Documentation

Kino SSH Manager

The desktop app - encrypted credential vault, terminals, SFTP, tunnels, and the client half of agent mode.

Repository: Samarthegde/kino-ssh-manager · Licence: GPL-3.0 · Stack: Tauri 2 (Rust) + React/TypeScript

This is the piece you actually look at. Everything else in Kino exists so that this app can reach machines it otherwise could not.

The vault#

Every credential lives in a single encrypted file on your machine.

  • vault.enc — AES-256-GCM ciphertext. The key is derived from your master password with Argon2 and a random 16-byte salt stored alongside.
  • Connection history and the snippet library are sibling encrypted files under the same key.
  • Secrets are zeroized in memory on lock, and the app auto-locks when idle.
  • Changing the master password re-keys the vault rather than re-wrapping it.

Nothing leaves the machine unencrypted. There is no account, no telemetry, and no server-side copy of anything — including on Kino Cloud, which only ever knows machine names and ids.

There is no password reset

The master password is the key. Losing it means losing the vault. Export anything you cannot recreate.

Connecting#

Direct mode is ordinary SSH: hostname, port, username, and a password, a key, or the OpenSSH agent / Pageant. Encrypted private keys are supported, and .pem / .key / .ppk files import; ed25519 keypairs can be generated in-app.

Agent mode reaches a machine that has no inbound port. See Agent mode below.

Beyond the basics:

Jump hosts Route through another saved host, like ssh -J. Each hop’s host key is verified independently, and bastions chain.
Port forwarding Local (-L), remote (-R), and dynamic SOCKS5 (-D), started and stopped per session. A per-host dial-through SOCKS5/HTTP proxy is separate from these.
Host key verification Trust on first use, pinned thereafter. In agent mode the pin is keyed by agent id, so a substituted backend is caught.
Snippets A reusable command library; selected snippets auto-run on connect, per host.

The terminal#

xterm.js, one instance per host, with split panes, broadcast input across panes, scrollback search (Ctrl+F), copy/paste (Ctrl+Shift+C / V), adjustable font size, pinned and renamable panes, and 14 themes.

Sessions can be recorded to an asciicast file and replayed in-app.

Beyond the terminal#

  • SFTP browser and editor — browse, upload and download with progress, rename, delete, create folders, chmod, and edit remote files in an embedded Monaco editor that saves straight back over SFTP.
  • Docker — containers, images, volumes and networks, with live logs and one-click shells, all over the same SSH connection.
  • Metrics and processes — a streaming CPU / memory / disk / network dashboard, and a process list you can kill from.
  • Host health — an optional background probe showing a reachability dot and round-trip latency per host in the sidebar.
  • AI copilot (optional, off by default) — a bring-your-own-key assistant powered by OpenRouter. Ask about a host, explain an error, or select terminal output and send it over. The key is encrypted in the vault.

Agent mode#

Enable it under Settings → Agent & Cloud → Kino Agent → Enable agent connections. It is off by default; turning it on adds a Kino Agent connection mode to the host editor.

Set Kino Cloud URL to https://kino.dpdns.org and paste an account key (kck_…) from the Account keys page. Agent mode in the host editor then becomes a machine picker:

  • Add machine creates it and shows the one-line install command.
  • Choosing a machine stores only its agent id. No relay URL, no token.
  • At connect time the app asks the controller for a fresh 1-hour manager token and the relay the agent is currently parked on, then dials that relay.

The account key is stored encrypted in the vault. The last successful connect result is cached, so a brief controller outage does not stop you reaching a machine you have already used.

Self-hosted relay#

For a relay you run yourself, fill in the fields directly:

Field Notes
Relay URL wss://relay.example.com. Use ws:// only for local testing.
Agent id Whatever you gave the agent. Must match exactly.
Relay token Only if the relay requires auth: its static RELAY_TOKEN, or a manager-role token from a controller.
Control URL Optional. With it, the app looks up where the agent is parked instead of using the fixed relay URL.

The host editor shows the exact command to run on the target to install the matching agent.

Sync and sharing#

  • Cloud sync (optional) — pushes the encrypted vault to a private GitHub repo through the Contents API, with sha-based conflict detection and optional auto-sync (pull on unlock, push on change). GitHub sees ciphertext.
  • Encrypted profile sharing — export a host as a password-encrypted .sshm file (Argon2 + AES-256-GCM). The recipient needs only the password.
  • ~/.ssh/config import and export.

Settings map#

Section What lives there
General Appearance, behaviour, themes
Agent & Cloud Agent mode toggle, Kino Cloud URL and account key, self-hosted relay defaults
AI Copilot Provider key and model
Vault & Sync Master password, auto-lock, GitHub cloud sync
Shortcuts & Tools Keyboard shortcuts, import/export

Updates#

New signed releases install from About, with a fallback to the release page. On Linux the AppImage updates in place; .deb and .rpm go through the system package manager.

Building from source#

npm install
npm run tauri dev      # develop
npm run tauri build    # release build

Needs stable Rust, the Tauri 2 prerequisites for your OS, and Node.js 18+.