Documentation
Documentation
Kino is SSH for machines that cannot be reached. Four programs, one job each - here is what they are, how they fit together, and how to run them.
What Kino does#
You have a machine — a homelab box, a Raspberry Pi, a VM at work — that sits behind NAT, CGNAT, or a firewall. Nothing on the internet can connect to it. But it can connect out, like any laptop on café Wi-Fi can open a website.
Kino is built on that one asymmetry:
If the hidden machine dials out and holds the connection open, someone else can send data back down the same connection — no inbound port, no port forwarding, no VPN.
Everything else in these docs is plumbing around that trick.
The four pieces#
| Piece | Job | Runs on | Licence |
|---|---|---|---|
| Kino SSH Manager | The desktop app you actually use: terminals, SFTP, an encrypted credential vault. | Your laptop | GPL-3.0 |
| kino-agent | Sits on the hidden machine and keeps an outbound line parked at a relay. | The target machine | GPL-3.0 |
| kino-relay | The public meeting point. Splices the manager’s socket to the agent’s and shovels bytes. | A public server | AGPL-3.0 |
| Kino Cloud | The hosted service: accounts, machines, relay directory, and the credentials that gate all of it. | Hosted for you | — |
Only the relay needs a public address. The manager and the agent both dial out to it, and neither ever listens.
The relay cannot read your session
SSH is negotiated end-to-end between your client and the target’s sshd.
The relay moves ciphertext it has no key for. A hostile relay can refuse to
connect you or drop your bytes; it cannot read your password, your key, or
a single character of your terminal. See
How it works.
Pick your path#
I just want to reach my machine. Quickstart — create an account, add a machine, run one install command on it, connect. Five minutes. Relays, credentials, and rotation are handled for you.
I want my traffic over my own hardware. Self-hosting — run your own relay and enroll it. Everything above keeps working; your bytes just take your route. No charge.
I want to understand the security model. How it works covers who sees what; Credentials and tokens covers every secret in the system, how long it lives, and how to revoke it. Kino Cloud covers what the service does and does not store about you.
I am integrating with the API. HTTP API is the full endpoint reference.
How much do I have to run?#
| What you want | What you run |
|---|---|
| SSH to a normal server with a public IP | The app only. Direct mode — no relay or agent involved at all. |
| Reach machines behind NAT | The app, plus one command per machine. Kino Cloud handles the rest. |
| The above, on your own relay | Add a relay. It enrolls in a click and keeps every convenience — see Self-hosting. |
The app is the product. The agent and the relay exist for the “machine behind NAT” feature, and Kino Cloud exists so you never have to think about either.
Open source#
The three pieces that touch your traffic are open, and auditable:
| Repository | Licence |
|---|---|
| kino-ssh-manager — desktop app | GPL-3.0 |
| kino-agent — agent | GPL-3.0 |
| kino-relay — relay | AGPL-3.0 |
Kino Cloud is the hosted service that ties them together.