Giving an agent your servers is easy. Trusting it is harder. Tryssh is a native Mac SSH client — terminal, host manager, SFTP — with a copilot that does the work and asks before it changes anything.
The risk gate is default-deny. Read-only commands auto-run; anything that mutates state renders the exact command and waits for your click. You stay the operator — the agent stays the intern with great ideas.
How the gate works →Hosts, chats, and history live in SQLite under ~/.tryssh. SSH keys and passphrases live in the macOS keychain — never in a database, never on our servers. Delete the folder and it's gone. Agent chat is the one thing that talks to the outside world, and we spell out exactly what it sends.
What leaves your machine →Checks services, tails logs, provisions packages, hunts vulnerabilities — over SSH, on your word.
AgentA command auto-runs only if it is on the read-only allowlist and has no pipes, redirects or chaining. Everything else waits for you.
Approval gateSSH keys and passphrases live in the macOS keychain. Databases hold metadata only.
KeychainBrowse, upload, and edit remote files over the same SSH session. No second app.
FilesAn SSH client holds the keys to your infrastructure. We built like it. No certifications to wave at you — just four decisions you can check.
Hosts, chats, and history in SQLite on your Mac — not on our servers.
Default-deny execution. Mutating commands need your explicit approval.
Keys and passphrases never touch a database, ours or yours.
The agent's exec channel is separate — it can't read or type into your terminal.
Credits meter agent chat only — 1 credit = 1 agent turn. SSH, terminal, and SFTP don't cost credits on any plan.
Monthly only — no annual billing, no credit top-ups, no trial. Unused credits don't roll over. Run out mid-month and agent chat stops with a clear message while terminals, SSH and SFTP keep working; you can upgrade or wait for the reset. The rest of the fine print.
~/.tryssh. SSH keys, passphrases, and passwords live in the macOS keychain — never in a database, never sent to us. Your terminal sessions go straight from your Mac to your server; we are not in that path.
nginx.conf, that file's contents leave the machine. We do not train on it. Delete ~/.tryssh and the local side is gone.
Download the app, add a host, and ask for something. The first 200 credits are on us.