SSH
Real shells over russh. Several terminals per server, reconnect that keeps scrollback.
SSH, SFTP, live metrics, services, and deploys — in one client. Local-first for people who care about convenience and the fact that secrets never leave the device.
LuTerm is a desktop app. Pick macOS, Windows, or Linux below.
macOS · Windows · Linux — one desktop app on every platform
Workspace
Terminal, files, services, deploys, and AI live in one application — one inventory, one vault, one window.
Parallel sessions in tabs and file transfer on the same host — no second client.
Real shells over russh. Several terminals per server, reconnect that keeps scrollback.
Graphical file manager on the same connection: edit, search, compare, queue trees.
CodeMirror overlay for configs. Saves truncate remotely so an old tail cannot linger.
systemd, Nginx, and Docker on the connected box. Push a folder when the hash changed.
Unit list including files that were never started. Pins, logs, and name filter locally.
Compare the local tree first, then hash only those paths. Preview the diff, then ship.
Services and deploys unlock on Pro. Free still has SSH, SFTP, telemetry, and the vault.
A universal operator of the connected SSH server — files, processes, nginx, git, whatever you named.
Bare Unix paths go to the server. Cloud only proxies tokens against your plan quota.
“Always this session” for non-destructive exec and writes. Deletes still ask.
Free 100k / Pro 2M / Team 10M tokens per month. Team is one shared pool.
Credentials sealed on the device. Optional Cloud syncs inventory — never the SSH stream.
Passwords and keys under a device key. Optional master password. We cannot recover secrets.
Delta inventory across desktop and mobile. Fully usable offline from the local cache.
Bring hosts from OpenSSH config, PuTTY, and MobaXterm instead of retyping them.
Replaces the usual set
Import profiles from PuTTY, MobaXterm, and OpenSSH config — then keep working in one window.
Built-in tools
Diagnostics, editing, deploys, and an AI operator sit inside the client. You do not need a separate file manager, metrics page, and chat tab in the browser.
xterm.js shells, several per host, reconnect that keeps the scrollback.
SFTP tree, search by name then contents, compare, overwrite uploads.
CodeMirror for remote configs. Dark chrome, truncate-on-save.
CPU, RAM, disks, network, NVIDIA GPUs — polled on the same SSH session.
Commands you run every day, one click from the session.
Local and remote forwards on the connection you already have.
OpenSSH config, PuTTY, MobaXterm — hosts land in the inventory.
AES-256-GCM under a key that never leaves the device.
Hash-compared uploads, preview, systemd/nginx bindings. Pro.
Units and unit files, logs, pins. Disabled services still show. Pro.
Sites, certbot --nginx, pin a vhost to the top of the list. Pro.
Universal SSH operator. Chats stay on the device; Cloud proxies tokens.
Session data stays on your machine. Cloud never sits on the SSH path.
How teams use it
Not a PAM, not an RDP suite — a daily SSH/SFTP workspace that replaces the pile of clients on an admin machine.
Day-to-day work is split across PuTTY or Terminal, WinSCP or rsync, htop in another pane, and a browser tab for the panel.
LuTerm becomes the standard window onto the server.
LuTerm replaces a bundle of admin utilities with one workspace for shells, files, metrics, and the chores you run on Ubuntu.
Profiles live in PuTTY and MobaXterm. Passwords sit in chat. A new machine means retyping hosts.
Install LuTerm, import, keep the same jump-and-type muscle memory.
You can leave PuTTY, WinSCP, and MobaXterm without inventing a new way to log in. The session is still yours, still direct.
PAM or a jump host decides who may connect. People still need a decent SSH/SFTP client on the desk, and they still share host lists in a spreadsheet.
LuTerm is the client. Your bastion/PAM stays the control plane.
LuTerm does not replace PAM. It is the workspace you actually type in — including next to a jump host you already trust.
Best SSH client?
What LuTerm covers, and what you still buy extra with the usual set. Honest about the gaps: we are an SSH/SFTP workspace, not an RDP/VNC/DB suite.
The table scrolls sideways
| LuTerm | PuTTY | WinSCP | MobaXterm | Termius | |
|---|---|---|---|---|---|
| Product | |||||
| Class | ✓ SSH/SFTP workspace + ops | ~ compact SSH/Telnet/Serial | ~ file manager + basic SSH | ✓ toolbox, X server, Unix tools | ✓ cross-platform SSH client |
| Protocols | |||||
| SSH terminal | ✓ | ✓ | ~ built-in terminal | ✓ | ✓ |
| Graphical SFTP | ✓ | ~ PSFTP console | ✓ | ✓ | ✓ |
| RDP / VNC / Serial | — not the product | ~ Serial / Telnet | — | ✓ | — |
| Built-in | |||||
| Live host telemetry | ✓ | — | — | ~ separate tools | — |
| systemd / Nginx / Docker | ✓ Pro | — | — | ~ you run the commands | — |
| Hash-based deploy | ✓ Pro | — | ~ sync folder | — | — |
| AI operator on the box | ✓ | — | — | — | — |
| Import PuTTY / Moba / ssh_config | ✓ | — | ~ ini / registry | ~ own format | ~ own format |
| Trust | |||||
| SSH via vendor cloud | — never | — | — | — | ~ optional agent / sync |
| Zero-knowledge vault | ✓ AES-256-GCM | — | — | — | ~ cloud vault |
| macOS / Windows / Linux | ✓ | ~ Windows | ~ Windows | ~ Windows | ✓ |
| Free to start | ✓ SSH, SFTP, vault, 100k AI | ✓ | ✓ | ~ Home limits | ~ free tier |
✓ yes ~ partial or a separate product — no
LuTerm is the one in this group that keeps terminal, graphical SFTP, live telemetry, a zero-knowledge vault, and an AI operator in a single desktop. The others are strong in a niche and need a second window for the rest.
Security
LuTerm encrypts credentials on the device and leaves SSH as a direct connection. Optional Cloud stores ciphertext inventory — not your sessions.
Argon2id on the device. Without the vault key, connection secrets do not open.
Passwords and keys are sealed under a random 32-byte key. AAD is the record UUID.
Hosts, keys, and history live on the machine. Offline still connects from cache.
We do not have the device key. Lose the master password and the recovery kit and the secrets are gone — by design.
Host fingerprints pin on the device. A changed key stops the connection with a warning.
Under the hood
Pricing
No time limit on Free. Upgrade when you need services, deploys, or a shared workspace.
Personal
No time limit
$0/ month
Professional
Most used
1 month · 1 seat
$12/ month
or $120 / year
Organizations
1 month · team inventory
$29/ month
or $290 / year
One Team subscription. Invited members get Pro features and the Team AI quota — they do not buy a seat.
The app is free. Sign in only when you want sync, AI, or a paid plan.
Link and membership land in your email. Manage the subscription in the Gumroad library.
One Team buyer. Invited members inherit Pro features and the shared AI pool.
Sign in first so the purchase is attached to your LuTerm account. Checkout opens with your email and the period you picked.
Yes. Download and use SSH, SFTP, and the vault without an account. Pro adds services, deploys, and more AI. Team adds shared workspaces; invited members inherit Team features.
No. Credentials are encrypted on the device. LuTerm Cloud stores ciphertext only, and SSH never goes through our servers.
Not here. This site only distributes the desktop builds for macOS, Windows, and Linux.
Sign in on this site, then pick monthly or yearly. Checkout is Gumroad; we receive your account id and email so the plan lands on the same user. You can also paste a license key in the desktop app.
Open Manage subscription on the pricing page (your Gumroad library). Cancel there to stop future charges. If you buy Team while Pro is still active, we ask Gumroad to drop Pro; if two memberships remain, cancel the extra one in the library.
No. The Team buyer creates workspaces and invites people. Members keep a Free billing plan but inherit Team features (services, deploys, Team AI quota) while they belong to that workspace. Only the buyer can create additional workspaces.
Yes. The inventory is local-first. If Cloud is unreachable, saved servers still connect from the cache.
No. LuTerm imports from OpenSSH config, PuTTY, and MobaXterm. Hosts land in the inventory with their connection parameters.