v0.8.1 · Electron 44 · React 19

All your remote access in a single app

Graphical SSH, SFTP/FTP(S) and RDP client, inspired by MobaXterm. Terminal, remote file manager and server organization — no plugins, no scattered terminals.

Orchid SSH terminal with an active session running uptime, docker ps, git status and free -m
TOFU host key verified
terminal xterm.js ssh2 + basic-ftp CodeMirror 6 Zustand 5 electron-updater
Features

Terminal power with the convenience of a GUI

From server setup to recursive upload, everything happens inside the same app.

Full SSH terminal

xterm.js with PTY, automatic resize, scrollback and multiple tabs — background tabs keep receiving output.

Remote manager

SFTP/FTP(S) with breadcrumb, column sorting, list/grid view, create, rename, recursive delete and drag & drop from the system.

RDP over SSH tunnel

Opens in the system client (mstsc/xfreerdp) and builds the jump chain, publishing 127.0.0.1:<port> as a bridge.

Flexible authentication

Password, private key (with passphrase) and SSH Agent — Pageant on Windows or SSH_AUTH_SOCK.

Folders and organization

Folders/subfolders, rename, move, duplicate, delete, search by name/host/user/tag and drag & drop in the tree.

Built-in editor

CodeMirror 6 with language highlighting and automatic upload on save (Ctrl+S).

Connections

From your computer to the destination, through jump hosts

Chain multiple jump hosts (ProxyJump) up to the final server. The app authenticates at each hop, opens a direct-tcpip tunnel to the next one and only then connects to the destination.

  • Each hop with its own host key verification (TOFU)
  • Works for terminal, SFTP and RDP
  • Passwords and passphrases encrypted in the local vault
  • Reorder the route with the arrows — the first is the closest to you
Youworkstation
gw1jump host · :22
gw2jump host · :22
db-primarydestination · SSH / SFTP

you → gw1 → gw2 → db-primary

Orchid SSH remote file manager listing /var/www with app, .env, config.yaml, deploy.sh and index.html
Files

Transfer, edit and organize remote files as if they were local

Upload and download files and folders (recursive) with a progress queue. Drag from the operating system straight to the server, edit in CodeMirror and save with automatic upload.

  • Recursive upload/download with progress
  • List/grid toggle and hidden files
  • Editor with highlighting and remote Ctrl+S
  • FTPS with certificate verification (TOFU)
Automation

Crontab-style macros and schedules

Automate repetitive commands without leaving Orchid SSH.

Global macros on any SSH connection

Command sequences with two modes: in the active terminal (as if typed) or silent (opens the connection, runs and captures the output per command).

  • Variables: {host}, {user}, {port}, {name}, {protocol}, {date}, {time}, {datetime}
  • Configurable pause between commands
  • Cancel a running execution, interactive or silent
  • Trigger from the toolbar, context menu or manager
Orchid SSH macro manager with the Deploy API and Diagnostics macros

Schedule macros like a crontab

Repeat with a 5-field cron expression (minute hour day month weekday, with *, lists, ranges and steps) or a one-time run at a date/time.

  • Ready-made presets and next-run preview
  • Stores last run, status and error
  • Toast when a schedule runs with the app open
  • View output button with stdout/stderr and exit code
Orchid SSH schedules with cron expressions, next run and last run status
Interface

9 app themes, 9 terminal themes

Mix and match — or let the terminal follow the app theme. Configurable terminal font.

Security

Your data stays with you

Isolated renderer process, strict CSP and credentials encrypted in the operating system.

Host key verification (TOFU)

Prompt to accept new hosts and an explicit alert when a key changes — the classic sign of a possible MITM. No silent acceptance.

Encrypted credentials

Passwords and passphrases stored via safeStorage (DPAPI/Keychain/libsecret) in secrets.vault.json. Never in workspace.json or logs.

Isolated renderer

contextIsolation: true, nodeIntegration: false and an API exposed only through contextBridge, with a restrictive CSP in production.

Update with a read-only token

The updater uses an embedded, locked token, read-only — nobody can publish releases with it.

FileContent
workspace.jsonFolders and connections (no passwords)
settings.jsonPreferences (theme, font)
secrets.vault.jsonPasswords/passphrases encrypted via safeStorage
known_hosts.jsonSSH host key fingerprints and FTPS certificates

Read the full privacy policy.

Stack

Solid technology underneath

  • DesktopElectron 44
  • UIReact 19 + TypeScript 5.9
  • Buildelectron-vite 5 + Vite 7
  • StateZustand 5
  • Terminal@xterm/xterm
  • SSH / SFTPssh2
  • FTP / FTPSbasic-ftp
  • EditorCodeMirror 6
  • TestsVitest 4
Shortcuts

Keyboard productivity

New connectionCtrlN
New folderCtrlShiftN
Close active tabCtrlW
Open settingsCtrl,
Save remote fileCtrlS

Real integration tests with in-process SSH and SFTP servers: handshake, host key TOFU, shell/echo, CRUD, recursive download and upload.

Screenshots

The real app, no mock

Real Orchid SSH screens: from the server panel to the remote editor, from macros to settings.

Themes

The same app in Dracula, Nord and Gruvbox.

Frequently asked questions

Common questions before downloading

Straight answers about installation, updates, security and known limitations.

Is Orchid SSH free?

Yes. It is an open-source project under the MIT license — no account, no subscription and no telemetry. The code is on GitHub.

Which operating systems does it work on?

Windows, macOS and Linux. There is an NSIS installer (Windows x64), a DMG for macOS (Intel and Apple silicon) and .deb / AppImage packages for Linux. Just download and install — no need for Node.js or any dependency.

Why does Windows show a SmartScreen warning?

The installer does not have code signing yet, so Windows may show "Unrecognized app". Click More info → Run anyway. Releases are generated by CI and published with integrity verification (sha256) on the download page.

Does automatic update work on all platforms?

No. Only the version installed via NSIS on Windows updates itself. On macOS a signed/notarized app is required, and the portable executable does not self-update. In those cases, download the new version manually — your data and connections are preserved.

Where are my passwords and keys stored?

Credentials are encrypted in the local vault via safeStorage (DPAPI on Windows, Keychain on macOS, libsecret on Linux), in the secrets.vault.json file. They are never written in plain text, in the workspace or in logs. See the security section.

Can I use jump hosts (ProxyJump)?

Yes, for SSH, SFTP and RDP. Chain as many bastions as you want; each hop has its own host key verification. Only FTP/FTPS does not support tunneling, since the FTP client does not accept chained connections.

Do macros and schedules run on any connection?

Macros run only on SSH connections (in the active terminal or in silent mode). Schedules always run in silent mode and only while Orchid SSH is open — there is no operating-system scheduler. The host key must already have been trusted beforehand.

Does RDP open inside the app?

No. RDP opens in a separate window of the system client (mstsc on Windows, xfreerdp on Linux/macOS) and credentials are entered there. The app builds the jump chain when needed and shows the session as a tab to close the tunnel.

Is there a limit to editing remote files?

The built-in editor (CodeMirror) works with files up to 5 MB; larger files are truncated and binaries open as text. Upload is automatic on save with Ctrl+S. There is no permission (chmod) editing through the interface yet.

Do you collect any data?

None. The app sends no telemetry or analytics. The update check only reads a public, anonymous feed on Cloudflare R2, with no embedded token.

How do I report a bug or suggest an improvement?

Open an issue on GitHub describing the system, the steps to reproduce and what was expected. Pull requests are welcome too.

Ready to organize your servers?

Download Orchid SSH and get terminal, files and RDP in the same place.

Only the NSIS-installed version receives automatic updates. The portable executable does not self-update.