Documentation

NexSSH User Guide

Everything NexSSH 1.0 can do, section by section — from your first connection to full automation.

12 sectionsReads top-to-bottom, or jump via the list

01Getting started

NexSSH is an advanced SSH management toolkit for Windows. It brings together a multi-tab SSH terminal, a dual-pane SFTP file manager, live server monitoring, a visual toolbox for automation, port forwarding and an encrypted credential vault — all in one desktop application. Everything runs locally on your machine: your settings, credentials and logs never leave it, and the app contains no telemetry of any kind.

Migrating from another client?

Skip ahead to Connections & hosts — NexSSH imports your existing OpenSSH config (~/.ssh/config) automatically, including users, ports, identity files and ProxyJump entries.

02Installation

NexSSH ships as a self-contained installer for Windows 10 and 11 (64-bit). No extra runtimes or frameworks are required — everything is bundled. Downloads are reserved to registered users, so create a free account first if you have not already.

Four steps and you are in

  1. 1Sign in and download NexSSH-Setup-1.0.exe from the Download page.
  2. 2Run the installer and follow the setup wizard.
  3. 3Launch NexSSH from the Start menu or the desktop shortcut.
  4. 4Optionally set a master password in Settings to lock your vault.

No administrator rights needed

All of your data lives in a per-user profile folder inside your user's application-data directory, so day-to-day use never requires elevation.

Uninstall-safe

Uninstalling the app never deletes your profile — your hosts, settings and vault survive a reinstall without any extra work.

03Connections & hosts

The host manager is the heart of NexSSH. Each host stores its address, port, authentication method and display options, presented as a card grid with live health dots and automatic distribution logos detected from the server. Hosts can be grouped, described and searched instantly.

Authentication

  • Password authentication, saved per host and encrypted at rest
  • Private-key authentication with optional key passphrase
  • SSH Agent support using keys already loaded on your PC
  • Interactive two-factor dialog when a server asks for a verification code

Routing & network

  • Jump host / bastion routing for servers behind a gateway
  • Outbound HTTP, HTTPS, SOCKS5 or SOCKS4 proxy — with authentication
  • Configurable keep-alive per host (15 s to 120 s, or off)
  • Auto-reconnect with smart back-off, up to 8 attempts

Host cards & groups

  • Card grid with groups, descriptions and instant search
  • Health dots driven by monitoring — problems visible before you connect
  • Distro logos detected from /etc/os-release over SSH
  • Wake-on-LAN: store a MAC address and power the machine on from the app

Import, export & restore

  • Import from your OpenSSH config, including ProxyJump entries
  • Export your saved hosts back to OpenSSH config format
  • Session Manager import/export as JSON
  • Session restore: reconnect to your last servers on startup

Trust-on-first-use host keys

NexSSH pins every server's fingerprint the first time you connect and shows it to you for confirmation. If the key ever changes you get an explicit "possible security risk" warning before anything proceeds.

04Terminal

The terminal is a custom-built ANSI emulator tuned for real work — not an embedded general-purpose widget. It handles alternate-screen applications, bracketed paste, application cursor keys and keeps full-screen programs perfectly aligned while you resize.

Multi-tab & split view

Open as many tabs as you need (Ctrl+T) and split a tab to run a second shell on the same connection.

Two kinds of search

Ctrl+F searches the current terminal with next/previous navigation; Ctrl+Shift+F searches every open terminal at once.

8 themes & zen mode

Nord, Cobalt2, Cyberpunk, Rosé Pine and more — plus F11 zen mode and per-tab font size controls.

Logging & recording

Log any session to a file, record terminals to asciinema .cast and replay them, or export a transcript to PDF.

Clickable links & paths

Ctrl+Click opens URLs in your browser and filesystem paths directly in the SFTP panel.

3,000-line scrollback

A deep scrollback buffer with a live-resizing remote PTY, so long builds never get truncated.

Command history & palette

Your last 500 typed commands are kept in a local, searchable history — and the fuzzy Command Palette (Ctrl+K) jumps you to any host, tab, snippet or command instantly.

05Files & SFTP

Switch any tab to SFTP mode and you get a dual-pane file manager: your machine on one side, the server on the other. Everything runs over the SSH connection you already have.

Moving files

  • Drag & drop between panes, or drop files straight from Windows Explorer
  • Transfer queue with up to 3 parallel jobs
  • Pause, resume, cancel and retry each transfer individually
  • Classic ZMODEM rz / sz inside the terminal for quick single-file moves

Remote file operations

  • Create folders and files, rename, delete and refresh
  • chmod dialog for permission changes
  • Preview with truncation and binary detection
  • Built-in editor that falls back to sudo when a system file is not writable

Compare & Sync

Diff a local folder against a remote one by size (optionally modification time, with a ±2 s tolerance) and sync missing or different files in either direction with one click.

Find things fast

Recursive filename search on the remote side, plus per-server bookmarks for the paths you visit all the time.

06Monitoring

The Monitor tab shows live CPU and memory ring gauges with sparkline history, plus network down/up traffic for any connected host. Readings are pulled from the server's /proc filesystem over the SSH connection itself.

No agent, no daemon, nothing to install

NexSSH reads /proc/stat, /proc/net/dev and free -m over SSH every 2 seconds. The server side needs absolutely nothing beyond the SSH access you already have.

Live gauges

  • CPU and memory ring gauges with sparkline history
  • Network down/up traffic sparklines
  • Measured connection latency shown per session
  • Process manager to list remote processes and kill offenders

Threshold alerts

  • Per-host CPU, RAM and disk thresholds (1–100 %)
  • Check intervals from 15 seconds to 1 hour
  • One notification per crossing — no spam
  • Per-host snooze: 30 minutes, 1 hour, 4 hours or off

07Toolbox

The toolbox gathers the everyday server tools most people stitch together from shell one-liners — all visual, all through your existing SSH connection.

Broadcast

Send one command to many servers at once and collect every output in one place.

Run on Multiple Hosts

Parallel execution with saved command presets and per-host exit codes and timing.

Scheduler

Run any command on an interval or a daily schedule, bound to any saved host.

Docker manager

Start, stop and restart containers, list stopped ones and follow their logs.

Live Logs

Follow journalctl or tail -F with live filtering, highlighting and match-only mode.

SSH Key Manager

Generate keys, copy public keys and deploy them straight to a server's authorized_keys.

systemd services

List, start, enable and inspect services — with optional sudo.

Crontab editor

Edit remote crontabs with safe atomic saving and an automatic backup line.

Disk Usage analyzer

Drill down into du output with percentage bars to find what eats your space.

Password Generator

CSPRNG passwords or memorable passphrases with a live entropy strength meter.

08Tunnels & forwarding

Port forwarding is fully visual: create tunnels from a form instead of long command lines, and manage every active forward from one dialog with stop buttons.

ssh -L

Local forwarding

Pull a remote service onto your machine — databases, dashboards, anything the server can reach.

ssh -R

Remote forwarding

Publish a local service back through the server so others can reach it.

ssh -D

Dynamic SOCKS

A real SOCKS5 (and SOCKS4) proxy on localhost that any application can point at.

One-click Quick Tunnels

Presets for the ports you open every week — pick one from the host context menu and the tunnel is up in a second:

HTTP · 80HTTPS · 443MySQL · 3306PostgreSQL · 5432Redis · 6379MongoDB · 27017Node/Next dev · 3000Docker API · 2375+ custom port

Self-healing tunnel profiles

Save named tunnel profiles with autostart, and a built-in watchdog restarts them automatically (checking every 8 seconds) if the connection drops — ideal for database GUIs, internal dashboards and long-lived routes.

09Automation

Three building blocks turn repetitive server work into one click — and the Command Palette ties them together.

SNIPPETS

Reusable commands

Store your most-used commands and insert them into any terminal in two clicks. Also reachable from the palette.

MACROS

Key & command sequences

Record a named sequence of commands and replay it on the active tab — or connect and run it straight from a host's context menu.

HOOKS

Lifecycle events

Run local commands on pre/post connect and pre/post disconnect — start a tunnel, notify a chat, log your time. Global or per-host, and audit-logged.

Command Palette

Press Ctrl+K for fuzzy search across servers, open tabs, snippets, history and commands. Your last 500 typed commands stay in a local, searchable history.

10Security & vault

Everything NexSSH knows about you stays in one folder on your PC. Secrets are encrypted at rest, integrity-checked and audited locally — and none of it ever leaves your machine.

Encrypted at rest

  • Saved passwords (including jump-host and proxy credentials) sealed with Windows DPAPI, per user
  • On other platforms: Fernet encryption with a random 32-byte key file restricted to your account
  • If neither mechanism is available, the app tells you plainly that storage is unprotected

Master-password vault

  • Optional master password encrypts the entire workspace
  • PBKDF2-HMAC-SHA256 at 600,000 iterations with a random salt
  • Change or remove it at any time from Settings
  • No recovery backdoor — and only a few unlock attempts are allowed

Host-key safety

  • Trust-on-first-use pinning with a visible fingerprint prompt
  • Loud warning if a server's key ever changes
  • Known Hosts manager to review or forget saved fingerprints
  • Key-change rejection also applies on the two-factor path

Backups & integrity

  • One-file encrypted backup (.s2bak) of hosts, settings, snippets and more
  • Restore by replacing or merging, with passwords kept encrypted
  • HMAC-SHA256 integrity tags on 13 core data files, verified at startup
  • Sanitized local audit log — records events, never passwords

11Keyboard shortcuts

NexSSH is fully operable from the keyboard. These are the bindings the app ships with:

Ctrl + TOpen a new terminal tab
Ctrl + WClose the current tab
Ctrl + Tab / Ctrl + Shift + TabCycle to the next / previous tab
Ctrl + ,Open settings
Ctrl + KCommand Palette — fuzzy search hosts, tabs, snippets & commands
Ctrl + FSearch inside the current terminal
Ctrl + Shift + FSearch across all open terminals
Ctrl + Shift + C / V / ACopy / paste / select-all in the terminal
Ctrl + SSave the file you are editing in the built-in editor
F11Toggle Zen mode (full-screen, distraction-free)
EscClose dialogs and pop-ups

12Troubleshooting

The four issues people run into most often — and what to do about each.

Connection refused or timed out

Verify the address and port and confirm the SSH service is running. Corporate firewalls often block non-standard ports — if the server sits behind one, route the connection through the proxy options on the host.

Authentication failed

Double-check the username; for key auth, confirm the public key is in the server's authorized_keys. If the server uses 2FA, keep the authenticator app ready — NexSSH will open a dialog asking for the code.

“Host key changed” warning

This fires when a server presents a different fingerprint than the one pinned on first connect. If you know the server was rebuilt or its key rotated, open the Known Hosts manager and remove the old entry; if you did not expect it, do not connect — investigate first.

Vault will not unlock

The master password cannot be reset or bypassed by design. Restore from an encrypted backup file (.s2bak) if you kept one, otherwise a new workspace must be created.

Still stuck?

The developer personally answers on Telegram — find every contact channel on the Support page, or browse the quick answers in the Help center.

End of the guide

That is the complete tour — all 12 sections, from installation to troubleshooting. If something did not work as described here, the Help center covers the common fixes, and every contact channel is on the Support page.