seedfire 中文 Get started — it's free
Self-hosted · single binary · Linux · Windows · macOS

Reach every machine.
Expose none.

Seedfire connects your people to the servers, firewalls, cameras and desktops behind NAT — across every site — with zero public ports. Certificate SSH and one-click RDP, a self-service portal for your users, and a control plane that runs on a box you own.

No public ports, no VPN Sign up with Google, GitHub or email Your data stays on your server
Works with what you already run: SSHRDPHTTP / HTTPSany TCP port LinuxWindowsmacOSx86-64 & ARM64
One product, three surfaces

For the people who run it — and everyone who just needs to connect

Operators manage the fleet in the console. Users sign up, install the app and connect from the portal. Devices dial out with one command. Everything meets on your server.

Seedfire admin console — dashboard
For operators

Admin console

Everything in one shell: assets, devices, users, credentials, permissions, audit and upgrades — one page per object, nothing buried.

  • Group tree: grant a folder, everyone in it follows
  • Permissions shown by person, not as raw rules
  • Bulk add from a pasted list or CSV; export any time
  • Push fleet upgrades with preflight and one-click rollback
My Seedfire portal — home
For users

My Seedfire portal

A self-service home at my.seedfire.org: sign up, install, see what you can access — without filing a ticket.

  • Sign in with Google, GitHub or email + password
  • Two-factor auth with recovery codes
  • Private devices: enroll your own machines, visible only to you
  • See every signed-in computer; sign out the ones you don't recognise
Seedfire desktop app
For connecting

Desktop app + CLI

One install gives you both: a tray app for clicking and a bastion-style menu for typing. They update together and never drift apart.

  • Sign in from the browser — no password typed into the app
  • SSH with a fresh certificate, RDP with one click
  • Background tunnels that survive the terminal closing
  • Auto-updates; uninstall is one line, nothing left behind
Why teams pick Seedfire

Built for real infrastructure

Not a demo lab — mixed fleets of Linux boxes, Windows desktops, firewalls, UPSes, iDRACs and cameras across many sites.

🔒

Zero public ports

Devices connect outbound over encrypted tunnels. Nothing on your sites listens on the internet — not even for us.

🎫

Certificate SSH & one-click RDP

A short-lived SSH certificate is issued per connection — no keys to copy, instant revocation. Windows opens straight into Remote Desktop with stored credentials.

🗂️

Groups and permissions by person

Organise thousands of assets as folders (denver/cams, denver/net). Grant a folder to a person or a team and see, per person, exactly what they can reach.

📟

Knows when things break

Every asset target is probed each minute. Debounced down/up alerts reach your webhook or Telegram — before your users notice.

🚀

Fleet upgrades from one seat

Signed, checksum-verified upgrades roll out in batches with a preflight check, offline devices catch up when they return, and rollback is one click.

🧾

Connection records & audit

Who connected to what, when, from where and for how long — metadata only, never content. Every login, grant and upgrade is an audit row.

🔑

Credentials that never leak

Stored passwords are sealed with a master key and delivered per connection — users log in without ever seeing them. Rotate once, everyone follows.

🧹

Clean install, clean exit

Enroll a machine with one line. Delete it in the console and the client uninstalls itself. Nothing to chase down later.

🏠

Yours, entirely

One Go binary, SQLite state, native systemd. Your own domain and logo if you want them. No third-party cloud in the path — the control plane is a box you own.

Permissions you can read

One row per person. Everything they can reach.

Grant a folder, a single asset, or both — permanently or until a date. The Grants page shows it the way you think about it: by person, with the groups they hold as chips and a running total of covered assets. Nothing hides in a rules table.

  • Chips for groups and single assets; hover ✕ revokes one rule
  • Expiring grants highlighted before they lapse
  • "Every asset is reachable by someone" — or a list of the ones that aren't
  • Switch to by-asset or the raw rules when you need to audit
Seedfire console — Grants, by person
How it works

Up and running in minutes

Three steps from nothing to certificate SSH — no network changes, no firewall tickets.

Deploy the server

One binary on any Linux box: tunnel broker, API, CA, admin console and user portal — all in it. Bring a domain; TLS certificates issue themselves.

manager-server serve

Enroll devices

Paste the one-liner from the console on the machine you want to reach. Have fifty? Paste the list, review, confirm.

curl -fsSL https://your-server:8443/install.sh | sudo -E bash

Let people connect

Users create an account at my.seedfire.org, install the app, and reach whatever they're granted — by click, name or menu.

$ seedfire connect web01 web01 $ _
Security

Designed so the safe path is the only path

Most access tools bolt security on. Seedfire's defaults are the security model.

🚪

Nothing inbound

Devices and users both dial out to your server. No listening ports on any site, no exposed RDP, no VPN concentrator to patch.

⏱

Short-lived everything

SSH certificates live minutes and are minted per connection. Enrollment links and initial passwords expire. Leaving means access is gone — not "remember to rotate".

🛡

Accounts that are hard to take over

Two-factor authentication with recovery codes, browser-based sign-in with an 8-character anti-phishing code, and social logins that can only attach to an account after you prove the password.

🔐

Sealed credentials

Stored secrets are encrypted with a master key you hold and are never displayed — not in the console, not in exports, not in logs.

📋

Honest records

Connection records capture who, when, where and how long — and say plainly that content is not recorded. Every administrative action is audited.

📦

Verified software

Agents and apps update only to builds signed by your server and checked by hash. Decommissioned clients remove themselves instead of lingering.

Why not just a VPN?

A VPN gets you a network. Seedfire gets you the machine — with identity, audit and control.

SeedfireTraditional VPN
Public attack surfacenone — everything dials outVPN port exposed to the internet
Access granularityper asset, per person, per groupwhole subnets once you're in
SSH & RDP loginsshort-lived certificates, stored credentials never shownkeys and passwords to manage
Onboarding a userself-service portal, Google/GitHub sign-in, 2FAconfig files and a helpdesk ticket
Audit trailevery connection, grant and upgradeconnection logs at best
Fleet software upgradesbuilt in, batched, verified, reversiblenot its job
Help

Common questions

How do I get access to something?

Create an account at my.seedfire.org, install Seedfire on your computer and sign in. The "What I can access" list shows everything your administrator has granted you. Need more? Ask your administrator — access is granted per person or per group in the console.

Is it free?

Creating an account, installing the app and enrolling your own private devices is free. If you run a fleet or want your own Seedfire server for your organisation, get in touch — we'll set you up.

What is a "private device"?

A machine you enroll yourself — a home NAS, a lab box, your desk PC — that only you can reach. It appears under "Mine" in the app and is invisible to everyone else, including administrators' asset lists.

Which platforms are supported?

The desktop app and CLI run on macOS and Windows; the CLI also runs on Linux. Device agents run on Linux, Windows and macOS, x86-64 and ARM64. Anything with an IP — firewalls, cameras, UPSes, iDRACs — can be reached through an agent on the same network.

I lost my phone. How do I get back in?

Use one of the recovery codes you saved when you turned on two-factor authentication. If you have none left, your administrator can reset 2FA for your account from the console.

Do you see my connections or my data?

No. Traffic flows through your organisation's own Seedfire server, end-to-end encrypted between your computer and the device. Connection records store only metadata — who, when, which device, how long — never content.

Still stuck? Contact us — we reply by email, usually within a day.

Own your access.

Seedfire runs real multi-site fleets today. Start with your own devices, or talk to us about yours.