Skip to main content

Documentation

Install, licensing, connections, AI integration and security, answered.

Install & platforms

How do I install SSHive?

SSHive is on the App Store. On a Mac, open the Mac App Store and search for SSHive, or use the download page. On iPhone and iPad, open the App Store. It is a Universal Purchase: buying Pro once covers all three platforms. SSHive is distributed through the App Store only, there is no separate DMG to download.

Which systems does SSHive support?

macOS 12 Monterey or later on an Apple Silicon Mac (M1 or later). The iPhone and iPad app needs iOS 17 or later on iPhone and iPadOS 17 or later on iPad.

Do I need an account?

No. SSHive has no account, no sign-up and no login. Nothing about your servers is sent to us. The app works fully offline apart from the connections you open yourself.

Which features are Mac-only?

The MCP server for AI assistants, broadcast mode, SOCKS5 (-D) tunnels, the built-in OTP authenticator, FTP and FTPS, the serial console, the Telnet client and the in-terminal AI assistant are macOS features. SSH, SFTP, RDP, VNC, local (-L) and remote (-R) tunnels, jump hosts, shared accounts, session logging, snippets and the network tools run on all three platforms. Remote tunnels, jump hosts, shared accounts and session logging need Pro, but that is a tier and not a platform: Universal Purchase unlocks them on iPhone and iPad too. The VPN client (IKEv2, IPSec, OpenVPN) is on iPhone and iPad only: the Mac App Store build has no VPN at all.

Free and Pro

What does the free version include?

The SSH terminal, the SFTP file manager with uploads up to 10 MB per file, 2 simultaneous sessions, 5 saved profiles, 1 local SSH tunnel (-L), the built-in snippet library plus 3 custom snippets, 3 OTP tokens and the dark theme. There is no trial period and no expiry: the free tier stays free.

What does Pro unlock?

Unlimited sessions and profiles, unlimited SFTP transfer size, RDP and VNC, remote (-R) and SOCKS5 (-D) tunnels, broadcast mode, the MCP server, jump hosts, shared accounts, encrypted profile export and import, session logging, opt-in iCloud sync, unlimited custom snippets and OTP tokens, every theme, and the VPN client on iPhone and iPad.

How much is Pro, and is it a subscription?

Pro is a one-time purchase of $12.99 on the App Store. There is no subscription and no recurring fee. It is a Universal Purchase, so buying it once unlocks Pro on Mac, iPhone and iPad with the same Apple ID. The pricing page sets out what Free and Pro each include.

After an update the app says I am back on Free. What do I do?

Open Settings, go to Purchases, and tap Restore Purchases. This re-confirms your existing purchase with Apple and costs nothing. It happens when the StoreKit receipt has not refreshed yet on the first launch after an update. A permanent fix is on the roadmap; if restoring does not work, email contact@netmesafe.com with your App Store country.

Connections & profiles

How do I import my existing SSH config?

On the Mac, import ~/.ssh/config in one click from the sidebar: SSHive parses Host, HostName, User, Port, IdentityFile and ProxyJump entries and creates one profile per host. Sessions exported from PuTTY (a .reg registry file), MobaXterm (a cleartext MobaXterm.ini) and Royal TSX (a .rtsx file) come in through Settings > Import / Export > Import from another tool. There is no direct import from Termius, SecureCRT, iTerm2 or Tabby: if your hosts are in ~/.ssh/config, importing that file brings them in. The free tier imports up to 5 profiles. The import guide walks through each step.

Can I move my profiles to another machine?

Yes, two ways. Pro users can turn on opt-in iCloud sync, which keeps profiles in step across Mac, iPhone and iPad through your own private iCloud database. Alternatively, export an encrypted .sshive file protected by a passphrase (scrypt key derivation and AES-256-GCM) and import it on the other device.

How do SSH tunnels work?

Tunnels are configured per profile in the Advanced section of the profile dialog and start automatically when the connection is established. Local forwards (-L) map a port on your machine to a host reachable from the server. Remote forwards (-R) and the SOCKS5 dynamic proxy (-D) are Pro features, and SOCKS5 is Mac-only. The free tier includes one local tunnel. The SSH tunnels page lists the per-profile limits on the Mac.

Where is my data stored?

Connection profiles live in the application support directory. Passwords and private key passphrases are never kept in a database of ours. On the Mac they are encrypted with Electron's safeStorage, whose key is kept in the macOS Keychain, then saved encrypted on the Mac; you can also require Touch ID before they are decrypted (off by default). On iPhone and iPad they go into the iOS Keychain as a device-only item excluded from iCloud backups, unlocked by Face ID or Touch ID when biometric protection is on. With iCloud sync (a Pro feature) turned on, an already-saved password can be mirrored to your iCloud Keychain. Host fingerprints are kept in a known-hosts store you can review.

AI and automation

Can Claude or Cursor drive my servers through SSHive?

Yes, on macOS. SSHive runs a local MCP server (Model Context Protocol) on 127.0.0.1 port 49422, protected by a Bearer token, and exposes 20 tools covering SSH command execution and full SFTP file management. Three of them (ssh_list_profiles, ssh_connect and ssh_disconnect) stay hidden unless you turn on "let the assistant open sessions". Turn the server on in Settings, MCP. SSHive does not write any client configuration for you: copy the claude mcp add command for Claude Code, paste the JSON block into Cursor, and install the one-click extension in Claude Desktop. MCP is a Pro feature.

Can the AI see my passwords or private keys?

No. The MCP server exposes sessions, not credentials. The passwords, private keys and passphrases SSHive stores stay encrypted, and no tool returns them; the assistant sees the host, port and user of the sessions it may use. An assistant can run a command on a session you have already opened, and unless you let it open sessions, it can only reach servers you are currently connected to.

Is there an AI assistant inside the terminal?

Yes, on macOS. Select some output and ask SSHive to explain an error, or ask a free-form question. It uses your own API key for Anthropic Claude, OpenAI, Google Gemini or Mistral, or any OpenAI-compatible endpoint such as LM Studio or Ollama; the key is stored encrypted in the Keychain and requests go straight from your Mac to the provider you picked. Nothing passes through our servers.

Security & privacy

Is my data secure?

Credentials are encrypted through the operating system Keychain, the app validates every internal call, and the renderer runs sandboxed with context isolation. There is no telemetry and no analytics inside the app, and no network traffic beyond the SSH, SFTP, RDP and VNC connections you open. You can also lock the app itself behind a master password.

Does SSHive send anything to the cloud?

Not unless you ask for it. The only optional network feature is iCloud sync, which is off by default, is a Pro feature, and uses your own private iCloud database rather than any server of ours; credentials travel through a separate end-to-end encrypted channel.

Does SSHive verify host keys?

Yes. SSHive keeps a known-hosts store and prompts you the first time it sees a server, then warns you if a fingerprint ever changes, which is what protects you from a man-in-the-middle. You can review and remove stored fingerprints from the settings.