HomeSupportContact | Settings
language Languages
dark_modeperson

Desktop app for Windows & Linux · no account needed to SSH

Run Linux with AI — commands only run on your machine

Diagnose over SSH. Local vault. Cloud keeps metadata, not keys.

NiOps AI Dashboard — machine cards and package widgets

Dashboard: machine cards for the Active Workspace, widgets from packages installed on the profile.

One metaphor

Propose → gate → Linux host

  1. AI proposes

    The model diagnoses and drafts commands. It does not execute, and it does not open SSH to your machine.

  2. you approve

    Desktop is the last gate

    The app on your computer holds the keys, asks for approval on changing commands, then runs them.

  3. Your Linux host

    The SSH session goes straight from Desktop to the server. Logs stay on your machine.

Four pillars

Enough to operate — not one extra tab

See 8 core features

SSH on your machine

Host profiles, interactive PTY terminal, command bar with Commander hints.

  • Profile CRUD + connection test
  • Import from PuTTY, WinSCP, MobaXterm…
  • Connect → Terminal from the Dashboard

AI diagnoses first

Three fixed steps: clarify the goal → investigate with evidence → propose a fix.

  • Investigate with read-only commands
  • Changing commands usually need approval
  • Verify again after the fix

Secrets stay on your machine

The local vault holds passwords, keys, passphrases. Secrets are never uploaded.

  • Lock / unlock the vault
  • Recovery Package .enc per secret
  • Cloud keeps profile metadata only

Team + control

Local · My · Protected · Team. One Active Workspace at a time.

  • Workspace Security Policy is the safety ceiling
  • Trusted devices, revocable
  • Approve access, approve AI commands, audit
Said plainly so it is not misunderstood

This is not web SSH

The backend does not open SSH to the client and does not store secrets. The web has an API but it does not replace Desktop for running commands — to run anything, the app on your machine must be open.

Read 5 security promises
How the agent works

You can read what the agent is thinking, doing, and citing

Every AI Ops session is an open timeline: each read command, the output, the conclusion, and why a fix is proposed. No black box — you approve because you see evidence, not because you trust the model.

Evidence travels with the conclusion

Every diagnosis points at the command and output that produced it. Click through to the original text.

Cost and time per step

Credits, command count, duration per step — know what the agent costs before you turn it on for the team.

Reports stay on the machine

The whole session is a readable local log — incident review without the cloud.

Recorder

Build a whole stack across a fleet with one button

Record a real terminal session (F8) or write a command script, then replay it on many hosts after one risk confirmation. Mid-run prompts are answered automatically from the script.

  • Do it once on a sample host — reuse it for the other 20
  • Preview the command list and target hosts before you run
  • Per-host results go into the local log
Coming soon: cron/scheduler and per-host variables.
Packages & add-ons

Extend it: install a package, write an add-on, or take one from the community

A package installs on a host profile and shows up as a Dashboard widget. Skills are Markdown packs that teach the agent your runbooks. Both import from files, so you can build internally or use a community pack.

Official packages

Server Monitor, Network Speed Test, Disk Health — installed over Desktop SSH, widgets on the Dashboard. Pro includes the NiOps package.

Skills you write

Pack an ops runbook as Markdown, install as ZIP. The agent runs the skill on the open PTY session and does not open its own SSH.

Community add-ons

Import someone else's bundle, see which commands it runs before you install. Share your package or skill back with the team.

Packages page: install, remove, import ZIP
Security & access

Who can do what, on which host, who approves — all under a safety ceiling

Workspace Security Policy

Workspace policy sets the maximum; grants per person or per machine cannot exceed it.

Trusted devices, revocable

Each machine with the app is a registered device. Revoke it and every cloud action from that device stops.

Approve access and AI commands

Access requests and AI commands that need approval share one Approvals inbox; who approved when is in the audit.

Secrets never leave the device

The local vault holds passwords, keys, passphrases. Cloud keeps metadata and redacted audit.

Role:OwnerAdminOperatorApproverViewerRead 5 security promises
Compare

Still a server admin tool — with diagnosis and an approval gate added

Lined up against tools you may already use: PuTTY, Termius, Warp, Ansible, Teleport. Where NiOps is not there yet, we write coming soon.

Job to be doneNiOps AIDesktop · AI + approvalPuTTYWindows SSH clientTermiusSynced SSH clientWarpTerminal with an agentAnsibleConfiguration toolTeleportAccess infrastructure
Interactive SSH terminalYesYesYesYesNot the goalYes (via proxy)
AI proposes commands3-step agent: clarify → investigate → fixNoAutocomplete hints; conversational agent in betaAgent Mode understands natural language and self-healsNoNo
Where commands runYour DesktopYour machineYour machineYour machine (plus a cloud agent)Control node pushes over SSHThrough Teleport's proxy
Where keys / passwords liveVault on the machine, never uploadedOn the machineLocal vault; sync uses an end-to-end encrypted cloud vaultOS SSH keysAnsible Vault / CI secretsCA issues short-lived certificates
Run one playbook across a fleetRecorder: record then replay, one buttonNoSnippets on many hosts (paid)Via agent / workflowIts strength — but you write playbooksNot its job
Approve before a changing command runsOn-machine gate + Approvals for the teamNoConfirm step in the agent (beta)Approve each command before it runsReview via Git/CIAccess Request approves access, not each command
Team access, approval, auditWorkspace + Security Policy + redacted auditNoShared vault per team, session logsTeam featuresVia Git/CI or the commercial editionIts strength — RBAC + session recording
Host widgets, no extra agentPackage widgets on the DashboardNoNoNoNeeds a separate monitorNot the goal
Administer from a browserAdmin web — except running SSH commands directlyNoNoNoVia the commercial web UIHas a Web UI
File transfer / SFTPComing soonUse bundled pscp / psftpSFTP in the appNormal terminal (scp/rsync)copy/fetch modulesYes
Compared from each product's published docs (August 2026) — their features can change. The table is about different ways of working, not a score; PuTTY, Termius, Warp, Ansible and Teleport are trademarks of their owners.
Pricing

Free to try SSH · Solo for AI & vault · Pro for teams

Free

$0
2 hosts

SSH, Scan and Import, local logs. No AI, recorder, or vault yet.

Popular

Solo

$19/month
5 hosts · +$4 per extra host

AI Ops, vault, recorder, metadata sync across devices.

Professional

$60/month
20 hosts

Team workspace, command & access approval, NiOps package included.

Enterprise

Contact us
Host count by contract

SLA, log retention, custom policy requirements.

1 credit = 1,000 tokens · unused monthly credits do not roll over · Free gets a one-time token grant · annual Solo/Pro saves 20% · pay on the web; Desktop only opens the billing page.

See full pricing

Download Desktop and SSH now

Local Mode runs with no account: import existing SSH sessions, open a terminal, use the vault and recorder. Sign in only when you need metadata sync, access, or cloud audit.

Quick questions