Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Guides · Connecting

    Remote Desktop (RDP)

    Open Windows desktops in a MangoSSH tab, next to your SSH sessions. The RDP client is built in, so it works the same on Windows, macOS and Linux, with clipboard, shared folders, sound, RD Gateway, SSH tunnels and session recording.

    • Built-in RDP client
    • Windows · macOS · Linux
    • About 10 minutes

    Add an RDP host

    1. Open Add Session → Add RDP session. Or click RDP on the main toolbar and then Add RDP Host.

    2. Fill in Host / IP and Username. The username can be user, DOMAIN\user or user@domain.com. Add a Domain only for domain accounts; leave it blank for local and Microsoft accounts.

    3. Type the Password to keep it in your operating system's keychain, or leave it blank to be asked each time you connect.

    4. Click Add & Connect. The host is saved to the sidebar and the session opens.

    5. The first time, MangoSSH shows the server's TLS certificate fingerprint under Unknown server certificate. Check it if you can, then click Yes, Trust & Connect. From then on the certificate is pinned (see Certificates).

    Click the screen once to give it the keyboard. Until you do, a hint reads Click the screen to send keys. To reconnect later, click the saved host in the sidebar. Each connected host gets its own tab, so several desktops can stay open at once.

    The host form

    The form has four sections down its left side. You meet it in two places: Add RDP session and Edit open it inside the RDP page, and the + button on the main toolbar, then RDP, opens it as the Add new RDP Session dialog. The fields are the same apart from the ones marked below.

    SectionFieldWhat it does
    GeneralHost / IP, PortThe target. The port defaults to 3389. The dialog calls it Hostname / IP and adds a Display name.
    GeneralUsername, Domain, PasswordSign-in details. The password is stored in the OS keychain; the dialog has a Save password box for it. Leave it blank to be asked at connect.
    GeneralResolutionAuto-fit window (crispest) sizes the remote desktop to the viewer and keeps following it. Or pick a fixed size, from 1280 × 800 up to 2560 × 1440.
    GeneralGroupWhere the host sits in the sidebar.
    GatewayTunnel via SSH hostReach the target through a saved SSH host (RDP page only). See Reaching hosts you cannot dial.
    GatewayRD Gateway, Gateway username, Gateway passwordTunnel through a Microsoft Remote Desktop Gateway. Blank means a direct connection.
    SecurityChoose VaultWhich vault the host is stored and synced in. See Vaults.
    SecurityPAM-broker modeIn the dialog, for a host synced through a Self Hosting or Cloud Vault: the relay signs in for you and this machine never holds the password. See PAM Broker.
    AccessMulti-monitorExperimental. Spans all of your local displays. The resolution setting is ignored while it is on.
    AccessSmartcard redirectionLets the remote session use a smartcard reader on this machine.
    AccessPrinter redirectionAnything printed in the session is saved here as a PDF.
    AccessDisable clipboardIn the dialog: no clipboard channel is opened, so nothing can be copied out of the session or pasted in.
    AccessConsole session (/admin)Attach to the existing console session instead of opening a new one, like mstsc /admin. If someone is signed in at the console, you take it over.
    AccessShared foldersLocal folders that appear as drives inside the session.

    The session toolbar

    While a session is open, a slim bar across the top shows the host name, the remote desktop size and a row of icon buttons. Hover over one to see its tooltip. From left to right:

    TooltipWhat it does
    Send local clipboard text to the RDP sessionTypes your clipboard text into the session as keystrokes. Useful where a normal paste does not reach, such as a sign-in box.
    Record session (screen capture)Starts recording. The icon turns into a square (Stop & save recording) until you click it again. See Recording.
    Auto-reconnect on disconnectA checkbox. When on, a dropped session reconnects by itself. Applies to this session.
    Refit displayRe-fits the picture to the viewer, keeping its shape. You may see empty bars at the sides. It never changes the remote resolution.
    Match windowA toggle: highlighted means on. On, the remote desktop is resized to fill the window whenever the window changes. Click it to freeze the current resolution; click again to snap back to the window.
    Fill the whole viewerA checkbox that stretches the picture to fill the viewer, ignoring its shape. Text will look squashed or stretched.
    Pop out into its own windowMoves the session into a separate window. Click again to bring it back.
    DebugOpens the RDP Debug log: every step of connecting (TCP, TLS, NLA, channels) and every disconnect, kept while the app is open. Copy or Save it for a support request.
    DisconnectEnds the session.
    Edit or delete this hostThe ⋮ menu for the host behind this session.

    Display and resolution

    With Auto-fit window (crispest), the remote desktop is created at the viewer's size, so text is drawn one-to-one rather than scaled. Match window starts on, and MangoSSH asks Windows to resize the desktop when you resize or maximise the window. Opening or closing a sidebar does not shrink it; the desktop only grows into space that frees up. If you would rather a resize never happens mid-task, turn Match window off.

    A fixed resolution never changes during the session. The picture is scaled to fit the viewer instead.

    When the desktop can't resize, the picture scales

    Resizing needs the server to accept MangoSSH's resize requests. When it doesn't, for example on some servers at the Windows sign-in screen, the picture is scaled to fill the window instead, and a true resize happens once the server accepts it.

    Defaults for every RDP host live in Settings → RDP Session. A host's own settings override them, and changes apply at the next connect.

    SettingWhat it does
    EngineWindows only. Embed Engine is the built-in client and the default. Native Engine is a bundled FreeRDP-based helper with smoother graphics for video. A host with Disable clipboard always uses the Embed Engine.
    ResolutionMatch Window, a fixed size, or Fullscreen.
    Display ScaleThe remote UI scale, 50–200%, used with a fixed resolution.
    High DPI (Retina)On a high-DPI screen, uses your monitor's real scale factor so the remote UI is not tiny. Automatic sizes are capped at 1920 pixels wide to keep bandwidth sane.
    Color Depth, QualityTrade picture quality for bandwidth on slow links.
    SoundPlay on this computer or Do not play.
    Send my timezoneGives the session your time zone instead of UTC.
    RDPGFX pipeline (experimental)A more efficient graphics stream. Off is the stable path; turn it on only to try it.

    Keyboard and clipboard

    Text copies both ways. Copy in the session and it lands on your local clipboard. Copy locally, click into the session, and it is ready to paste there. The toolbar's paste button is the fallback: it types up to 16 KB of clipboard text as keystrokes.

    Ctrl+Alt+Del is claimed by your own operating system before any app sees it. To send it to the session, pop the session out and use Send Ctrl + Alt + Del on the pop-out toolbar.

    To keep data inside the session, tick Disable clipboard on the host. No clipboard channel is opened, and the paste button refuses as well. This is enforced by MangoSSH; for a boundary that does not depend on the client, use the PAM Broker, whose sessions have no clipboard at all.

    Shared folders, printing and smartcards

    • Shared folders. In Access, click Add Shared Folder and pick a folder. Its drive name defaults to the folder name and you can change it. Inside the session it appears in File Explorer as name on MANGOSSH, and you can open, copy, rename and delete files there. Explorer does not refresh by itself when something changes on your side; press F5.
    • Printing. With Printer redirection on, the session gets a printer called MangoSSH PDF Printer. Each job is saved to your Downloads folder as mangossh-print-<number>.pdf. It cannot print to a physical printer on your side; print the PDF from there.
    • Smartcards. Smartcard redirection passes a local reader through, so you can sign in or sign documents with your card. Windows and macOS include the smartcard service this needs; on Linux, install and start pcscd.

    Sound

    Sound from the remote desktop plays on this computer unless Sound in Settings → RDP Session is set to Do not play. Your microphone is not sent to the session.

    Pop-out window

    Pop out into its own window moves a session into a window you can put on another monitor, maximise or keep on top. Its floating toolbar has Keep this window on top, Send Ctrl + Alt + Del, Refit the display to this window, paste, record, Toggle fullscreen, the connect log, Return this session to the main window and Disconnect this session. Drag the toolbar to move it, or collapse it out of the way.

    Recording

    Click the record button to capture what the screen shows. Click it again to stop; MangoSSH confirms with “Session log saved — see Tools → Session Logs”. Open Tools → Session Logs, select the recording, and click Play to watch it in the Recording Player, or export it as an .mrdprec file.

    This recording is made on your device, so the person connecting can turn it off. For recordings they cannot switch off, broker the host and tick Record every session on the relay (see PAM Broker).

    Reaching hosts you cannot dial

    SituationUse
    The PC is on a network you can SSH intoTunnel via SSH host. Pick a saved SSH host that can reach the PC. MangoSSH opens that SSH session, forwards a local port to the PC's RDP port and connects through it. A policy or host setting that blocks port forwarding on the SSH host blocks this too.
    Your organisation publishes desktops through an RD GatewayRD Gateway. Enter the gateway as host:port (for example gateway.example.com:443) with its own username and password. The gateway password is kept in the keychain, separately from the host password. The gateway must accept HTTP Basic sign-in.
    The PC is behind NAT with no port forwardingConnect by ID, on the RDP page. The PC runs MangoSSH and registers with your relay; you connect with its ID and password. See Remote Access.
    People should use the desktop without ever seeing its passwordPAM-broker mode. The relay holds the credential and runs the session; you get the screen. Clipboard and shared folders are not available on a brokered session. See PAM Broker.

    With an RD Gateway, MangoSSH does not check the gateway's own TLS certificate. The RDP connection inside the tunnel is still encrypted end to end to the PC, and the PC's certificate is still pinned.

    Certificates

    Windows RDP servers usually present a self-signed certificate, so there is no certificate authority to check it against. MangoSSH trusts on first use instead, like SSH host keys: you confirm the fingerprint once, it is pinned, and every later connection must present the same certificate. If it changes, the connection is refused with RDP HOST KEY MISMATCH and both fingerprints.

    A certificate changes legitimately when the PC is reinstalled or its certificate is reissued. If you know that is what happened, right-click the host, choose Properties…, click Forget RDP Host Key, and connect again to confirm the new one.

    Limits in this version

    • No RemoteApp. MangoSSH opens full desktops. Single published applications (RemoteApp) are not available.
    • No file copy through the clipboard. Copying files with Ctrl+C and Ctrl+V is built but switched off while a crash it triggers is fixed. Use a shared folder to move files.
    • Text-only clipboard. Images and rich text do not cross.
    • No microphone. Sound comes out of the session, but nothing goes in.
    • Multi-monitor is experimental.

    Troubleshooting

    SymptomLikely cause
    Refused or timed out, and MangoSSH suggests Connecting to a Mac?Nothing is answering RDP on that port. macOS has no RDP server; use VNC for a Mac. On Linux, install xrdp or use VNC. On Windows, check that Remote Desktop is enabled and port 3389 is open.
    “RDP HOST KEY MISMATCH”The PC's certificate changed. See Certificates.
    “Connection cancelled — the RDP server's TLS certificate was not trusted”The first-connect prompt was declined or left unanswered. Connect again and choose Yes, Trust & Connect.
    Keys do nothingThe session does not have focus. Click the screen once.
    Remote text is tiny on a high-DPI laptopTurn on High DPI (Retina) in Settings → RDP Session, then reconnect.
    The desktop does not follow the windowMatch window is off (click it: highlighted means on), the host uses a fixed resolution, or the server does not support resizing. The picture is scaled instead.
    Connect by ID accepts the ID and password, then failsThe other PC has MangoSSH Direct enabled instead of RDP, or the reverse. Reopen Connect by ID and switch the protocol to match.
    Anything elseOpen Debug on the session toolbar. The log shows the step where the connection stopped.