Guides
Step-by-step instructions for every major feature, from adding your first SSH host to running your own vault server and brokering access your team never sees the password for.
Getting started
Connecting
SSH hosts, tab by tab
Every tab of the Add / Edit SSH Host form and what each setting does.
Keys and sign-in methods
Passwords, key files, agents, FIDO2, smartcards, Windows Hello, TOTP and password managers.
SSH certificates
Short-lived certificates from the built-in MangoSSH CA or HashiCorp Vault.
Identities and groups
Reusable credentials and folder-level inheritance, including jump hosts.
Port forwarding and jump hosts
Local, remote and dynamic forwards, ProxyJump chains and auto-detected dev servers.
SFTP and file transfer
The file browser, the inline editor, Quick SFTP, FTP, TFTP and folder compare.
Remote Desktop (RDP)
The embedded RDP client: display, clipboard, drives, gateways and recording.
VNC and Apple Remote Desktop
The embedded VNC client and Apple Remote Desktop hosts.
Remote access by ID
Reach a machine with no port forwarding: the host agent, Connect by ID, P2P and the unattended service.
Automation
Scripts
Run a saved script on one host or many, with parameters, attachments and schedules.
Runbooks
Multi-step workflows with branches, approvals and triggers.
Macros, broadcast and clusters
Type once into many terminals, replay keystrokes and save host sets.
Importing hosts
Bring hosts in from OpenSSH config, PuTTY, Ansible, Terraform or a network scan.
Vaults and teams
Vaults: Personal, Team and Cloud
Where your hosts and secrets are kept, and how each tier encrypts and syncs them.
Self-hosting the vault server
Run your own vault server for team sync, step by step.
Self-hosting the relay
Run the relay that powers persistent sessions, Connect by ID and the PAM Broker.
Password manager
Keep logins, notes and API keys in the vault, with a generator and a reveal gate.
Access and governance
PAM Broker and browser access
Let people connect without ever seeing the password, from the app or a browser link.
Just-in-time access
Time-boxed, approved access to sensitive hosts.
Policies
One page to set recording, JIT, crypto and key rules across many hosts.
Single sign-on (OIDC)
Sign in with your identity provider and map its groups to vault roles.
Device posture
Require an encrypted disk before a device gets credentials.
Audit, recording and alerts
What is logged, how sessions are recorded, and how alerts and forwarding work.