Skip to content

CloudSSH

Browser SSH client that runs in a Cloudflare Worker, with SFTP, jump hosts and a bring-your-own-key AI assistant

CloudSSH connection form with host, port, username, password or key, and region fields

CloudSSH connects a browser to SSH servers through a Worker that speaks SSH-2.0 over Cloudflare TCP sockets. Each session runs in its own Durable Object. The UI adds an SFTP file manager, saved servers and one-time share links.

CloudSSH implements SSH-2.0 itself, in TypeScript on the Web Crypto API. It supports password, keyboard-interactive and key authentication (Ed25519, ECDSA and RSA), verifies host keys on first connect, and can reach machines without a public IP through a Cloudflare Tunnel. The browser talks to the Worker over WebSocket. The terminal is xterm.js with several tabs per page, search, log export and a layout for phones. Beside it, an SFTP file manager handles uploads, downloads and in-browser editing of text files. Signed-in users, through GitHub OAuth or a single admin password, can save servers with encrypted credentials, keep command snippets, chain up to three jump hosts and create one-time share links that give someone an audited session. An AI agent panel, using a user-supplied key for an OpenAI-compatible API, can run commands and read terminal output on the connected host. Everything runs in one Worker with three SQLite-backed Durable Objects for SSH sessions, per-user data and share records. Turnstile can be switched on to block bots. A fork can also enable an optional GitHub Actions workflow that syncs upstream releases daily.

Built for: Developers and sysadmins who want browser SSH access to their servers, hosted in their own Cloudflare account instead of a third-party web terminal.

What you can use it for

  • SSH into servers from a locked-down laptop, tablet or phone
  • Edit server config files over SFTP in the browser
  • Reach private hosts through jump hosts or a Cloudflare Tunnel
  • Give a contractor a one-time, audited shell session
  • Ask an AI agent to check load, ports or Docker status

Deploy

  • Manual

    Fork the repository, create a Worker in Workers & Pages by importing the fork from GitHub, and set the build command to pnpm run build:frontend. Add login and Turnstile settings afterwards as Worker variables and secrets.

Setup is a dashboard import of a fork with one build command. Signing in and Turnstile each need extra Worker variables, and GitHub login needs an OAuth app.

What it needs to run

  • Durable ObjectsSSHSessionDO, SSHShareDO, UserDBDO

Also uses

  • GitHub OAuth (optional): Sign-in for saved servers, snippets and sharingSource
  • IPinfo (optional): Looks up the region of directly reachable saved servers
  • OpenAI API (optional): Running the AI agent panel with a user-supplied key for any OpenAI-compatible API

Good to know

Anonymous SSH is enabled by default. On a public instance, set REQUIRE_GITHUB_AUTH=true and an allowlist of GitHub user IDs so the Worker cannot be used as an open SSH proxy. REQUIRE_GITHUB_AUTH ships in wrangler.toml, so a value set only in the dashboard is overwritten on the next deploy. Saving a directly reachable server sends its host to the third-party IPinfo service to pick a Durable Object region. If a phone's OS discards the page, the shell cannot be resumed. The main README is in Chinese, with an English README alongside; the UI ships English, Simplified Chinese and Traditional Chinese.

Cost on Cloudflare

Likely fits the free plan

The README targets the Workers Free plan, where TCP sockets and SQLite-backed Durable Objects are available. Durable Object duration is capped at 13,000 GB-s per day on Free, which is why idle sessions close after 30 minutes by default (IDLE_TIMEOUT).

Source

The estimate is based on Cloudflare’s documented limits and the app’s configuration. What you pay depends on your usage and plan.

Where this comes from

An alternative to Shellngn, Termius.

Listing history

  • Oct 2, 2026 · CloudSSH listed
  • System prompt optimization with a rewritten Hard-Nosed Reviewer role and two test outputs side by side

    Browser-based tool for optimizing, testing and comparing LLM prompts with your own model API keys

    Deploy
    One-click
    License
    AGPL-3.0-only
    GitHub stars
    36.7k stars
    Last commit
  • VibeSDK home on build.cloudflare.dev with the build prompt box and a grid of community-built apps

    Self-hostable AI app builder from Cloudflare: describe an app and an agent plans, builds, previews and repairs it

    Deploy
    One-click
    License
    MIT
    GitHub stars
    5.4k stars
    Last commit
  • ternssh homepage with Deploy now and Documentation buttons and a dashboard preview in Chinese

    Browser-based SSH workspace with terminal tabs, SFTP and server monitoring, running on Cloudflare Workers

    Deploy
    One-click
    License
    GPL-3.0-or-later
    GitHub stars
    617 stars
    Last commit