Portal is a native SSH and VNC client built for speed and simplicity. Manage your servers with an intuitive interface that's equally comfortable with keyboard shortcuts or mouse navigation. Built with Rust for native performance, with full Wayland support on Linux.
>_ Multi-Tab Terminal — Manage multiple SSH sessions in tabs. Switch between servers instantly without juggling windows.
<> Portal Hub Beta — Keep SSH terminal sessions alive through a Tailscale-only hub, sync hosts/settings/snippets, and store encrypted private-key vault items.
< > Dual-Pane SFTP — Browse local and remote files side by side. Drag, drop, copy, and manage files with ease.
{ } Smart OS Detection — Automatically detects 20+ operating systems and displays branded icons for Ubuntu, Debian, Arch, Fedora, and more.
#! Built-in File Viewer — View code with syntax highlighting, preview images and PDFs, edit markdown—all without leaving Portal.
:: Beautiful Themes — Choose from 6 built-in themes including the popular Catppuccin palette in both light and dark variants.
/> Command Snippets — Save frequently used commands and insert them into any session with a click. Never retype complex commands.
[] VNC Remote Desktop — Connect to VNC servers with GPU-accelerated rendering. Supports multiple encodings, ARD authentication, and multi-monitor displays.
- Multi-tab sessions — Open multiple SSH connections in tabs
- Local terminal — Launch local shell sessions alongside remote connections
- Scrollback search — Find text in the terminal buffer with
Ctrl+Shift+F - Clickable links —
Ctrl+clickURLs and file paths in terminal output; files open in the built-in viewer at the referenced line - Port forwarding — Local, remote, and dynamic (SOCKS5) forwards per host
- Jump hosts — Chain connections through bastion hosts (ProxyJump)
- Auto-reconnect — Reconnects dropped sessions with exponential backoff
- Session logging — Optionally log terminal output to disk, plain or timestamped
- Adjustable font size — Scale from 6px to 20px for your preference
- Configurable scroll speed — Tune mouse wheel and trackpad scrollback speed
- SSH key installation — Install your public key on remote servers with
Ctrl+Shift+K - Image clipboard paste — Paste a screenshot into an SSH terminal to upload it and insert the remote image path
- Status bar — See hostname and connection duration at a glance
- Session history — Quick reconnect to recent servers
- Portal Hub beta — Route selected SSH hosts through Portal Hub for persistent remote terminal sessions, resumable thumbnails, reconnect replay, profile sync, and encrypted key vault storage
- Dual-pane interface — Local filesystem on one side, remote on the other
- File operations — Copy, rename, delete, and change permissions
- Hidden files toggle — Show or hide dotfiles with one click
- Quick filter — Search files in the current directory
- Breadcrumb navigation — Click any part of the path to jump there
- Context menus — Right-click for common actions
- Host groups — Organize servers into folders
- SSH config import — Import hosts (including ProxyJump chains) from
~/.ssh/config - Quick connect — Type
user@hostnameto connect instantly - Search & filter — Find hosts as you type
- Connection history — See when you last connected and for how long
- OS detection — Automatic identification with branded icons for:
- Ubuntu, Debian, Fedora, Arch, CentOS, RHEL
- openSUSE, NixOS, Manjaro, Linux Mint, Pop!_OS
- Gentoo, Alpine, Kali, Rocky, AlmaLinux
- macOS, FreeBSD, OpenBSD, NetBSD, Windows
- Syntax highlighting — Support for 20+ languages including Rust, Python, JavaScript, Go, and more
- Image viewer — View PNG, JPG, GIF, WebP, SVG with zoom controls
- PDF viewer — Read PDF documents with page navigation
- Markdown preview — Toggle between edit and rendered preview
- In-app editing — Make quick edits without leaving Portal
- GPU-accelerated rendering — Custom wgpu shader for efficient framebuffer display
- Multiple encodings — Tight, ZRLE, CopyRect, and Raw with automatic selection
- ARD authentication — Apple Remote Desktop support for macOS Screen Sharing
- SSH tunneling — Carry VNC traffic over an encrypted SSH channel; the toolbar warns when a session runs unencrypted
- Scaling modes — Fit, Actual (1:1), and Stretch modes
- Keyboard passthrough — Forward all keystrokes to the remote desktop
- Special key toolbar — Send Ctrl+Alt+Del, Alt+Tab, Super, Print Screen, and more
- Clipboard sharing — Bidirectional clipboard between local and remote
- Screenshot capture — Save the current VNC view to a file
- Adaptive quality — FPS tracking with configurable refresh rate, encoding, and color depth
- 6 built-in themes
- Portal Default
- Catppuccin Latte (light)
- Catppuccin Frappé (dark)
- Catppuccin Macchiato (dark)
- Catppuccin Mocha (dark)
- Noctalia (dark)
- Responsive layout — Sidebar auto-collapses on narrow windows
- Keyboard-first — Full keyboard navigation support
Download from the Releases page: https://github.com/DigitalPals/portal/releases
Pick the file that matches your OS and CPU:
| Platform | Asset name |
|---|---|
| Linux (arm64) | portal-*-linux-arm64.deb / .rpm / .tar.gz |
| Linux (x86_64) | portal-*-linux-x86_64.AppImage / .deb / .rpm / .tar.gz |
Verify downloaded release assets with:
sha256sum --ignore-missing -c SHA256SUMSPick one of these options:
AppImage (x86_64):
chmod +x portal-*-linux-x86_64.AppImage
./portal-*-linux-x86_64.AppImageDEB (Debian/Ubuntu):
sudo dpkg -i portal-*-linux-*.debRPM (Fedora/RHEL):
sudo rpm -i portal-*-linux-*.rpmTarball (manual):
tar -xzf portal-*-linux-*.tar.gz
sudo mv portal /usr/local/bin/
portalPortal is built for Wayland. If it does not start, install your distro's Wayland/XKB/Vulkan runtime packages and try again.
Requires Rust 1.88 or later.
git clone https://github.com/DigitalPals/portal.git
cd portal
./run.sh build
./run.sh runBuild commands:
./run.sh build # Build release binary
./run.sh run # Build and run release
./run.sh dev # Build and run debug
./run.sh check # Run cargo check and clippyBuilds run locally and write artifacts to Cargo's normal target directory:
target/release/portal for build and target/debug/portal for direct debug
builds. On Linux, run.sh prefers an installed Cargo toolchain and falls back
to nix develop when Cargo is not available directly.
Linux requires a C compiler, pkg-config, and the Wayland, XKB, Vulkan, and
GLib development packages. The DBus C library is vendored by Cargo so local
builds do not require a distro-specific DBus development package.
Portal logs to the console and to a daily rotating file in the config logs
directory. The default log level is INFO in debug builds and WARN in release
builds. Override it with RUST_LOG.
Environment variables:
PORTAL_LOG_DIR(optional) - set a custom log directory. Set to an empty string to disable file logging.PORTAL_MAX_COMMAND_OUTPUT_BYTES(optional) - cap command output collected from SSH exec calls. Default: 4194304 (4 MiB).PORTAL_VNC_ENCODING(optional) - VNC encoding preference:auto,tight,zrle, orraw. Default:auto.PORTAL_VNC_COLOR_DEPTH(optional) - color depth in bits:16or32. Default:32.PORTAL_VNC_REFRESH_FPS(optional) - framebuffer refresh request rate, 1-20. Default:10.PORTAL_VNC_POINTER_INTERVAL_MS(optional) - minimum interval between pointer events in ms. Default:16.PORTAL_VNC_REMOTE_RESIZE(optional) - request remote desktop resize. Default:false.PORTAL_VNC_QUALITY(optional) - quality preset for new VNC sessions:auto,speed,balanced,quality, orlossless. Default:auto.PORTAL_VNC_DEBUG(optional) - enable VNC debug logging.
Example:
RUST_LOG=portal=info PORTAL_LOG_DIR=/var/log/portal ./portalPortal is available as a Nix flake with binaries cached on Cachix.
Run directly:
nix run github:DigitalPals/portal/vX.Y.ZInstall in NixOS configuration (flake.nix):
{
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
# Use a release tag for stable builds with Cachix cache hits.
# Don't use inputs.nixpkgs.follows for portal - it breaks cachix
portal.url = "github:DigitalPals/portal/vX.Y.Z";
};
outputs = { nixpkgs, portal, ... }: {
nixosConfigurations.yourhostname = nixpkgs.lib.nixosSystem {
system = "x86_64-linux";
modules = [
({ pkgs, ... }: {
# Enable cachix for pre-built binaries
nix.settings.substituters = [ "https://digitalpals.cachix.org" ];
nix.settings.trusted-public-keys = [ "digitalpals.cachix.org-1:YWuWBw08EbEeTsIccpPfRTaqksfo4QtAVQaTRljYFm8=" ];
environment.systemPackages = [ portal.packages.${pkgs.system}.default ];
})
];
};
};
}Note: Do not add
inputs.nixpkgs.follows = "nixpkgs"to the portal input. This changes the derivation hash and prevents cachix from providing pre-built binaries.
Note: Replace
vX.Y.Zwith a published release tag. Themainbranch may contain unreleased development changes.
Build from source:
nix build
./result/bin/portal- Launch Portal — Run the application
- Add a host — Click the
+button and enter your server details - Connect — Double-click a host card or press Enter to connect
That's it. You're in.
Portal can route SSH terminal sessions through Portal Hub so remote shells survive a Portal crash, laptop sleep, or network drop. Portal Hub can also store synced hosts, settings, snippets, and encrypted private-key vault items. The hub is intended to run on a small Linux host or LXC reachable only over Tailscale.
To use it:
- Deploy Portal Hub and restrict access with Tailscale ACLs.
- Start the Portal Hub web server and create the first owner account.
- In Portal settings, choose Set up Portal Hub and enter its URL or address. The port is optional; include
:portonly when the Hub uses a custom web port. - Check the connection, then use Sign in to authenticate through the browser.
- Choose the profile-sync, Vault, and default host-routing options for this device.
- Review which SSH Agent or Public Key hosts should use persistent Hub sessions.
- Open the Sessions view to see active proxy sessions, terminal thumbnails, and resume an existing session.
Typing exit in the remote shell closes the real session. Closing the Portal tab or losing connectivity only detaches Portal from the proxy session.
For SSH hosts that authenticate with a private key (key file or vault key), Portal sends the decrypted key to Portal Hub over TLS when the proxied session starts; the Hub uses it to open the SSH connection to the target. Only route key-based hosts through a Hub you trust with those keys — each transmission is recorded in the security audit log, and the host dialog warns when this applies. SSH Agent authentication does not transmit key material.
Vault private keys are encrypted locally before sync. Portal Hub stores the encrypted blobs but does not receive the vault passphrase or decrypted key material.
| Shortcut | Action |
|---|---|
Ctrl+Shift+P |
Open the command palette |
Ctrl+Shift+F |
Search terminal scrollback |
Ctrl+Shift+K |
Install SSH public key on remote server |
Ctrl+Tab |
Switch to next tab |
Ctrl+Shift+Tab |
Switch to previous tab |
Ctrl+Shift+W |
Close current session |
F11 |
Toggle fullscreen (VNC) |
Ctrl+Shift+S |
Capture screenshot (VNC) |
Ctrl+Shift+V |
Paste clipboard to VNC server |
Ctrl+Shift+Escape |
Release keyboard passthrough (VNC) |
Common shortcuts (new tab/connection, copy/paste, search, fullscreen, and more) are rebindable in Settings.
- Rust — Systems programming language
- Iced — Cross-platform GUI framework
- Alacritty Terminal — Terminal emulation
- Russh — SSH protocol implementation
- vnc-rs — VNC client implementation (vendored)
Portal stores configuration in your platform's config directory:
- Linux:
~/.config/portal/ - macOS:
~/Library/Application Support/portal/
Configuration files:
hosts.toml— Saved host definitions (SSH and VNC protocols)snippets.toml— Command snippetssnippet_history.toml— Snippet execution history (enabled,store_command,store_output,redact_output)settings.toml— Theme, terminal font and scroll preferences, VNC settings, and Portal Hub settingshistory.toml— Connection historyknown_hosts— SSH host key storage
MIT License. See LICENSE for details.


