Platform

A terminal in the browser, with the audit trail built in

SSH Console opens SSO-authenticated, recordable sessions to any node on your tailnet — no client, no keys, no jump host.

Why a console at all?

🌐

Zero-setup access

On a machine without your keys — a colleague's laptop, a tablet, a kiosk? Log into the console and you're one click from any server you're authorized to reach.

🎥

Recording on by default

Every console session is captured with identity attached. Watch replays from the audit log — no configuration required.

🛡️

Same ACLs, same rules

The console enforces exactly the policy your tailnet already has. No parallel permission system to drift out of sync.

How teams use it

Break-glass access

Pagers go off while you're out. Borrow any browser, authenticate, run the fix — recorded, attributable, revocable.

Vendor support sessions

Let a vendor into exactly one host, for exactly the window you grant, with the session recorded end to end.

On-call from a phone

Small check, big cluster. The console works on mobile browsers when SSH apps don't.

Auditor-friendly

Compliance wants evidence, not stories. Sessions are replayable asciinema files tied to a person.

Console vs. CLI SSH

OpenVLAN SSH (CLI)SSH Console
AuthenticationSSO via tailnet identitySSO via web login
Local client requiredYes (any SSH client)None — browser
Session recordingIn check modeAlways on
Best forEveryday engineering workBreak-glass, mobile, vendor access

Open a console to your tailnet

Included on Premium plans and above.