Skip to content
Home
Docs/Terminal Linux & SSH

Terminal Linux & SSH

FreePro: Split, Broadcast, Automation, Sync

Full Linux terminal with on-device local shell (native PTY + bundled Busybox), SSH/SFTP client with nested host groups, reusable Identities and device-bound biometric keys, port forwarding (LOCAL/REMOTE/SOCKS), Telnet, Serial/UART via USB OTG, Mosh for unreliable networks, 100+ predefined snippets across 15 categories, live Team Rooms over the local network, and a complete automation system (macros, scripts, expect rules, watchdog, webhooks).

Local shell

Native pseudo-terminal over a bundled Busybox (~150 applets: curl, wget, vi, awk, sed, find, gzip…).

SSH/SFTP

Password / KeyPair / Keyboard-interactive (MFA) auth, auto reconnect, TOFU verified.

Tabs and split

Multiple simultaneous sessions with renamable tabs. Horizontal/vertical split (Pro) + Broadcast (Pro).

Linux tools

File Manager · Processes · Network · Packages · Disk · System Info · Git Panel with native UI parsed from output.

100+ snippets

Built-in library in 15 categories (System, Docker, Git, Nginx, Database, Monitoring…) + custom snippets.

Security

Biometric + PIN + autolock + clipboard timeout. SSH keys encrypted on-device (AES256-GCM + Android KeyStore).

Connections — SSH · SFTP · Telnet · Serial · Mosh

SSH

Password · KeyPair · Keyboard-interactive (MFA). Auto-reconnect on network restore. NONE/SOCKS5/HTTP/SSH_JUMP proxy. Agent forwarding. Startup command on connect.

SFTP

List, mkdir, delete, rename, read/write, download/upload with progress. Single-pane + Dual-pane (local↔remote) + inline remote file editor + transfer queue.

Telnet

Connect on port 23. No crypto auth — only for legacy devices / network consoles.

Serial / UART

USB OTG → /dev/ttyUSB0 with configurable baud (115200 default), databits 5-8, parity NONE/ODD/EVEN/MARK/SPACE, flow control NONE/RTS_CTS/XON_XOFF.

Mosh

Persistent session over UDP for unreliable networks. Predict mode ALWAYS / ADAPTIVE / NEVER / EXPERIMENTAL. Available when remote has mosh-server.

SSH keys and TOFU verification

RSA / ED25519 / ECDSA key generation with configurable bit size, optional passphrase, deployment to hosts via ssh-copy-id-like flow. TOFU (Trust on first use) verification distinguishes new host vs key change (potential MITM). Key exchange also negotiates a post-quantum hybrid algorithm (sntrup761x25519-sha512, Streamlined NTRU Prime + X25519) by default against any modern OpenSSH server — no setting to turn on.

Key manager

List / generate / copy public key / deploy / delete. The private key is stored as an encrypted reference, never as plain text.

Host-key verification

Shows SHA256 fingerprint and distinguishes Trust (new host) from Warning: key changed (probable MITM). Decision is persisted as a known host.

Device-bound biometric keys

EC P-256 key pair generated and held entirely inside Android Keystore — the private key never exists as exportable bytes. Optional requirement of a recent biometric/PIN unlock (30s window) before it will sign. Same idea as Termius' SSH.id, without a public hosting dependency.

Import from ~/.ssh

Paste an SSH config to import Host blocks as hosts (wildcard patterns skipped), or a known_hosts file to import trusted keys (hashed entries are skipped — irrecoverable by design).

Host groups and Identities

Nested groups

Groups and subgroups (not folders) with a color-coded filter chip row; "Connect all" opens one tab per host in the active group. Configuration merging: theme, proxy and default identity are inherited from the nearest ancestor that defines them; environment variables merge down the whole chain.

Identities

Reusable username + credential (password or a Key manager entry) applied as a template to any host or as a group's default. Save one straight from a host's Authentication section, or apply an existing one with a single tap.

Port forwarding

LOCAL (-L)

localhost:8080 → remote:80. Access remote service from local.

REMOTE (-R)

remote:9000 → localhost:3000. Expose local service to remote.

DYNAMIC_SOCKS (-D)

Dynamic SOCKS5 proxy over the SSH session.

Per-rule autoStart toggle: lifts automatically when connecting to the host.

Predefined snippets

Built-in library with 100+ snippets across 15 categories, plus custom folders to organize your own. Resolvable variables ({host}, {user}, {date}, {cwd}) and any custom variable defined on a Terminal profile (${NAME}), unresolved placeholders are left literal instead of silently emptied.

SYSTEM
DOCKER
GIT
NGINX
NODE_PM2
DATABASE
SECURITY
DEPLOY
MONITORING
NETWORKING
PACKAGES
FILES
TEXT_PROCESSING
USER_ADMIN
CUSTOM

Generate with AI (BYOK)

Describe what you need in plain language and get a name, command and description back, ready to save. Only shown when at least one AI provider is connected (Bring Your Own Key) — no hidden cost, no fake option shown when nothing is configured.

Built-in Linux tools

File Manager

ls -la, stat, du → browser with metadata

Process Viewer

ps aux → tree, filter by user/name, kill signal

Network Tools

ip a, ss, ping, traceroute, nslookup → parsed results + bandwidth monitor

Package Manager

apt list, yum list, apk info → paginated list with search, install/remove

Disk Usage

df -h, du -h → top dirs, mount points, inodes

System Info

uname, uptime, /proc/meminfo → cards for hostname, kernel, mem, CPU

Git Panel

git status, branch, log → panel + common git command shortcuts

Automation

Pro

Keyboard macros

Bind raw sequences (e.g. ls\n\x03) to quick buttons in the input bar.

Quick scripts

Multi-line scripts organized by category. Execute sequentially with optional interruption.

Expect rules

Auto-response on pattern match (regex). E.g. pattern [sudo] password for .* → response mypwd\n.

Watchdog rules

Periodic monitoring (every N seconds): runs command, compares expected output, notifies on failure.

Webhooks

Deep link with secret that executes a command. Triggerable from Tasker or any app.

Terminal profiles

Profiles with shell type (Bash/Zsh/Fish/PowerShell), working dir, env vars, startup commands, theme, opacity, bell.

Cloud providers and external integration

Cloud Provider import (Pro)

Imports instances from cloud providers as SSH hosts automatically.

AWSGCPAzureDigital OceanKubernetesDocker

API tokens (Pro)

External terminal control via deep link with a token, or intent broadcast. Permissions: EXEC_COMMAND, READ_HOSTS, MANAGE_HOSTS, FILE_TRANSFER.

Terminal themes

9 built-in themes with 16 ANSI colors each (8 base + 8 bright), cursor, selection, background and customizable welcome ASCII art.

dark
dracula
solarized_dark
monokai
one_dark
catppuccin_mocha
gruvbox_dark
nord
light

Additional premium themes available from the Marketplace. The module brand color is a green palette (#1B5E20 / #66BB6A).

ANSI parser and link detection

Supported ANSI sequences

  • Reset, bold, dim, italic, underline
  • FG/BG standard (30-37 / 40-47)
  • FG/BG bright (90-97 / 100-107)
  • FG/BG 256-color (38;5;N / 48;5;N)
  • FG/BG RGB (38;2;R;G;B / 48;2;R;G;B)
  • OSC 52 → writes to Android clipboard; other OSC stripped (window title…)

Detected link types

  • URL — http(s)://, ftp://, IP:PORT
  • FILE — /absolute/path, ./rel, ~/home
  • ERROR — file.ext:line:col → opens in editor
  • emphasis — error, warning, failed

Split view and Broadcast

Pro

Split view

NONE / HORIZONTAL / VERTICAL. Buffer search isolated per pane. Green border accent marks the active pane. Tap on a pane switches focus.

Broadcast input

Sends the same command to ALL tabs simultaneously. Useful for managing server fleets. BROADCAST badge in top bar.

Sync and Team Rooms

Pro

Sync hosts, keys, snippets and settings with optional E2EE. A Team Room is a live session over the local network: hosting generates a 6-digit pairing code, joining discovers nearby rooms or accepts the code directly. Every device pairs over an ephemeral ECDH handshake + AES-GCM, the same encrypted-transport engine that powers live collaborative editing.

Roles and members

Live member list with role badges (Admin / read-write / read-only), enforced at the sync layer: a read-only peer that tries to write gets its change reverted and is disconnected before it reaches anyone else's device.

Shared hosts and snippets

A room is a live-only concept — it doesn't survive an app restart, same as a live editor collaboration session. No standing cloud copy of the room itself.

Security and logging

Security

  • • Biometric + numeric PIN
  • • Inactivity autolock (configurable minutes)
  • • Clipboard timeout (60s default)
  • • SSH private keys encrypted on-device (AES256-GCM + Android KeyStore)

Logging and recording

  • • Logging: tee of output to plain text file (LOG badge)
  • • Recording: asciicast v2 format compatible with asciinema (REC badge)
  • • Auto-record per group: a group can force logging to start automatically on every host it contains, inherited the same way as theme/proxy
  • • Session logs sheet: lists all logs with date search, star to bookmark (survives the 100-log trim) and a free-text comment per log

Productivity

Smart autocomplete

Per-tab shell history, real recursive path completion against the workspace filesystem (local shell only), and username suggestions from saved Identities after ssh/scp.

Attach files to a session

Clip icon opens the system file picker. On a local shell it's written straight into the workspace; on a remote SSH session it's uploaded to /tmp via SFTP. The resolved path is inserted into the command field, with (1)/(2)… suffixing on a name collision — never overwrites.

Unseen output badge

A tab that isn't currently on screen gets a small badge on its connection dot the moment new output arrives — cleared the instant you switch to it. No heuristic guessing whether it "needs input", just a real signal that something happened.

Volume keys as arrows

Optional setting: while a session is connected, the physical volume buttons send arrow-up/arrow-down to the terminal instead of changing system volume.

The SFTP explorer also supports multi-select (long-press then tap to add more) with batch delete, each item removed independently so one failure never blocks the rest.

Import / Export

Export hosts + keys + snippets + settings as encrypted JSON (passphrase required). Import from .json file, by scanning a QR code or from clipboard.

JSONSSH configknown_hostsCSV

CSV needs a header row (column synonyms accepted: label/name/alias, hostname/host/address/ip, port, username/user, group/folder); a referenced group is matched by name or created if it doesn't exist yet.

Free vs Pro plan

FeaturePlan
Local shell (PTY + Busybox)Free
SSH (1 host free, unlimited Pro)Free
SFTP + transfer queueFree
Predefined snippets + customFree
Port forwarding (LOCAL / REMOTE / SOCKS)Free
SSH keys + TOFUFree
Telnet / Serial / MoshFree
Linux toolsFree
9 built-in themesFree
Biometric + PIN + autolockFree
Host groups + IdentitiesFree
Device-bound biometric keysFree
Post-quantum hybrid key exchangeFree
Import: ~/.ssh/config, known_hosts, CSVFree
Smart autocomplete (paths, identities)Free
Attach files to sessionFree
AI snippet generation (BYOK)Free
Session log bookmarks + commentsFree
SFTP multi-select + batch deleteFree
Marketplace themes (premium)Pro
Split view (horizontal / vertical)Pro
Broadcast input (multi-host)Pro
Multiplexed shellPro
Keyboard macrosPro
Quick scriptsPro
Expect rules (auto-response)Pro
Watchdog rulesPro
WebhooksPro
Terminal profilesPro
Sync + Team RoomsPro
Cloud provider importPro
API tokens (external control)Pro

Module statistics

100+

Predefined snippets

15

Snippet categories

9

Built-in themes

13

Pro features

7

Native tools

6

Connection types