Live Showcase Active: Deployed at https://goxterm.interloop.live:8443 for remote infrastructure management.
🛡️ Pure Go • Zero CGO • Clientless Web Bastion • Build 20260920.248

The Modern Web-Based Terminal
& Remote Infrastructure Gateway

GoXterm bridges the gap between traditional desktop terminal emulators and heavy enterprise bastions. Access SSH, Telnet, Local Shell, SFTP files, and HTML5 Remote Desktop from any browser — protected by hardware-free bot defense, multi-factor authentication, and containerized access control.

0 CGO
Single Pure-Go Binary
1 Port
TLS 8443 Multiplexer
3-Way 2FA
TOTP, Email & SMS OTP
AD / LDAP
Enterprise Identity

Built for Daily Remote Productivity

Experience a full-featured, zero-install desktop environment inside your web browser. Seamlessly manage Linux servers, network switches, and Windows hosts.

🟢 prod-bastion (SSH)
🟡 edge-router-01 (Telnet)
🔵 win-server-rdp (RDP)
⚡ dev-preview:3000
GoXterm v2.0 Enterprise Gateway (Build 20260920.248)
📁 Session Containers
▼ 📁 Production Core 👥 Group
• prod-bastion
• db-cluster-primary
• k8s-worker-pool
▶ 📁 Home Lab Cluster 🔒 Private
▶ 📁 Public Staging 🌐 Public
📂 SFTP Browser
📁 /var/log/nginx
📁 /etc/goxterm
📄 config.yaml
📄 goxterm.db
rliu@prod-bastion:~$ goxterm status --cluster
[GoXterm Gateway Engine v2.0-RELEASE • Build 20260920.248]
# System health & network multiplexing report
Status: ONLINE (Zero-CGO Pure-Go Runtime)
Public WAN IP: 204.15.68.91 (Reflected via multi-source WAN monitor)
Bound Endpoint: https://goxterm.interloop.live:8443
Authentication: LDAP / Active Directory + 2FA Active (TOTP/SMS/Email)
Bot Defense: Cryptographic PoW Gatekeeper ENABLED
Active Remote Sessions: 4 (SSH: 2, Telnet: 1, RDP HTML5: 1)

rliu@prod-bastion:~$ docker ps --format "table {{.Names}}\t{{.Status}}\t{{.Ports}}"
NAMES                STATUS              PORTS
api-gateway-live     Up 14 days (healthy) 0.0.0.0:8080->8080/tcp
postgres-db-core     Up 28 days           127.0.0.1:5432->5432/tcp
redis-cache-tier     Up 28 days           127.0.0.1:6379->6379/tcp

rliu@prod-bastion:~$ _

Built for Demanding Infrastructure

Everything needed for secure daily operations, zero-maintenance bastions, and enterprise access control.

💻

Multi-Protocol Web Terminal

High-performance xterm.js terminal with pure-Go WebSocket bridge. Includes native SSH, pure-Go RFC 854 Telnet for legacy switches/routers, and integrated local shell console.

SSH • Telnet • Local Shell
🖥️

Clientless Remote Desktop

Directly connect to Windows servers and virtual desktops via HTML5 RDP and VNC. Supports auto-resolution fitting, smart-sizing, clipboard syncing, and 1-click native mstsc.exe launch.

HTML5 RDP • VNC Viewer
📁

Session Containers & RBAC

Organize sessions into containers with fine-grained permission scopes: Private (creator only), Group (authorized team groups), and Public. Move sessions with one click.

Container Permissions • User Groups
🏢

LDAP & Active Directory

Pure-Go LDAP/AD client supporting LDAPS (Port 636) and StartTLS. Authenticate corporate domain credentials, extract group memberships, and auto-provision admin or operator roles.

LDAPS • StartTLS • AD Integration
🔐

Triple-Tier 2FA Security

Secure every user with Multi-Factor Authentication: offline TOTP (Google/Microsoft Authenticator), Email OTP via outbound SMTP alerts, or SMS OTP to mobile phones. Includes air-gapped emergency disaster recovery.

TOTP • Email OTP • SMS OTP
🛡️

Bot-Defense Gatekeeper

Client-side cryptographic Proof-of-Work (PoW) verification stops automated brute-force attacks and password sprayers in their tracks without requiring privacy-invasive Google reCAPTCHA.

Proof-of-Work • Anti-Brute-Force
📂

Dual-Pane SFTP Studio

Integrated left sidebar SFTP browser for active sessions. Browse remote file hierarchies, drag-and-drop file uploads, download logs, and edit configuration files.

SFTP Browser • Session Import
🎧

Remote Tech Support

Assist remote customers or team members without third-party tools. Generate 6-digit session PINs, share real-time screens, and chat interactively over an end-to-end WebSocket channel.

Screen Sharing • Live Assistance
🌍

Dynamic WAN IP Tracker

Ideal for road warriors and home network admins. Automatically discovers dynamic public WAN IPs and alerts you by email whenever your residential or lab ISP rotates your address.

Public IP Discovery • Hourly Daemon
🔒

AES-256 Secret & Note Vault

Built-in encrypted password and note vault. Protect root passphrases, API tokens, and TLS private keys with native AES-256-GCM column encryption at rest. Features in-tab mask/reveal, one-click copy, and file export.

AES-256-GCM • Key & Cert Vault • Zero-Cloud
🤖

AI Proxy Gateway & DLP Firewall

Enterprise OpenAI-compatible proxy (/v1) routing prompts to OpenAI, Anthropic, DeepSeek, or air-gapped local Ollama. Sub-millisecond pure-Go regex DLP intercepts and masks/blocks secrets, API keys, credentials, and internal IP leaks.

OpenAI /v1 • Inline DLP Redaction • Local Ollama
📦

Dependency Proxy & CVE Firewall

Multi-ecosystem caching proxy for Python (PyPI), Node.js (NPM), Go Modules, and Debian/Ubuntu (APT). Integrates real-time OSV.dev CVE intelligence to drop High/Critical supply chain vulnerabilities before they reach dev enclaves.

PyPI • NPM • Go • APT • Air-Gapped Cache
📱

Smartphone-Adaptive Mobile Workspace

Full-featured on-call terminal access from any smartphone or tablet. Off-canvas navigation drawer, dynamic visual viewport (100dvh) that auto-resizes around soft keyboards, single-tap session launching, bottom-sheet modals, and a pinned quick-key accessory ribbon.

Responsive Drawer • Dynamic Viewport • Virtual Key Ribbon
🚨

Air-Gapped Break-Glass Protection

Guarantees emergency recovery superuser privileges cannot be exploited remotely. Strictly disabled by default, it requires physical server-side activation with configurable TTL expiry and instant single-use self-destruction upon login.

Single-Use Self-Destruction • Air-Gapped Trigger • Root Defense
📝

In-Browser SFTP Editor & Diff Engine

Live GUI text editor for remote scripts, configs, and logs directly from SSH sessions with syntax highlighting (JSON, YAML, Bash, INI, Python, Markdown). Includes Side-by-Side Diff comparing original remote versions against local unsaved buffers, and remote file-to-file comparison with synchronized scrolling.

In-Browser GUI Editor • Side-by-Side Diff • Synchronized Panes
📜

Top 100 Command Quick Reference

Privacy-conscious terminal command tracker aggregating your top 100 most frequent shell commands. Accessible from anywhere via Ctrl+Shift+H for instant search, 1-click execution (⚡ Run), pasting into the terminal buffer (📋 Paste), and starring mission-critical one-liners.

Usage Analytics • 1-Click Run • Pinned Production One-Liners

Operational Best Practices & Security Guide

Practical rules and workflows to maximize efficiency, protect credentials, and maintain Zero-Trust isolation across all your devices.

Core Principle 1 • Device Posture & Network Access

How you access GoXterm should depend on whether your client machine is a trusted personal workstation or an untrusted public computer.

🏢 Trusted & Corporate Devices
Recommended Flow
Personal laptops, company-managed PCs, and dedicated administrator workstations with active disk encryption and endpoint protection.
  • ✓
    Install GoXterm Extension: Download the Web Bastion extension (.zip) and load unpacked into Chrome/Edge for instant 1-click isolated routing without modifying system settings.
  • ✓
    Selective Split-Tunneling: Only requests targeting authorized internal subnets (e.g. 10.x.x.x, 192.168.x.x) route through GoXterm. All other internet traffic (Google, SaaS, intranet) remains 100% direct with zero latency.
  • ✓
    1-Click Launcher Scripts: Alternatively, use the generated .bat (Windows) or .command (macOS) script to spawn an isolated browser profile configured exclusively for your active session.
  • ✓
    Save Bookmarks in Vault: Keep server bookmarks organized into hierarchical folders. All host credentials, private keys, and passphrases are encrypted at rest with AES-256-GCM.
💡 Pro-Tip: Toggle the extension off via the popup icon when done with lab sessions, or let GoXterm's automatic 2-hour Just-In-Time (JIT) authorization expire.
⚠️ Public & Shared Computers
Strict Security Warning
Hotel business centers, internet cafes, conference loaners, university computer labs, or any unmanaged/shared computer.
  • 🚫
    NEVER Install Browser Extensions or Scripts: Do NOT download the extension or save .bat/.command scripts on public PCs. Unpacked files and proxy settings persist in local folders and can be recovered by subsequent users!
  • 🛡️
    Use Zero-Footprint Web Canvas: Rely exclusively on GoXterm's native in-browser terminal emulator, SFTP side-drawer, or HTML5 Remote Desktop. They render entirely inside ephemeral canvas memory with zero files written to disk.
  • 🔒
    Always Use Incognito / InPrivate: Open GoXterm only inside an Incognito window so cookies, history, and cached pages are destroyed as soon as the window closes.
  • 🚪
    Always Explicitly Click "Logout": Never merely close the browser tab. Clicking Logout immediately destroys your session token and revokes all backend proxy authorizations on the server.
🚨 Caution: If you ever suspect you left an active session on a shared computer, log into GoXterm from your trusted device and click Active Sessions → Revoke Other Sessions to immediately kill all remote access.
Core Principle 2 • Daily Security & Workflow Hygiene

Adopt these best practices during day-to-day operations to keep your infrastructure resilient against unauthorized access.

🔐 Authentication & Vault Hygiene
Zero-Trust
  • 🔑
    Enable Multi-Factor Authentication (TOTP): Pair your account with Google Authenticator, 1Password, or YubiKey. Requiring 2FA blocks 99% of automated credential stuffing attacks.
  • 🛡️
    Never Store Passwords in Plaintext Notes: Use GoXterm's built-in credential vault. Passwords and private keys are encrypted with authenticated AES-256-GCM before touching SQLite.
  • ⚡
    Protect the Vault Passphrase: Set a strong master passphrase for your server vault. Even if raw database backups are compromised, encrypted fields remain indecipherable.
⏱️ Session Lifecycles & Remote Revocation
Access Control
  • 📱
    Audit Active Sessions: Check Settings > Active Sessions periodically to view device types, client IPs, and login timestamps connected to your identity.
  • ❌
    One-Click "Revoke Other Sessions": Instantly terminate stale logins from old phones, tablets, or borrowed laptops with a single click.
  • ⏳
    Configure Idle Lockout: Enforce an automatic 15-30 minute session idle timeout to lock unattended browser tabs on your office desk or home workstation.
🌐 Enclaved Web Bastion Browsing
Split-Tunnel
  • 🚀
    1-Click Enclave Access: Open internal admin consoles (ESXi, Proxmox, iDRAC, routers, Grafana) directly in Chrome tabs with zero system-wide network disruption.
  • ⏱️
    Just-In-Time (JIT) 2-Hour TTL: Target appliance routes are granted dynamically upon session launch and expire automatically after 2 hours.
  • 🛡️
    Automated SSRF Defense: GoXterm's forward proxy automatically drops requests targeting cloud metadata endpoints (169.254.169.254) or loopback interfaces.
📂 SFTP Transfers & Terminal Productivity
Productivity
  • 📁
    Integrated SFTP Drawer: Open the side-drawer on active SSH tabs to drag-and-drop upload/download files, edit configs in-browser, or chmod permissions without external tools.
  • 🗂️
    Containerized Organization: Group servers into shared team containers (e.g. Production/, Staging/) with granular RBAC permissions.
  • 📹
    Audit Logs & Recordings: Review automated session recordings and audit logs for compliance, troubleshooting, and post-incident investigation.
🚨 Air-Gapped Break-Glass Disaster Recovery
Disaster Recovery
  • 🔒
    Disabled by Default: Emergency break-glass superuser access is strictly disabled during normal operation to prevent internet-facing brute-force or credential stuffing.
  • ⚡
    Host-Level Physical Authorization: Activating emergency recovery requires direct server host access with time-limited TTL expiry. Detailed CLI commands and operational runbooks are documented in the Administrator Guide.
  • 🔥
    Single-Use Self-Destruction: The moment emergency recovery successfully authenticates, the trigger is automatically consumed and destroyed, instantly locking the door behind the administrator.
📱 Mobile & On-Call Incident Operations
On-Call Mobility
  • ☰
    Off-Canvas Drawer & 1-Tap Connect: On mobile screens (≤ 768px), tap the hamburger menu to view sessions; single-tapping any host immediately launches full-screen terminal and closes the drawer.
  • ⌨️
    Virtual Accessory Key Ribbon: Dedicated bottom-pinned touch ribbon provides ESC, TAB, ^C (kill process), sticky CTRL toggle, navigation arrows, |, /, -, ~, and soft keyboard focus.
  • 📐
    Visual Viewport Auto-Fit (100dvh): Listens to mobile virtual keyboard popups via window.visualViewport and automatically resizes terminal rows and columns so terminal output is never obscured.
Core Principle 3 • Daily Developer Ergonomics & Productivity

Maximize daily engineering velocity with built-in zero-friction editing, visual diffing, and intelligent command history reference.

📝 In-Browser SFTP File Editor & Diff
Workflow
  • ✏️
    Frictionless In-Place Editing: In any active SSH session, open the SFTP drawer, click ••• → Edit (or double-click) to open scripts, YAML configs, and server logs directly in the browser.
  • 🎨
    Syntax Highlighting: Automatically formats JSON, YAML, Bash scripts, INI/systemd units, Python, and Markdown with real-time gutter line numbering and cursor metrics.
  • 🔍
    Integrated Find & Replace: Press Ctrl+F (or Ctrl+H) to search text with match counters, case-sensitivity toggles (Aa), whole-word boundaries (\b), regex support (.*), and one-click Replace All.
  • ⚖️
    Side-by-Side In-Editor Diff: Click ⚖️ Diff in the editor header to instantly compare original remote content against your unsaved local buffer with synchronized scrolling and addition/deletion line highlights.
  • 💾
    Instant Server Sync: Press Ctrl+S (Cmd+S) to save and stream updates straight to the remote host without local downloading or file staging.
📜 File Compare & Top 100 Command Reference
Ergonomics
  • ⇄
    SFTP File-to-File Comparison: Select ••• → Compare with... on any file in the SFTP browser, then click a second file to immediately inspect a dual-pane visual difference view.
  • ⌨️
    Global Quick Reference (Ctrl+Shift+H): Press Ctrl+Shift+H or click 📜 Commands on the topbar to open the Top 100 command reference modal from any screen.
  • ⚡
    Run, Paste & Pin Actions: Click ⚡ Run to execute immediately with Enter, 📋 Paste to insert into the terminal without Enter for argument editing, or ⭐ Pin to lock vital one-liners to the top.
  • 🔒
    Privacy-Preserving History: Commands are stored purely in client-side localStorage with sensitive token/credential filters, keeping your credentials off the server.

AI Proxy & Dependency Firewall Setup

Quickly configure developer toolchains, AI assistants, and security policies with zero infrastructure friction.

🤖 AI Proxy Gateway & DLP Firewall

GoXterm exposes an OpenAI-compatible /v1/chat/completions endpoint. Point any AI coding tool, IDE extension, or Python/Node SDK to GoXterm to enforce real-time DLP inspection before prompts leave your enclave.

Step 1 • Launch with AI Proxy Support Server Side
# Build with AI proxy tag:
$ ./scripts/build.sh ai # or: go build -tags aiproxy -o goxterm .

# Launch gateway with upstream provider key:
$ OPENAI_API_KEY="sk-..." ./goxterm -mode gateway
Step 2 • Configure IDEs & SDKs (Cursor, Continue, LangChain) Client Tooling
# Set standard OpenAI environment variables:
$ export OPENAI_BASE_URL="https://goxterm.internal:8443/v1"
$ export OPENAI_API_KEY="your-goxterm-jwt-token"

# Or in Cursor / Continue config.json:
{ "apiBase": "https://goxterm.internal:8443/v1", "model": "gpt-4o" }
Step 3 • Enterprise Policy & Security Controls Admin Console • REST API

Configure custom DLP regex rules, redaction actions (mask or block), and compliance exemptions directly via the GoXterm Web Console or authenticated Admin APIs.

🛡️ View DLP Admin API Specification in Admin Guide →

📦 Dependency Proxy & Supply Chain Firewall

Enclave build environments download packages from GoXterm's caching endpoints. Any library exhibiting High or Critical CVE vulnerabilities is rejected in real time with HTTP 403 Forbidden.

Dual-Mode Deployment: Integrated or Standalone Server Side
# Option A: Built into GoXterm gateway:
$ ./scripts/build.sh pkg && ./goxterm -mode gateway

# Option B: Run standalone micro-daemon (25 MB RAM):
$ ./goxterm-pkg -listen :8081 -upstream-npm https://registry.npmjs.org -cve-block=true
Client Toolchain Configuration Pip • NPM • Go • APT
# 🐍 Python (Pip): ~/.pip/pip.conf or CLI
$ pip install --index-url https://goxterm.internal:8443/pypi/simple/ flask

# 🟩 Node.js (NPM): ~/.npmrc or CLI
$ npm config set registry https://goxterm.internal:8443/npm/

# 🔷 Go Modules: environment variable
$ export GOPROXY="https://goxterm.internal:8443/go,direct"

# 🐧 Debian / Ubuntu: /etc/apt/sources.list.d/goxterm.list
$ deb https://goxterm.internal:8443/apt/debian bookworm main
Admin Audit & Policy Control Admin Console • REST API

Inspect blocked vulnerability events, review package caches, and test new ecosystem libraries via the Admin Console or internal security APIs.

🛡️ View Supply Chain Admin API in Admin Guide →

Built for Hostile Public Perimeters

GoXterm was architected from day one to be safely exposed directly to the public internet.

🛡️ Proof-of-Work Shield
Before attempting a password, the client browser must solve a cryptographic SHA-256 challenge. Renders automated botnets and distributed password spraying mathematically ineffective.
🔐 Column-Level Vault Encryption
Passwords, passphrases, private keys, and notes are encrypted at rest using AES-256-GCM authenticated encryption (ENC:v1:...). A decoupled 256-bit vault key ensures sensitive secrets remain unreadable even if raw SQLite databases are inspected.
🔒 Single-Port Multiplexing
All SSH, Telnet, RDP, SFTP, and API traffic multiplex through a single inbound TLS 1.3 port (8443). Eliminates the security risk of opening multiple raw SSH or RDP ports to the world.
🚨 Air-Gapped Break-Glass
Dedicated disaster-recovery emergency account protected by constant-time cryptographic verification. Strictly locked down and disabled by default, requiring physical host-side activation with configurable TTL and automatic single-use self-destruction upon login. Detailed runbooks are restricted to the authenticated Administrator Guide.
🧱 CrowdSec & Fail2ban Ready
Structured security audit logging with immediate IP lockout jail for malicious connection attempts, brute-force probes, and unauthorized privilege escalation.
⚡ Memory-Safe Pure Go
100% pure Go (`CGO_ENABLED=0`). Memory-safe, statically linked binary immune to buffer overflows, OpenSSL memory leaks, or C library vulnerabilities.
🏠
Home & Lab Network
  • Zero-login Standalone desktop mode
  • Direct connection to local routers & Pis
  • Zero cloud reliance • 100% offline
  • Session bookmark import (.mxtsessions / JSON)
🌐
Remote Road Warrior
  • Clientless access from iPad, Mac, or PC
  • Dynamic WAN IP discovery & hourly email alerts
  • Dynamic dev port forwarding previewer
  • Zero VPN setup needed for web apps
🏢
Enterprise Gateway
  • LDAP / Active Directory authentication
  • Multi-user RBAC & user groups
  • Private & group container permissions
  • Embedded zero-maintenance SQLite DB

Transparent Licensing Built for Enterprise Infrastructure

Zero telemetry. Fully offline Ed25519 cryptographic validation. No hidden cloud phone-home.

Standalone Edition
For individual developers, system administrators, and personal hardware lab workstations.
$0 / forever free
  • ✓ Unlimited local shells, SSH & pure-Go Telnet
  • ✓ In-Browser SFTP File Editor & Side-by-Side Diff
  • ✓ Top 100 Command Quick Reference (Ctrl+Shift+H)
  • ✓ Web Serial client (USB / COM dongles)
  • ✓ In-browser HTML5 RDP & VNC desktop viewers
  • ✓ AES-256 encrypted credential & note vault
  • ✓ Zero cloud connection, 100% private & offline
Download Free Binary
Enterprise & AI Security
For regulated industries, defense, enterprise compliance, and mission-critical AI workloads.
Custom / volume licensing
  • ✓ Everything in Gateway Pro
  • ✓ AI Proxy Gateway (/v1) with inline regex DLP Firewall
  • ✓ Dependency Proxy & Supply Chain CVE Firewall (PyPI/NPM/Go/APT)
  • ✓ Air-Gapped Break-Glass emergency disaster recovery
  • ✓ Full audit trail logging & keystroke recording
  • ✓ 100% Air-gapped offline activation (zero telemetry)
  • ✓ Custom seat pools, multi-node clustering & priority SLA
Contact Enterprise Sales
🔑

Customer Licensing & Activation Workflow

GoXterm licenses are signed with high-assurance Ed25519 asymmetric cryptography. The server verifies licenses purely using an embedded public key, guaranteeing zero outbound telemetry and 100% compliance in air-gapped enclaves.

1
Get Server Host ID
Log into your GoXterm Gateway as admin, open Settings → License & Edition, and copy your permanent Server Host ID (e.g. GOX-HOST-A1B2-C3D4).
2
Order on goxterm.com
Visit goxterm.com, choose your plan (Gateway Pro or Enterprise), and provide your Server Host ID and admin contact email.
3
Instant Key Delivery
Upon successful Stripe/invoice payment, the Master License Hub automatically mints your signed token (GOXTERM-LIC-...) on your confirmation screen and delivers it via email.
4
1-Click Activation
Paste your license key into Settings → License & Edition and click 🔑 Unlock / Activate License. Features unlock instantly without requiring internet access.

Download Free & Open Source

Zero-dependency, standalone pre-compiled binaries. Extract and run with zero external prerequisites.

🪟

Windows (x86_64)

Windows 10, 11, Windows Server. Includes batch startup script & headless autostart service.

⬇ Download ZIP (x64)
🍎

macOS (Apple Silicon)

M1, M2, M3, M4 Macs. Native arm64 architecture with zero Rosetta emulation needed.

⬇ Download ZIP (arm64)
🍏

macOS (Intel x86_64)

Intel-based MacBooks, iMacs, and Mac Minis. Includes launchd daemon autostart scripts.

⬇ Download ZIP (x64)
🐧

Linux (x86_64 / amd64)

Ubuntu, Debian, RHEL, CentOS, Rocky Linux, Arch. Includes systemd autostart support.

⬇ Download tar.gz (x64)
🥧

Linux ARM64 / Pi

Raspberry Pi 4/5, AWS Graviton, Oracle ARM, embedded boards running 64-bit Linux.

⬇ Download tar.gz (arm64)
⭐

GitHub Releases

Full source code, changelogs, checksums, and issue tracking hosted on GitHub.

🐙 View GitHub Releases

⚡ Quick 3-Step Deployment:

  1. Extract the archive: Unzip or run tar -xzf goxterm-*.tar.gz in your target directory.
  2. Configure startup (Optional): Edit start_GoXterm.sh (or .bat) to enable Gateway mode, set your initial admin password, or configure SMTP for dynamic IP tracking.
  3. Launch: Run ./start_GoXterm.sh and open https://localhost:8443 in any browser!