓ ARGON2ID · 64 MB · 3 PASSES
Master keyDerived on your device, and it stays there.
Device
↓ HKDF-SHA256 SPLITS IT IN TWO
Auth key → serverProves it's you. Stored only as an Argon2 hash.
Server
Wrap keyLocks your random 256-bit vault key.
Device
↓ XCHACHA20-POLY1305
Hosts, keys, passwords, snippetsThe server stores ciphertext and nothing else.
Ciphertext

Direct connections

The desktop and mobile apps open SSH themselves. Your sessions never pass through Kelrik's servers.

Strict host keys

Every host key is checked against your known hosts. A changed key stops the connection and tells you why. Nothing is skipped silently.

Keychain for secrets

On Mac and iOS your vault key lives in the system Keychain. Nothing secret is logged or written in plain text.

The web app, disclosed

Browsers can't open SSH, so web sessions run through Kelrik's gateway using the same Rust engine. It's labeled in the app, and it can't reach private networks.

No telemetry

No analytics in the app and no tracking on this site. Your server list lives in your encrypted vault, where we can't read it.

Integrations

Know the moment your server needs you.

Give each host its own notify key. When a job ends, a deploy fails, or Claude Code or Codex is waiting on you, Kelrik posts it where you already are.

Slack
Microsoft Teams
Discord
Telegram
ntfy push
Signed webhooks
KelrikApp · 14:02
🟠 Claude Code needs youClaude needs your permission to use BashKelrik · prod-api-1 · api
KelrikApp · 14:09
🟢 Codex finishedAll 214 tests pass. The migration is ready for review.Kelrik · ci-runner-1 · web
KelrikApp · 14:31
🔴 Failed: make deployexit 2 after 94sKelrik · stg-api
$ kn -- make deploy

Ready for Claude Code and Codex

Paste one block into their settings and get pinged when they finish or ask for permission, even with the laptop closed.

One curl away

Cron jobs, CI, backups, monitoring: anything that can make an HTTPS request can notify you. Plain text, JSON or form fields.

Careful with your data

Webhook URLs and bot tokens are stored encrypted. The log keeps titles and results, never the message text. Revoke a key in one click.

Coming in version 2

An agent that asks before it acts.

Describe what you need in plain words. The agent suggests the commands, shows you exactly what it will change, and waits for your OK.

It never runs anything on a Production host without your confirmation.

Disk is at 82%. Want me to find what is using it and clean up safely?
yes, free up space but don't touch app data
Ran sudo du -sh /var/log/* | sort -h | tail -3
1.1G /var/log/syslog.1 2.4G /var/log/syslog 9.3G /var/log/journal
The journal is using 9.3 GB. I'll cap it at 2 GB and vacuum old entries. App data in /srv stays untouched.
Platforms

One account. Every screen you work on.

Your hosts, keys and settings follow you, end-to-end encrypted.

Web

Available nowOpen

macOS

Private beta

iPhone & iPad

TestFlight beta

Windows

Coming soon

Linux

Coming soon
Pricing

Start free. Go Pro when you sync.

Every new account gets three months of Pro, no card needed. Paid plans open at launch.

Free

$0forever
  • Every SSH feature on one device
  • Hosts, groups, keys and snippets
  • Tunnels and SFTP
  • Termius and ~/.ssh/config import
  • All 47 themes
Create account

Team Later

Soon
  • Everything in Pro
  • Shared vaults for your team
  • Roles and guarded production
  • Shared snippets and runbooks
Get early access
Questions

Good questions, straight answers.

Can Kelrik see my servers or passwords?

Not your vault. The Mac, iPhone and iPad apps connect from your device straight to your servers, and when you sync, hosts, keys and passwords are encrypted on your device first, so Kelrik's server stores only ciphertext it can't read.

The one exception is the web app: its sessions pass through Kelrik's gateway, which records the host and port you connect to (not what you type or see).

What happens if I forget my password?

Your password is what encrypts your vault, so nobody, including us, can reset it and get your data back. That's the point of end-to-end encryption.

Your devices keep their own copy of your vault, so you won't lose your hosts and keys. But the account itself can't be recovered without the password. Changing a password needs the current one. Keep it in a password manager.

How does the web app connect over SSH?

Browsers can't open raw TCP connections, so web sessions run through Kelrik's WebSocket gateway, which runs the same Rust SSH engine as the apps. The app says so when you use it. The gateway only connects to public hosts, never to private or internal networks.

I use Termius. Can I switch without starting over?

Yes. On the Mac, Import from Termius reads your local Termius data, read-only, and brings over hosts, groups, identities, snippets and themes. Run it again later and it updates instead of duplicating.

Which platforms can I use today?

The web app is open to everyone with an account. The Mac, iPhone and iPad apps are in private beta. Windows and Linux builds are in progress. One Kelrik account works everywhere.

What does the trial include, and what happens after?

Every new account gets three months of Pro: sync, the web app and integrations. When it ends, your account stays on Free, and everything on your devices keeps working locally. Nothing is deleted.

How do integrations work, and what do they see?

You connect where messages should go (Slack, Microsoft Teams, Discord, Telegram, ntfy or your own webhook) and create a notify key for each host or tool. Anything that sends that key's URL a message, from a cron job to Claude Code, gets it delivered within a second or two.

To deliver a message, Kelrik's server has to read it, so integrations aren't end-to-end encrypted like your vault. Webhook URLs and bot tokens are stored encrypted, and the delivery log keeps only titles and results, never the text.

Can I delete my account?

Any time, from your account page. Your encrypted vault, devices and sessions are deleted from the server immediately.

Ready when you are

Your servers deserve
a better terminal.

Create your Kelrik account in seconds. Your keys are made on this device, right in your browser.