czlterm
A lightweight SSH / RDP / VNC connection manager
Terminals and remote desktops open in the programs your system already has; czlterm handles connections, credentials and files. Passwords and private keys come straight from your Vaultwarden, and built-in MCP lets AI work on the servers you allow.
Windows 10 / 11 and macOS 10.15+. Written in Go with Wails: no Java, no Electron
Screenshots
Connection list, machine info, file manager and settings, following your system's light or dark theme. (UI currently in Chinese.)
Main window
Connections in groups with OS logos; the overview shows OS, CPU, memory and disk.
One-click connect
Connect opens SSH in your usual terminal, with the key or password supplied automatically.
File manager
Browse, upload, download, rename and delete over SFTP; double-click to edit, saved back on save.
Edit connection
Credentials only reference Vaultwarden items, never plaintext in the config; multi-hop jump hosts supported.
MCP
Tiered permission switches and ready-to-copy config for Claude Desktop and Claude Code.
Sync
Connections sync through git to your own private repository, with optional username and key.
Let the system do what it does best
No built-in terminal or remote desktop stack: a small app, low memory, and clients you already know.
System clients
SSH in Terminal, iTerm2, Ghostty, WezTerm or Windows Terminal; RDP with mstsc or Windows App; VNC with Screen Sharing or TigerVNC.
Vaultwarden credentials
Passwords and SSH keys are read through the official bw CLI; the session lives in memory and is cleared on lock or quit.
Nothing on the command line
Keys go into a per-connection in-process ssh-agent, passwords are supplied through SSH_ASKPASS; neither touches the disk.
Jump hosts
Each hop of a jump chain can use different credentials, and keys in your system agent still work.
SFTP file manager
Browse, upload, download, rename and delete; double-click to open in VS Code or your editor, saved back automatically.
Machine info
OS, kernel, CPU, memory, disk and uptime are collected after connecting, with Ubuntu, Debian, Windows and other OS logos in the list.
Git sync
One JSON file per connection, no secrets, pushed to your own private repo so every machine shares the same setup.
Open source, auto-update
AGPL-3.0; the app checks for new versions and installs only after the SHA-256 check passes.
Credentials stay put, AI gets to work
Credentials never leave the czlterm process; AI uses your servers through MCP without ever seeing a password.
Vaultwarden as your credential store
Run bw login once in a terminal, then unlock with your master password in czlterm. Connections reference items and store no passwords.
- SSH key items work as-is; add a passphrase field for encrypted keys
- On Windows, RDP credentials go into Credential Manager temporarily and are restored afterwards
- Auto-locks when idle, closing the in-process agents and connections
MCP: put Claude to work on your servers
Tools list connections and directories, read and write files and run commands. Scripts are sent to the shell over stdin, so multi-line scripts, heredocs and quotes run exactly as written.
- Listens on 127.0.0.1 only and requires a token
- Permissions step up: list connections → read files → write files / run commands
- Passwords and keys never pass through MCP
claude mcp add --scope user czlterm -- /Applications/czlterm.app/Contents/MacOS/czlterm mcpFour steps to get started
Install, log in to bw once, and you are ready in minutes.
Install
Windows installs per user without admin rights; on macOS drag it to Applications and run one xattr command if it is reported as damaged.
Log in to bw
Install the Bitwarden CLI with npm, point bw config server at your Vaultwarden, and run bw login once.
Add connections
Create SSH, RDP or VNC connections and pick Vaultwarden items, or keep using your system ~/.ssh.
Turn on extras
Choose your terminal and editor, enable git sync, or switch on MCP for Claude.
FAQ
A few questions you might have before trying it.
Do I have to use Vaultwarden?
Why no built-in terminal?
Can passwords leak to the command line or disk?
macOS says the app is damaged?
Passwords are not filled in on Windows 10?
Could MCP let AI run anything it wants?
Where do I report issues?
Free download, open source
Windows installer and universal macOS build, with built-in updates.
- Free and open source, AGPL-3.0
- Per-user install on Windows, no admin rights
- Universal macOS build for Intel and Apple silicon
- Built-in updates with SHA-256 verification
Open source by CZL
About CZL →CZL focuses on AI, technology and internet services. czlterm is the tool we built to manage our own servers and released as open source.