WeShell connects you to your servers directly from your browser. No SSH client, no VPN — with MFA and full audit trail.
WeShell is designed to be easy to use and solid in production.
A full-resolution xterm.js terminal with color support, automatic resize, and native copy-paste. Just like your local terminal.
Your SSH passwords and private keys are entered at connection time and transit encrypted. They are never written to disk or kept in memory between sessions.
Enable TOTP two-factor authentication on your account in 30 seconds. Compatible with Google Authenticator, Authy, and any standard TOTP app.
Save your servers (host, port, user, auth type) to connect in two clicks. Each user manages their own list, completely private.
Every connection is logged: user, target server, start and end time, duration, source IP. Admins get a complete global view.
Each user has their own isolated space: their server list, sessions, and history. Nothing is shared between users.
Open multiple SSH connections simultaneously in separate tabs within the same window. Switch between servers instantly, each with its own live terminal.
Share a read-only view of your terminal with a single link. Teammates watch your session live in their browser — no account needed, no way to type.
No complex setup, no client to install.
Free sign-up in 30 seconds. Enable MFA to secure your access with Google Authenticator.
Enter the address, port, and authentication type of your SSH servers. Your passwords are never saved.
Click "Connect", enter your SSH credentials on the fly. The terminal opens in your browser, wherever you are.
Security is not an option at WeShell — it's the core principle.
SSH passwords and private keys are transmitted once over an encrypted WebSocket (WSS), used to open the session, then destroyed. They never touch disk.
TOTP MFA adds a second authentication layer to your WeShell account, independent of your password.
All communications between your browser and WeShell travel over TLS (HTTPS/WSS). No data in clear text on the network.
A configurable inactivity timeout automatically closes open SSH sessions, limiting exposure if you forget.
Application access is based on signed JWT tokens with configurable expiry. No server-side session.
Every session is audited: who, which server, from which IP, for how long. Admins maintain total visibility.
Free, no credit card, no commitment.