Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Authentication

    Thirteen methods, from a saved password to a key that never exists in software at all.

    Key pairs generated or imported into MangoSSH, each with its type and fingerprint.
    • Password and SSH key — The common cases, including a key with a password fallback for servers that reject it.
    • Keyboard-interactive / MFA — Each prompt the server sends is surfaced as a dialog, so one-time codes work normally.
    • SSH agent — Uses your running agent, including FIDO2 security keys, which prompt for a touch during the handshake.
    • Hardware-backed — PKCS#11 tokens such as a YubiKey in PIV mode, or a non-exportable key generated inside your PC's TPM or a Mac's Secure Enclave. The private key never exists in software; every connection needs the physical gesture.
    • External secret managers — Fetch the password at connect time from pass, Bitwarden, AWS SSM Parameter Store, Doppler or 1Password rather than storing it.
    • CA-signed certificates — HashiCorp Vault SSH issues a short-lived certificate instead of trusting a static key.

    Host key trust

    MangoSSH trusts a host key on first use and warns loudly if it later changes. A prompt on a host you have connected to before is worth taking seriously. Certificate revocation lists are supported for fleets using a CA.

    Inherited credentials

    Groups can carry a credential or a bastion that every host in them inherits, so a shared jump host is configured once. A value set explicitly on a host always wins.

    Step-by-step guides

    How to set each of these up, one task per page.

    Full detail

    Step-by-step instructions, how to check each one worked, and what to do when it did not.