burrow
client.

A local-first SSH client for macOS and Linux.

No account, no telemetry, no cloud unless you run it yourself.

Download
View on GitHub

macOS (Apple Silicon) · Linux (RPM, AppImage) · v1.0.0

The Burrow Client window: tabs for the vault and two open sessions, a sidebar with Hosts, Keychain, Snippets, Known hosts and Settings, and the Hosts view with hosts grouped under Home Lab, Production and Staging.

Burrow keeps your hosts, keys and passwords on your own machine. Secrets sit in an encrypted vault that only opens with your master password. If you use more than one computer, you can host a small sync server yourself, and it only ever stores data it can’t read.

Everything I kept missing, in one window

  • Tabs and split panes

    Split side by side or stacked, and open local shell tabs right next to your sessions.

  • Host profiles

    Groups, search and notes, plus an optional dot that tells you whether a host is reachable.

  • Encrypted vault

    Passwords, keys and passphrases are encrypted with scrypt and AES-256-GCM.

  • Key management

    Generate Ed25519 or RSA 4096 keys, or import the ones you already have.

  • Known hosts

    Confirm the fingerprint on first connect, and get a warning when a server key changes.

  • SFTP browser

    Drag and drop to upload, then download, rename, delete or make new folders.

  • Snippets

    Save the commands you keep typing and send them to any terminal, globally or per host.

  • Auto-lock

    The vault locks after idle time, when your machine goes to sleep and when the screen locks.

  • Screenshot protection

    On macOS the window is hidden from screenshots and screen recordings.

  • Self-hosted sync

    Optional and end-to-end encrypted. You run the server, and it can’t read your data.

Privacy and security

Privacy

  • Nothing leaves your machine unless you set up sync.
  • There is no account to make, and nothing phones home.
0accounts
0analytics
0telemetry

Security

  • Outdated SHA-1 algorithms are turned off.
  • The app window is sandboxed with a strict Content Security Policy.

To be honest about it: Burrow has not been independently audited, and the builds are not code signed.

Read the full security overview

Download and install

Pick your system under the button and the newest release comes straight from GitHub. Then follow the steps for it.

Download

Prefer to build it yourself?

macOS

  1. 01Open the .dmg and drag the app into Applications.
  2. 02 On first start macOS says it can’t verify the app, because it isn’t signed. Click Done.
  3. 03 Go to System Settings → Privacy & Security and click Open Anyway. You only need to do this once.

Linux

The Download button gets you the AppImage. Make it executable, then run it:

chmod +x burrowclient.appimage
./burrowclient.appimage

Sync server

Sync is optional. The server is a single Node.js file with no dependencies. It runs in Docker behind your existing reverse proxy and only stores encrypted data.

Set up your own sync server

Open source

Burrow is MIT licensed. Bug reports and pull requests are welcome on GitHub.

Found a security issue? Please report it privately through my contact form, not as a public issue.

Burrow is free.

If it saves you some hassle, you can buy me a coffee.

Support me on Ko-fi

Made with love by zukotuutori