
Your keys never reach us
Private keys and passwords are encrypted in your browser with a passphrase only you know. We store ciphertext we cannot open. Lose the passphrase and they are gone, and we say so up front.
Describe the problem. The Guru inspects your server, explains what it finds, and proposes one command at a time. You approve, it runs, you both watch the output. Your keys never leave your browser.

sudo systemctl restart nginxOne disk, one afternoon, three commands. Two ran themselves because they only read. The third waited for a click.
user@web-01:~$
Most AI tools ask you to trust the model. This one is arranged so that trust is never required.

Private keys and passwords are encrypted in your browser with a passphrase only you know. We store ciphertext we cannot open. Lose the passphrase and they are gone, and we say so up front.

The Guru can only propose. Approval happens in your browser, not on our servers. A compromised backend or a poisoned log file can write a command card, and still cannot execute it.

The SSH client runs inside your browser. Our relay pipes encrypted bytes to your host and nothing else. It cannot read your session because there is nothing readable to see.

Terminal output passes a deterministic secret scanner before any AI model sees it. Tokens, passwords and keys become placeholders. The model never sees the real values.
Host, user, key or password. The host key is pinned on first connect and you are warned the moment it changes.
A read-only fingerprint you approve once: distro, package manager, init system, running services. No more guessing apt versus dnf.
Chat on the left, terminal on the right. Every proposal is a card with a risk tier. Read-only cards can run themselves if you allow it. Destructive ones need the hostname typed.

The tier comes from a deterministic classifier, never from the model. The Guru cannot talk itself into a lower one.
df -hsystemctl status nginxtail -n 50 /var/log/syslogapt installsystemctl restartjournalctl --vacuum-sizerm -rfdd if=mkfsiptables -FThe Guru is the method: the profile, the playbooks, the tiers, the approval. The model behind it is your choice.
Use the subscription you already pay for, through the same device sign-in the Codex CLI uses. No API key, no per-token bill.
ProOpenAI, Anthropic, OpenRouter, Groq. Encrypted at rest, used only for your sessions, removable in one click.
ProThe free tier runs on our models with a daily cap. Enough to fix a disk, not enough to run a fleet.
FreeHome labs and office racks are not on the internet, and should not be. A bridge is an ESP32-S3 you flash from this browser and plug into any USB power on that network. It dials out to SSH Guru, so nothing is opened inbound: no VPN, no port forwarding, no exposed sshd.

Any ESP32-S3 with a native USB-C port and 4 MB flash works. The XIAO ESP32-S3 adds PSRAM and an antenna connector, worth the extra dollar for a bridge that stays plugged in. SSH Guru flashes it from your browser in about a minute.
As an Amazon Associate we earn from qualifying purchases; other links may pay a small commission at no cost to you.
Free is a real plan, not a trial. Pro is for people who do this every week.
No. The SSH client runs inside your browser. Our relay forwards encrypted bytes to your host and never holds a key, a password or a session. There is no path from our side into your machine.
Your saved keys and passwords are gone. We cannot recover them, because we never had them. Your connection list, host-key pins and history remain. You add the secrets again.
It sees the output of the commands it proposed, after a deterministic secret scanner has replaced tokens, passwords and keys with placeholders. Anything you type manually stays out unless you share it.
Yes, with a bridge: a $5 ESP32-S3 board you flash from this browser. It dials out to SSH Guru, so nothing is opened inbound, and it only dials the subnets and ports you wrote to it over the USB cable. The SSH session is still end-to-end encrypted between your browser and the server; the board carries ciphertext.
Yes, on Pro. The in-browser client dials the bastion and opens the inner connection through it, so the jump host never sees your credentials for the target either.
It uses the same device sign-in flow the Codex CLI uses, under your own subscription and your own usage limits. If that door ever closes, your own keys and the house models keep working.
