Windows
Desktop client
See downloads for live recordsCLIENT × RESIDENT AGENT
A native client and resident agent keep persistent terminals, monitoring, files, and system tools in the context of the same host.
Desktop client
See downloads for live recordsMobile companion
See downloads for live recordsIndependent desktop client
Planned · Downloads not openIndependent mobile companion
Planned · Downloads not openThe client authenticates and initiates, SSH is the only entry point, and the resident agent exposes structured capabilities through a server-local socket.
Hosts, credentials, trust, and operation entry points stay local.
CLIENTReuse SSH authentication and encryption without a new public port.
PURE SSHListen only on the server-local socket and provide structured capabilities.
AGENTTerminal context and monitoring history persist on the server.
SERVER STATEReliable transfers and system actions use explicit protocols.
STRUCTUREDStandard terminals, port forwarding, and access grants keep a native SSH path.
Fallback boundaryPersistent terminals, monitoring history, files, AI, systems, and apps use the structured protocol.
Primary pathEvery module states its dependency and result. The product docs continue with architecture, boundaries, interfaces, and verification.
Connections, authentication, host keys, and real reachability results.
Connection entryChoose persistent tmux or a standard SSH PTY by task.
Resume contextSnapshots, live subscriptions, history, and top processes.
Structured statusBrowse, search, edit, and transfer with integrity checks.
Same host contextMap server-reachable ports safely to the client machine.
Native SSHInvoke structured tools behind permission, confirmation, and audit gates.
Bring your modelRead system facts and manage processes or firewalls explicitly.
Visible actionsFocus on Docker, common apps, and systemd services.
Capability modulesIssue isolated access keys and revoke them by stable marker.
Least accessTutorials form an executable path from first connection to daily operations instead of a loose article collection.
Complete SSH authentication and host-key trust.
Verify connectionProbe server architecture and select the matching agent and tmux pair.
Paired deploymentDisconnect deliberately, then verify task and screen recovery.
tmuxInspect live detail, historical ranges, and processes.
redbUpload or download and verify integrity results.
Chunk verificationUse your own model and begin with read-only diagnosis.
Permission gateThe two paths stay separate: Creation Cloud never enters the SSH data plane between the client and your server.
The agent uses a local socket, host-key changes require confirmation, and SSH, tmux, or user processes are never ended without authorization.
Cloud is not in this pathHost and AI provider accounts sync only when the user asks. Trusted clients encrypt secrets, and the service stores versioned opaque ciphertext only.
No plaintext sensitive dataThe Creation Cloud control plane is deployed on the production server with accounts, devices, sync, model metadata, encrypted vault envelopes, releases, downloads, and administration. Production client integration ships separately.
Account status, security settings, and password boundaries.
Account password ≠ vault passwordRegister, rename, and revoke trusted devices.
No SSH host recordsHost and AI resource revisions, generations, and manual-sync outcomes.
No persistent conflictsRead administrator-managed global model names, vendors, API formats, and API URLs.
Client-encrypted manual sync onlyShow resource ciphertext versions, generations, and required metadata only.
Server cannot decryptExpose compatible releases, sources, and download history.
Real recordsThe home page keeps only high-value decision questions; the FAQ page carries the full explanation.
No. The SSH data plane remains direct from the client to your server. Cloud only provides account, device, and optional sync controls.
A standard SSH terminal, port forwarding, and access grants remain available. Persistent sessions, monitoring, and structured management depend on the agent.
Host names, addresses, ports, tags, status, connection settings, credentials, and AI provider settings sync only as client-encrypted ciphertext. known_hosts, terminal content, and command history never upload.
No. The account password signs you in. The vault password derives encryption keys only on trusted clients and is never uploaded.
Formal download entries expose platform, architecture, source, file size, and SHA256 for verification before installation.
No. Android is a mobile companion focused on inspection, lightweight actions, and continuity with desktop workflows.