SSH into a Raspberry Pi from your Mac
The shell and file copies for everyday upkeep, a tunnel to Home Assistant, and the Pi desktop when you need it, from one Mac app.
By Lucas Russo, developer of SSHive · Updated
A Raspberry Pi tends to end up running something the household relies on: Pi-hole, Home Assistant, a small web server, a script on a timer. Looking after it from a Mac comes down to four jobs: a shell for
apt and config files, a way to copy files across, a look at the desktop now and then, and a route to the web pages it serves without opening them to the whole network.
SSHive keeps the four in one window, with the Pi saved as a profile. The shell, the file transfers and one local tunnel are free, and one tunnel is exactly what Home Assistant's port 8123 needs. Only the desktop, over VNC, calls for Pro.First connection: turn SSH on
SSH is off on a fresh Raspberry Pi OS install. The simplest way to turn it on is before the first boot: in Raspberry Pi Imager, under Customisation > Remote Access, switch on Enable SSH and set a username and a password. On a Pi that is already running, use
sudo raspi-config, then Interface Options > SSH, or Control Centre > Interfaces on the desktop.
A fresh install answers to the hostname raspberrypi, so from the Mac ping raspberrypi.local should reply. In SSHive, create a New Connection with raspberrypi.local as the host (or the address your router gave the Pi), the username you chose in Imager and its password. Give it a name you will recognise in the sidebar: from then on the Pi is one click away.Swap the password for a key
A password is fine for the first login; a key is better for every one after. In SSHive, open Settings > SSH Keys and choose Generate a key (Ed25519 is the default). With the Pi session open, choose Install on host: SSHive adds the public key to
~/.ssh/authorized_keys on the Pi through that session. Edit the Pi profile to sign in with the key and connect again to check it works. The SSH key guide covers the same steps with the macOS Terminal.
Only then turn password logins off on the Pi, keeping your current session open in case something goes wrong:
echo "PasswordAuthentication no" | sudo tee /etc/ssh/sshd_config.d/01-no-passwords.conf && sudo systemctl restart ssh
Afterwards, sudo sshd -T | grep -i passwordauthentication should print passwordauthentication no.Home Assistant through a tunnel
Home Assistant answers on port 8123. Rather than forwarding that port on your router, let the SSH connection carry it. Edit the Pi profile and add a tunnel under Local Tunnels (-L): local port 8123, remote host
localhost, remote port 8123. Connect, then open http://localhost:8123 in your browser on the Mac. The page travels inside the SSH connection, and nothing new is exposed on the network.
That tunnel is included in the free version. A second one on the same profile, say local port 8080 to port 80 for the Pi-hole admin page, needs Pro.The Pi desktop over VNC
Raspberry Pi OS ships wayvnc as its VNC server. Turn it on with
sudo raspi-config, Interface Options > VNC; a viewer then signs in with the Pi's own username and password. The Mac app handles the VeNCrypt / X.509 sign-in wayvnc uses: create a VNC profile pointing at the Pi and enter those credentials. VNC is part of Pro.
On a network you do not trust, send it through SSH: add a local tunnel from port 15900 to localhost:5900 on the Pi profile, and point the VNC profile at localhost:15900. The VNC guide covers other VNC servers. One limit to know: the iPhone and iPad app does not do VeNCrypt / X.509, so a Pi that requires it is reachable from the Mac only.What is free here, and what needs Pro
Everything above the VNC section works in the free version: SSH, SFTP with uploads of up to 10 MB per file, one local tunnel on the profile, 5 saved profiles and 2 SSH sessions at once. SSHive Pro adds the VNC desktop, more tunnels, uploads without the size cap for a disk image or a backup, and broadcast once you run several Pis. It is a one-time purchase of $12.99, valid on the Mac, iPhone and iPad.
Frequently asked questions
My Pi does not answer as raspberrypi.local+
The
.local name comes from mDNS: the Pi announces itself with avahi-daemon, and macOS resolves it through Bonjour. On the Pi, systemctl status avahi-daemon should say active. On the Mac, dns-sd -G v4 raspberrypi.local shows whether the name resolves and to which address. If you changed the hostname in Imager, use that name instead. Failing that, find the Pi in your router's list of connected devices and put its IP address in the profile.Does it work with a Raspberry Pi 5 or a Pi Zero?+
Yes. SSHive speaks SSH, SFTP and VNC to whatever runs on the other end, so the model does not matter: a Pi 5, a Pi 4 or a Pi Zero 2 W on Raspberry Pi OS behaves the same. What differs between releases is the VNC server. Older releases on the X11 desktop use RealVNC Server, whose RSA-AES sign-in the Mac app also handles.
Can I reach the Pi from my iPhone as well?+
Yes, for the shell and the files: the iPhone and iPad app does SSH and SFTP, and the same Pro purchase unlocks both apps. For the desktop, see the note on VeNCrypt / X.509 above.
Related SSHive features
Try SSHive Free for macOS
Get the all-in-one SSH, SFTP, RDP and VNC client for Mac. Free download, no signup required.