sshguru Start free
A home wifi router

Open a port and hope nobody finds it.

Router settings, dynamic DNS, fail2ban, and a VPN client on every device you own.

Inbound, from anywhere on the internet.

An ESP32-S3 SuperMini on a short USB cable
plugged into the USB port of the same home router, which is otherwise untouched
sshguru

SSH into anything, whatever it sits behind.

A $5 board on your network, the SSH client in your browser, and nothing to change on your router.

Start freeSign in

Outbound only. Nothing listens on your network.

What does your server sit behind?

Pick one. This side of the page rewrites itself for it.

It doesn't matter.

Home router, Starlink, an office firewall, a phone hotspot, someone else's router. Pick any of them. Nothing on this side of the page changes.

The usual way, behind a home router

0 steps so far

    Sample: what a port 22 open to the internet logs

    SSH Guru, behind anything

    4 steps, total

    1. Create a free account and set a vault passphrase.
    2. Flash a $5 ESP32-S3 from the browser (Chrome or Edge).
    3. Write its allow list: this machine, port 22.
    4. Plug it into any powered USB port: a charger, or the router itself.

    The same four for every choice on the left. The board only ever dials out, so there is nothing to open.

    Where your key goes

    Most web SSH tools run the SSH client on their own server. You upload your private key, and their machine logs in for you.

    1. Your browser
    2. Their serverholds your key
    3. Your server

    It stays in your tab.

    The SSH client is compiled to WebAssembly and runs in the page. Your key is encrypted with your passphrase before it is stored. The relay and the board only ever carry scrambled bytes.

    1. Your browserholds your key
    2. Relayciphertext
    3. Boardciphertext
    4. Your server

    An AI agent with a shell

    It decides, it runs, and you read about it afterwards.

      Illustration of the pattern, not a real product's output.

      The Guru asks first.

      Tier 1 · changes stateproposed by the Guru
      sudo journalctl --vacuum-size=500M

      Deletes archived journal files beyond 500 MB. Active logs are untouched.

      Tiers come from fixed rules, not from the model. Destructive commands make you type the hostname.

      Done for the day?

      Done for the day?

      Switching it off

      Behind a home router

        Until you do, it keeps answering anyone who asks.

        The bridge board on its cable

        Unplug it.

        Bridge online. Dialling out to SSH Guru.

        Nothing on your network is reachable now. Plug it back in when you need it.

        Your machines, behind your home router, from any browser.

        Free for three servers and 30 Guru messages a day. Pro is $9 a month, Team is $29 a month for five people.

        Start freeSign in