Interactive Terminal
VT100 terminal emulator with splits, tabs, scrollback search, customizable fonts, and palettes. Replaces raw shell access with a modern macOS window.
SSH, SFTP, bastions, and tunnels in one native app — the power of a pro terminal with the elegance of Apple. Built in Swift & SwiftNIO for rock-solid, blazing-fast sessions.
Version 1.0 · see what’s new
One app to manage your remote hosts, terminal sessions, port tunnels, and file transfers — with the authentications your servers actually request, from private keys to 2FA.
VT100 terminal emulator with splits, tabs, scrollback search, customizable fonts, and palettes. Replaces raw shell access with a modern macOS window.
Local (-L), Remote (-R), and Dynamic SOCKS5 (-D) port forwarding with an active status panel. Perfect for database tunnels or secure web routing.
Browse and transfer remote files, watch and auto-upload edits, and edit permissions with a visual CHMOD grid — operating on the same SSH channel without logging in again.
Credentials are stored in the macOS Keychain. Private keys never leave your Mac. Host fingerprints are verified with TOFU checks.
A multi-tab terminal with horizontal and vertical splits, an SSH tunnel manager, a built-in key manager, and visual file transfers.
Open infinite terminal tabs and split them horizontally or vertically. The geometry is controlled by you — split pane fractions stay locked exactly where you drag them, and tab environment colors dynamically signal where you are.
Reach internal hosts through multiple SSH jump servers. Up to 8 hops supported natively, resolving inline usernames and ports. Credentials for each hop authenticate separately, and host key fingerprints are verified end-to-end for every single hop.
Enabling agent forwarding should not be a security risk. Upshell runs a private, in-process agent that only signs signatures inside the app. Your private keys never leave your Mac and the agent is gated per host, never globally.
Open a visual browser for files next to your terminal session. Drag files to upload, download, watch and auto-upload remote edits, or change file permissions natively using a visual chmod grid — all on the same connection, with zero secondary logins.
Press ⌘K, type a few letters, and fuzzy search finds your saved hosts, snippets, active forwards, or settings. Local key monitoring intercepts arrow keys and escape, so you can execute actions without touching the mouse.
Dozens of small decisions that add up to a client you actually enjoy using.
Every credential is stored in the macOS Keychain. Nothing ever leaves your Mac in the clear.
Preview remote files instantly with the spacebar — no download, no detour.
Full support for keyboard-interactive multi-round authentication challenges.
Watch active connections, history, and real node stats inside the Parco Server welcome screen.
Create local, remote, and dynamic SOCKS5 tunnels with rules configuration.
Filter any listing as you type to find the one file among thousands in a heartbeat.
Every transfer is recorded with speed, duration and the exact error if it failed.
Calculate the size of a remote folder with a live count and a Stop button.
Map your web root once, then copy the public address of any remote file from the context menu.
Migrate every server in seconds, including wildcards and ProxyJump bastions.
Verifies host fingerprints with strict Trust-On-First-Use checks. Changes block the connection.
Stay connected to several servers at once and switch sessions in a click.
Save commands and run them locally in your terminal or on multiple hosts.
Cap the global transfer speed so a big upload never hogs your whole connection.
Keep your saved hosts in sync across all your Macs via CloudKit, and credentials via iCloud Keychain.
Edit remote files directly in your local editor, with watch mode auto-upload on save.
Reach servers that only answer through an SSH bastion. Up to 8 hops supported natively.
Upshell runs inside Apple's App Sandbox and treats your servers and credentials the way a native Mac app should.
The app is fully sandboxed per Apple's guidelines, and every password lives in the system Keychain — never in plain text.
SFTP and SSH host keys are pinned in a known-hosts store. If a fingerprint changes, Upshell stops and blocks to protect you from MITM.
There's no Upshell login, no telemetry, and no analytics harvesting your activity. Your sites, keys and files are yours.
RSA and ed25519 keys are read locally and used only to authenticate. They're never uploaded, copied or shared with anyone.
From managing production clusters to homelab tinkering, Upshell fits the way you work.
Manage fleets of servers, ProxyJump through bastions, execute snippets, and keep port forwards under control.
Open tabs and splits, edit remote configurations directly in VS Code, and browse remote directories over SFTP.
Save credentials securely in Keychain, import ssh_configs, and connect with a single click.
Organize saved hosts with tags and environment colors, and sync them across all your Macs through iCloud.
Coming from another client? Upshell imports your whole server list so you don't retype a single host, port or username.
Point Upshell at your ~/.ssh/config.
Import the config file — every host, port, username, ProxyJump and tunnel comes across intact.
Add passwords to the Keychain or select your SSH private key, and you're connected.
Core SSH terminal and SFTP connections are always free. Pro adds advanced automation — choose subscription or lifetime.
| Feature | Free | Pro |
|---|---|---|
| Free · Pro 19,90 €/yr or 99,00 € once | — | ✓ |
| Yes (Swift) | ✓ | ✓ |
| Tabs only · splits in Pro | ✓ | ✓ |
| Yes | ✓ | ✓ |
| Yes | ✓ | ✓ |
| — · Pro only | — | ✓ |
| — · Pro only | — | ✓ |
| — · Pro only | — | ✓ |
| Yes | ✓ | ✓ |
| — · Pro only | — | ✓ |
| — · Pro only | — | ✓ |
| — · Pro only | — | ✓ |
| — · Pro only | — | ✓ |
No forced subscriptions. Flexible plans. Free core features.
Everything you need to connect to your servers.
Professional automation suite, billed annually.
One-time purchase, own it forever.
All paid plans support Family Sharing. You can restore purchases on any of your Macs.
Practical write-ups on the problems remote servers and bastions throw at you — useful whichever client you use.
How to generate an ed25519 key, install it on your server, and use it for SSH and SFTP from a Mac client — including what App Sandbox means for reading ~/.ssh and how passphrases are handled.
Read guide →How to configure local (-L), remote (-R), and dynamic (-D) SOCKS5 port forwarding on macOS, and manage tunnels through a visual client instead of the terminal.
Read guide →How to temporarily rename SSH tabs and set custom environment tags and tinting colors in Upshell to easily manage multiple sessions connected to the same host.
Read guide →How SSH agent forwarding works, the security risks of forwarding standard sockets, and how Upshell runs a secure in-process agent to restrict key access per host.
Read guide →