127.0.0.1:5432→db:5432A native app for managing port forwarding, servers, and files. It lives in your system tray — no browser, cloud, or separate server required.
127.0.0.1:5432→db:5432127.0.0.1:8080→app:80127.0.0.1:3000→grafana:3000// LESS CLICKING, MORE DOING
From a simple tunnel to day-to-day work with a remote host — everything in one native tool.
Keep multiple local → remote mappings in one tunnel. Copy a port address with one click straight from the system tray.
Connect, disconnect, and copy a port without leaving your current task.
A terminal, SFTP browser, resource statistics, and Docker container overview.
Import and export ~/.ssh/config. No proprietary format or lock-in.
Auto-connect, auto-reconnect, and launch at login keep your work uninterrupted.
// CHOOSE YOUR PLATFORM
No account or cloud setup. Download the current stable release.
Windows 10/11 · x64
Apple Silicon and Intel
x64 distributions
The app is distributed under the MIT License. Every installer and archive is published in GitHub Releases.
// RELEASE HISTORY AND ROLLBACK
Need to return to an earlier version? Choose a release and download the right file for your platform directly from GitHub.
// QUESTIONS AND ANSWERS
The essentials before installation and your first connection.
No. The app runs locally, without an account or external configuration server. Passwords for encrypted keys go to the operating system credential store, not to the app's files.
In the standard ~/.ssh/config file. App metadata is stored as comments,
so the configuration remains readable by other SSH clients.
Yes. You can use ProxyJump and ProxyCommand as well as RSA, ECDSA, and Ed25519 keys — including password-protected keys.
Yes. Quit the app, download an installer or archive from the selected release
above, and install it again. Before rolling back, keep a backup of
~/.ssh/config, especially after a major update.
The app checks GitHub Releases on startup and lets you know when a newer release is available. You start the update yourself from settings or the tray menu.
Regular tunnels do not. On macOS 13+, Portless asks once to approve SSH Tunnel
Manager's signed system service. It restores DNS, loopback aliases, and the narrow
PF redirect after reboot for all accounts; the GUI still runs as your normal user.
On Linux, a port below 1024 needs the CAP_NET_BIND_SERVICE capability.
// CONTACT
Describe the issue on GitHub or email the author directly.