Skip to main content
iOS 17+ · iPadOS 17+

A VPN client for iPhone and iPad, built into your SSH app

IKEv2, IPSec with Cisco Xauth and OpenVPN on iPhone and iPad, connected before your SSH, SFTP or RDP session and disconnected when you close it. No second app to switch to.

Reaching a protected network from an iPhone usually takes two apps: the VPN client your company hands out, and the app you actually work in. Open one, sign in, switch to the other, work, come back to disconnect. SSHive puts the VPN client inside the app: IKEv2, IPSec with Cisco Xauth, and OpenVPN from a .ovpn file, set up in SSHive and handled by iOS like any other VPN.

Choose a VPN under VPN profile in an SSH profile on the iPhone, an SFTP profile or the profile of a remote desktop on the iPhone: SSHive connects it before the session and disconnects it when you close the session. With Check locally first, on by default, it skips the VPN when the server already answers on the network you are on, so the office Wi-Fi does not pay for the VPN's detour. The VPN client is part of Pro, the one-time purchase of $12.99 that covers iPhone, iPad and Mac; the client itself exists only in the iPhone and iPad app.

What works on iPhone and iPad

IKEv2 / IPSec / OpenVPN

IKEv2 with a user name and password; IPSec with a pre-shared key and Cisco Xauth, the setup many corporate gateways still use; and OpenVPN from the .ovpn file your provider or administrator gives you, with the certificates and keys it carries inline.

A real system VPN

IKEv2 and IPSec use the VPN client built into iOS; OpenVPN runs in a network extension that ships with SSHive. Either way iOS handles the tunnel at the system level, and it shows in the iOS VPN settings instead of hiding in a proxy inside the app.

Connected when a session needs it

Pick a VPN in the VPN profile field of an SSH, SFTP or RDP profile. Opening the session brings the VPN up first, or reuses it if it is already connected; closing the session disconnects it. VNC profiles do not offer this setting.

Local network first

With Check locally first, on by default, SSHive tries to reach the server directly on the network you are on before starting anything. If it answers, the session opens without the VPN; if not, the VPN comes up first. At the office you connect directly, from a hotel through the tunnel, with the same profile.

.ovpn import

In an OpenVPN profile, tap Import a .ovpn file and pick it from Files, iCloud Drive or wherever you saved it. A user name and password are optional, for servers that ask for them; the password is stored in the iOS Keychain.

Why build a VPN into an SSH client

One app for the whole path

A typical night on call: VPN into the corporate network, SSH to a bastion and on to the internal server, a configuration read over SFTP, RDP to a Windows VM. With a VPN profile on each connection and the bastion set as a jump host (Pro), SSHive covers every step without leaving the app.

No traffic through us

The VPN goes from your iPhone to the gateway you configure. SSHive runs no VPN server and no relay, shows no ads and sends no telemetry. The app is paid, $12.99 once for Pro, and that is the whole business model.

Next to Tailscale and WireGuard

If you already use Tailscale or WireGuard, keep them: they stay separate VPN configurations in iOS, and when one of them is connected SSHive uses the route it provides. SSHive's own client is there for the gateways they do not speak: IKEv2, IPSec and OpenVPN.

Other VPN clients on iPhone

OpenVPN Connect

Free

The official OpenVPN client, free. It does OpenVPN and nothing else: you still need a separate SSH or RDP app, and connecting the VPN before each session is up to you.

Cisco Secure Client (formerly AnyConnect)

Free

The standard client for Cisco gateways, free on the App Store. If your company runs AnyConnect, keep it for that: SSHive's IPSec client covers gateways that use Cisco Xauth, not AnyConnect's own protocol.

Tailscale / WireGuard

Free apps; paid Tailscale plans

Modern VPNs built on WireGuard, excellent for personal networks and team meshes. A different job from a corporate IKEv2, IPSec or OpenVPN gateway, and they work alongside SSHive.

How the VPN works on iOS

iOS does not let an app invent its own VPN. It offers two doors, both in Apple's Network Extension framework: the VPN client built into the system, which speaks IKEv2 and IPSec, and packet tunnel providers, extensions an app ships to carry other protocols. SSHive uses both. An IKEv2 or IPSec profile is handed to the system client, with its password stored as a Keychain reference that iOS reads when it connects. An OpenVPN profile runs in SSHive's own tunnel extension, a separate process that iOS starts and manages.

That is why the VPN is a real one: iOS routes traffic into it at the system level, it shows in the iOS VPN settings, and it keeps running independently of SSHive's window. It is also why SSHive takes care to disconnect it. A VPN started for a session is closed when that session ends, and if you leave the app during a remote desktop session that brought up a VPN, SSHive ends both, so that no tunnel stays connected behind your back.

The sequence on call: the alert arrives, you open the saved SSH profile. SSHive checks whether the server answers on the current network; from home it does not, so the VPN comes up, then the SSH session opens through it. You investigate, close the session, and the VPN goes down with it.

As for secrets, the VPN password and the IPSec shared secret are stored in the iOS Keychain, where the system can use them without showing them to anyone. The .ovpn file itself is kept in the app's data on the device. No .mobileconfig configuration profile is installed on the iPhone.

Frequently asked questions

Can I import my company's .ovpn file into SSHive?+
Yes. Create an OpenVPN profile in SSHive, tap Import a .ovpn file and pick the file in Files: AirDrop, Mail or iCloud Drive can put it there first. If the server asks for a user name and password, enter them in the same profile; the password is stored in the iOS Keychain.
Does SSHive VPN log my traffic?+
No. The VPN connects your iPhone directly to your gateway; nothing goes through a server of ours, and the app sends no telemetry. We never see your traffic, the addresses you reach or your credentials.
Can the VPN connect on its own when I open an SSH profile?+
Yes. In the SSH profile, or an SFTP or RDP one, pick the VPN under VPN profile. SSHive connects it before opening the session, unless the server already answers on your local network (Check locally first), and disconnects it when you close the session. If that VPN is already connected, it is reused.
Is the VPN client in the free version?+
No, it is part of Pro, the one-time purchase of $12.99 that also unlocks RDP, VNC and remote tunnels. It exists only in the iPhone and iPad app: the Mac app has no VPN client. A VPN run by another app, Tailscale or WireGuard for instance, works with the free version.

Try SSHive free on iPhone and iPad

Free on the App Store, no account needed: 2 SSH sessions at a time, 5 profiles, SFTP uploads up to 10 MB per file. Pro costs $12.99 once, covers iPhone, iPad and Mac, and unlocks RDP, VNC, the VPN client and remote tunnels in this app.

Download SSHive Free