Hatoba

mcp
Security Audit
Fail
Health Warn
  • License — License: MIT
  • Description — Repository has a description
  • Active repo — Last push 0 days ago
  • Low visibility — Only 5 GitHub stars
Code Fail
  • rm -rf — Recursive force deletion command in apps/desktop/e2e/run-smoke.sh
  • process.env — Environment variable access in apps/desktop/e2e/smoke.mjs
  • network request — Outbound network request in apps/desktop/e2e/smoke.mjs
  • Hardcoded secret — Potential hardcoded credential in apps/desktop/e2e/smoke.mjs
Permissions Pass
  • Permissions — No dangerous permissions requested

No AI report is available for this listing yet.

SUMMARY

Open-source desktop SSH client with an AI assistant and end-to-end encrypted sync through your own Cloudflare account

README.md
Hatoba logo

Hatoba

Open-source desktop SSH client with an AI assistant and end-to-end encrypted sync through your own Cloudflare account

Release
CI
Tauri
Sync
License

Hatoba keeps your hosts, keys, and terminal sessions in one place, syncs them
between your devices, and puts an AI assistant beside each terminal. The sync
backend is a Worker and a D1 database that you deploy to your own Cloudflare
account.

  • No Hatoba server. Sync runs entirely in your Cloudflare account, so
    nobody else holds your data.
  • End-to-end encrypted. Everything is encrypted on your device before it
    leaves, so a leaked Worker, D1 database, or even the whole Cloudflare account
    exposes only ciphertext.
  • Local first. Everything works offline, and sync is optional.
  • Windows first. A custom title bar with Snap Layouts, Mica, Segoe UI and
    Cascadia fonts, and Windows input methods. macOS and Linux follow.

Features

  • Hosts: groups, tags, favorites, fuzzy search, recent connections, online
    status, ~/.ssh/config import, and ProxyJump.
  • Terminal: tabs, 256 colors and truecolor, CJK wide characters and input
    methods, confirmation before multi-line paste, search, and clickable links.
  • Authentication: passwords, Ed25519, ECDSA, and RSA keys with or without
    a passphrase, ask on every connection, ssh-agent, and keyboard-interactive
    (2FA).
  • Security: host key confirmation on first connect, a blocked connection
    when the key changes, a master password with a recovery code, and auto-lock
    on idle, on sleep, or on demand.
  • SFTP: a file panel beside the terminal with drag-and-drop upload,
    download with progress and cancel, rename, delete, and new folder.
  • Key vault: import OpenSSH, PEM, and PuTTY .ppk keys, generate Ed25519
    or RSA 4096 keys, and copy or deploy public keys.
  • Port forwarding: local forwards that can start with the connection.
  • Cloud sync: through your Worker or directly to D1, with incremental
    sync, automatic conflict resolution you can review item by item, and a
    device list with revocation.
  • AI assistant: a panel beside each terminal that reads the screen, runs
    commands, and types into the shell with your approval (or without it, in
    bypass mode), and can search the web and read pages. It uses your own
    OpenAI-compatible or Anthropic API key, supports skills and MCP servers, and
    takes terminal selections, connection errors, long pastes, and text files as
    attachments. Conversations sync with the rest of the vault.

Download

Download for Windows

Download Hatoba_<version>_x64-setup.exe from
Releases and run it. It installs
for the current user without administrator rights, and each release's notes
cover what changed and how to install it. Builds for macOS and Linux will
follow; until then, build from source.

Security

Keys are derived from your master password with Argon2id, and every item is
encrypted with AES-256-GCM before it is stored or synced. The Worker stores
ciphertext and the hashes it needs to sign you in, never your master password
or any plaintext. If you forget the master password and lose the recovery code,
your data cannot be recovered. The
security model describes
the key hierarchy and the threat model.

The AI assistant sends the model provider your messages, their attachments,
and what its tools read. Host addresses, passwords, and keys reach the provider
only when they appear on the screen, in a tool result, or in an attachment you
send.

Build from source

You need Rust stable, Node.js 22 or later, and pnpm. Windows also needs
WebView2, which Windows 11 includes, and Linux needs the Tauri system
dependencies such as libwebkit2gtk-4.1-dev.

pnpm install
pnpm tauri dev

On Windows, pnpm tauri build produces the NSIS installer. The
development guide covers the browser-only frontend,
tests, and the generated TypeScript bindings.

Set up sync

Sync is optional. It runs on a Worker and a D1 database that you deploy once to
your Cloudflare account, and the free plan usually covers personal use. Hatoba
can deploy them for you with a Cloudflare API token; otherwise deploy them with
one click from the browser or with wrangler, then connect the first device with
the Worker URL and a setup token you generate during deployment. Other devices
need only the Worker URL and the master password.

Deploy the sync Worker walks through each way and
connecting Hatoba, and covers upgrades, resets, and backups.

Documentation

License

Hatoba is licensed under MIT.

Reviews (0)

No results found