{"slug": "shellit-open-source-ssh-client-with-self-hosted-e2ee-sync-and-mcp", "title": "Shellit – Open-source SSH client with self-hosted E2EE sync and MCP", "summary": "Developer kobaltgit released Shellit, an open-source cross-platform SSH client, SFTP manager, and server hub built with Flutter and Dart, completing the project from an empty folder to version 0.7.3 in under 24 hours (~19 hours of active work with autonomous AI agents). Shellit ships self-hosted zero-knowledge end-to-end encrypted sync using Argon2id and AES-256-GCM, a Model Context Protocol (MCP) server for Cursor, Claude, and Windsurf, and a built-in Gemini AI snippets assistant, with 133+ passing tests and 0 analyzer errors across 34 completed stages. The client adds live RTT host telemetry, PROD/STAGE/DEV environment badges with destructive-command confirmation, and an Omni-Bar command palette on Windows, macOS, Linux, Android, and iOS.", "body_md": "**A modern, secure, and cross-platform SSH client, SFTP manager, and next-generation server hub built with Flutter & Dart.**\n\n**English** | [Русский](https://github.com/kobaltgit/Shellit/blob/main/README.ru.md)\n\n**Shellit** combines the ergonomics of premier infrastructure management tools with uncompromising security. Engineered as an independent developer and sysadmin power tool, it emphasizes blazing-fast performance, strict architectural isolation, and transparent connection control.\n\nUnlike traditional terminal emulators, Shellit delivers live server telemetry before connecting, built-in protection against accidental destructive commands in production, and an open, extensible plugin ecosystem.\n\nShellit was designed, engineered, and tested from scratch in **under 24 hours** (~19 hours of active vibe-coding with autonomous AI agents): from an empty folder to a production-grade cross-platform application with self-hosted E2EE sync, an MCP AI Gateway, and a Gemini assistant.\n\n## **⏱️ View Development Timeline & Milestone Breakdown**\n\n| Elapsed Time | Milestone | Key Deliverables | \n|---|---|---|\n| **0h 00m** | **Inception** | Concept, monorepo architecture, package isolation, agent contracts | \n| **+1h 40m** | **Core Foundation** | 4 isolated packages ( `core` ,`vault` ,`network` ,`plugins` ), 105 tests | \n| **+2h 00m** | **Terminal UI** | Obsidian Dark theme, live RTT ping dot, 126 unit & widget tests | \n| **+5h 17m** | **v0.1.0** | Matrix 2x2 splits, tabs, two-pane SFTP, Windows Inno Setup installer | \n| **+6h 03m** | **v0.2.0** | Self-hosted E2EE cloud sync on VPS, zero-knowledge Go relay server | \n| **+7h 46m** | **v0.3.0** | Keychain manager, Ed25519/RSA key generator, integrated `ssh-copy-id` | \n| **+9h 11m** | **v0.4.0** | Desktop Plugin SDK, sandboxed WebView2 IPC, Docker Monitor plugin | \n| **+11h 31m** | **v0.5.0** | 100% i18n-ready (Zero Hardcoded Strings) & official Russian language pack | \n| **+14h 35m** | **v0.6.0** | Mobile-first Android client with touch accessory bar & haptic feedback | \n| **+20h 52m** | **v0.7.0** | Model Context Protocol (MCP) server for Cursor, Claude & Windsurf | \n| **+24h 15m** | **v0.7.3** | Built-in Gemini AI snippets assistant, dynamic models, pop-out log windows | \n| **+24h 45m** | **Phase 14** | 1-click ConPTY local terminal with shell discovery (PowerShell, WSL, cmd) | \n\n⏱️ **Total Active Time:** ~19 hours (including a 4-hour night rest).\n\n🛡️ **Quality Metrics:** 34 completed stages, 24 reported & resolved bugs, 133+ passing tests, 0 analyzer errors.\n\n📖 **Read the unfiltered developer log:** [**`docs/CHRONICLE.en.md`**](https://github.com/kobaltgit/Shellit/blob/main/docs/CHRONICLE.en.md).\n\n- \n🔄 **Self-Hosted Zero-Knowledge E2EE Sync:** Seamlessly synchronize hosts, SSH keys, command snippets, and folders across all your devices (Windows, macOS, Linux, Android, iOS) using your own ultra-lightweight VPS relay server. All data is end-to-end encrypted client-side using**Argon2id** and**AES-256-GCM** . The server never sees your passwords, private keys, or host metadata. Supports plain HTTP (ideal for WireGuard, Tailscale, or LANs without domain/SSL hassles) as well as HTTPS (including self-signed certificates).\n- \n🟢 **Live Host Telemetry (Real-time Ping):** Instant RTT latency indicator displayed directly on host cards (`<50ms` green,`<200ms` yellow, offline grey). Inspect server reachability and response times before opening a connection.\n- \n🛡️ **Environment Protection & PROD Guard:** Distinct color badges for every server (`PROD` alert red,`STAGE` cautionary yellow,`DEV` calm blue). On servers marked with the`PROD` tag, a glowing red border activates around the terminal, and potentially destructive commands (`rm -rf` ,`DROP` ,`reboot` , fork bombs) trigger an interactive confirmation modal.\n- \n⚡ **Omni-Bar (`Ctrl+K` / `Cmd+K`):** Universal command palette inspired by Raycast and Spotlight: lightning-fast fuzzy search across hosts, one-key snippet execution, instant theme switching, and split management without taking your hands off the keyboard.\n- \n🪟 **Matrix Tiling Splits & Drag & Drop:** Flexible terminal workspace layouts (horizontal, vertical, 2x2 grid) within tabs. Drag and drop open session tabs into empty split slots, or use**Broadcast Input** to send keystrokes simultaneously to all active panes.\n- \n📂 **Two-Pane SFTP Manager:** Full-featured file manager integrated right into the session tab: local filesystem on the left, remote server on the right, drag-and-drop transfers, context menus, interactive visual chmod permissions editor, and background transfer queue.\n- \n📜 **Asciinema Session Recording & Audit:** Built-in terminal session recording following the**asciinema v2 (`.cast`)** standard and raw text logs (`.log` ). Automatic recording policy for PROD servers, live`● REC` timer badge in the toolbar, and a two-tab audit log inspector.\n- \n⚡ **Command Snippets:** Curated library of frequently used shell commands with tag search, 1-click execution into the active shell, and instant lookup via Omni-Bar (`Ctrl+K` ).\n- \n🗂️ **Multi-View Catalog:** Instantly switch between catalog view modes: responsive tile Grid, dense high-capacity List (for 50+ servers), and hierarchical Folder Tree.\n- \n🔐 **Zero Credentials Leakage & SQLCipher Vault:** Local database encrypted with**AES-256 (SQLCipher)** . Master password secured with**Argon2id** key derivation. Strict memory hygiene (Zeroize) clears plaintext secrets upon session closure, coupled with comprehensive log sanitization.\n- \n🤖 **Model Context Protocol (MCP Server Plugin):** Built-in MCP Gateway (specification 2024-11-05, Server-Sent Events / SSE) to securely connect modern AI assistants (Cursor, Claude Desktop, Windsurf, Antigravity) directly to your servers and terminal sessions. Exposes standardized tools to run commands, fetch terminal buffers, and inspect remote SFTP files under PROD Guard protection with a dedicated AI audit trail.\n- \n🧩 **Open Desktop Plugin SDK:** Extend the application's capabilities with custom sandboxed plugins (`.shellit` ) communicating via an isolated WebView IPC bridge on desktop platforms.\n- \n🌐 **Community Language Packs:** 100% internationalization-ready UI (Zero Hardcoded Strings). English is the native default, with an official Russian language pack readily available:[**Download `russian_lang_pack.shellit`**](https://github.com/kobaltgit/Shellit/blob/main/plugins/russian_lang_pack.shellit) .\n\nShellit supports dynamic installation of custom plugins and language packages (`.shellit`) on the fly without restarting the application.\n\n- 🤖 **[MCP Server Plugin (`plugins/mcp_server.shellit`)](https://github.com/kobaltgit/Shellit/blob/main/plugins/mcp_server.shellit)** — built-in AI Gateway for Cursor, Claude, and Windsurf with PROD Guard security gate*(bundled out of the box)* .\n- 🐳 **[Docker Monitor (`plugins/docker_monitor.shellit`)](https://github.com/kobaltgit/Shellit/blob/main/plugins/docker_monitor.shellit)** — real-time container management and log inspector*(bundled out of the box)* .\n- 🌐 **[Russian Language Pack (`plugins/russian_lang_pack.shellit`)](https://github.com/kobaltgit/Shellit/blob/main/plugins/russian_lang_pack.shellit)** — 100% Russian translation of the user interface (527+ keys).\n\n1. Download the desired `.shellit` package from the[**`plugins/`**](https://github.com/kobaltgit/Shellit/blob/main/plugins) directory.\n2. In the Shellit application, open the **Plugins** sidebar.\n3. Click the **Install .shellit** button in the top-right corner and select the file.\n4. For language packs: navigate to **Settings → Language & Localization** and select your preferred language!\n\nLearn more about the plugin ecosystem: [`plugins/README.md`](https://github.com/kobaltgit/Shellit/blob/main/plugins/README.md).\n\nTranslation authoring guide: [`docs/LOCALIZATION_AND_I18N_GUIDE.md`](https://github.com/kobaltgit/Shellit/blob/main/docs/LOCALIZATION_AND_I18N_GUIDE.md).\n\nThe project is structured as a modular monorepo following contract-first design and strict package isolation:\n\n```\nShellit/\n├── apps/\n│   └── shellit/                    # Main Flutter application (DI, Riverpod, Routing, Run)\n├── packages/\n│   ├── core_foundation/            # Domain entities, Result/Failure, interfaces/contracts\n│   ├── storage_vault/              # Encrypted storage (Drift + SQLCipher, Argon2id, SyncCrypto)\n│   ├── ssh_network_core/           # Network core (dartssh2, PTY streams, SFTP client, tunnels, recorder)\n│   ├── terminal_ui/                # Terminal emulator (xterm.dart, tabs, matrix splits, mobile panel)\n│   └── desktop_plugin_sdk/         # Plugin manifest specs, validator, and IPC sandbox\n├── plugins/                        # Bundled plugins and language packs (.shellit)\n├── servers/\n│   └── sync_server/                # Lightweight sync relay server (Dart + SQLite, Docker, <20MB RAM)\n└── docs/                           # Central coordination and documentation hub\n```\n\n**Isolation Rule:** Feature packages depend *strictly* on abstractions from `packages/core_foundation/`. Direct cross-dependencies between feature packages are prohibited.\n\n- **Flutter SDK** :`>= 3.12.0`\n- **Dart SDK** :`>= 3.12.0`\n- Supported desktop environments: Windows 10/11, macOS (12+), Linux (Ubuntu 22.04+ / Debian / Fedora)\n\n```\n# Clone the repository\ngit clone https://github.com/kobaltgit/Shellit.git\ncd Shellit\n\n# Fetch dependencies for the main app\ncd apps/shellit\nflutter pub get\n# Windows\nflutter run -d windows\n\n# macOS\nflutter run -d macos\n\n# Linux\nflutter run -d linux\n# Analyze code across all packages\nflutter analyze\n\n# Run unit and widget tests\nflutter test\n```\n\nShellit frees you from expensive proprietary clouds. You can deploy your own lightweight synchronization relay server on any home server or VPS in under 60 seconds.\n\n- **Client-Side Encryption:** All hosts, private keys, snippets, and folders are encrypted using**AES-256-GCM** . Encryption keys are derived client-side from your Passphrase via**Argon2id** .\n- **Blind Server:** The server only receives blind authentication tokens (`authHash` ) and encrypted binary payloads. The server owner cannot read hostnames or any metadata.\n- **Tombstones & LWW:** Deletions are tracked via tombstones, and conflicts are resolved via Last-Write-Wins (Pull-Then-Push).\n- **Transport Freedom:** Works over plain`http://` (inside WireGuard, Tailscale, or private LANs without domain or certificate overhead) as well as`https://` (including self-signed certificates).\n\n1. Copy the server directory or create `docker-compose.yml` on your VPS:\n\n```\nversion: \"3.8\"\n\nservices:\n  shellit-sync:\n    build: ./servers/sync_server\n    container_name: shellit-sync\n    restart: unless-stopped\n    ports:\n      - \"8080:8080\"\n    volumes:\n      - ./data:/data\n    environment:\n      - PORT=8080\n      - HOST=0.0.0.0\n      - DATA_PATH=/data/shellit-sync.db\n      - REGISTRATION_TOKEN=super-secret-invite-token # Optional: protect against unauthorized registrations\n```\n\n1. Start the service:\n\n```\ndocker compose up -d\n```\n\n1. Open **Settings → Sync & Cloud** .\n2. Configure:\n  - **Server URL:**`http://<your-vps-ip>:8080` or`https://sync.your-domain.com` .\n  - **Vault ID:** Storage vault identifier (e.g.`my-servers` ).\n  - **Sync Passphrase:** Encryption passphrase (remember it for your other devices).\n  - **Registration Token:** Registration token (if configured in`REGISTRATION_TOKEN` on the server).\n  - When using self-signed certificates, enable **\"Allow self-signed SSL / insecure HTTP\"** .\n3. Click **Test Connection** , then**Sync Now** .\n4. Repeat on your phone or secondary computer — and your infrastructure is synchronized!\n\nComprehensive server documentation: [`servers/sync_server/README.md`](https://github.com/kobaltgit/Shellit/blob/main/servers/sync_server/README.md).\n\nAll development processes, technical specifications, and tasks are cataloged in the [`docs/`](https://github.com/kobaltgit/Shellit/blob/main/docs) directory:\n\n- [`docs/AGENTS_MASTER_GUIDE.md`](https://github.com/kobaltgit/Shellit/blob/main/docs/AGENTS_MASTER_GUIDE.md) — Master architectural guide and engineering standards.\n- [`docs/ROADMAP.md`](https://github.com/kobaltgit/Shellit/blob/main/docs/ROADMAP.md) — Milestone roadmap and progress timeline.\n- [`docs/CHECKLIST.md`](https://github.com/kobaltgit/Shellit/blob/main/docs/CHECKLIST.md) — Interactive task tracker across packages.\n- [`docs/BUGS_AND_ISSUES.md`](https://github.com/kobaltgit/Shellit/blob/main/docs/BUGS_AND_ISSUES.md) — Realtime bug registry and incident log.\n- [`docs/CHRONICLE.en.md`](https://github.com/kobaltgit/Shellit/blob/main/docs/CHRONICLE.en.md) — Project development devlog and chronicle.\n- [`GEMINI.md`](https://github.com/kobaltgit/Shellit/blob/main/GEMINI.md) — System operating guide for AI agents.\n\n- **Zero Hardcoded Secrets** : Never store credentials or private keys in the codebase.\n- **Master Vault** : Passwords and private keys are encrypted locally with SQLCipher. Without the master password, decrypting the database is mathematically impossible.\n- **Memory Hygiene** : Sensitive decrypted credentials are wiped from memory (`zeroize` ) immediately after use.\n\nThis project is licensed under the copyleft **[GNU General Public License v3.0 (GPLv3)](https://github.com/kobaltgit/Shellit/blob/main/LICENSE)**.\n\n- ✅ **Freedom of Use:** You may freely run and use Shellit for personal and commercial server administration.\n- ✅ **Freedom to Study & Modify:** Full source code is open, inspectable, and extensible.\n- ⚠️ **Strict Copyleft Requirements:**  - **Reciprocal Freedom:** Any forks, modifications, or derivative products must also be distributed under GPLv3 with full source code made available.\n  - **No Closed-Source Redistribution:** Proprietary commercial wrapping of core components without source disclosure is strictly prohibited.\n  - **Attribution:** Original copyright notices and license texts must remain intact.", "url": "https://wpnews.pro/news/shellit-open-source-ssh-client-with-self-hosted-e2ee-sync-and-mcp", "canonical_source": "https://github.com/kobaltgit/Shellit", "published_at": "2026-09-19 12:10:58+00:00", "updated_at": "2026-09-19 12:25:07.939405+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "agent-protocols", "developer-tools", "generative-ai"], "entities": ["Shellit", "kobaltgit", "Flutter", "Dart", "Model Context Protocol", "Cursor", "Claude", "Gemini"], "alternates": {"html": "https://wpnews.pro/news/shellit-open-source-ssh-client-with-self-hosted-e2ee-sync-and-mcp", "markdown": "https://wpnews.pro/news/shellit-open-source-ssh-client-with-self-hosted-e2ee-sync-and-mcp.md", "text": "https://wpnews.pro/news/shellit-open-source-ssh-client-with-self-hosted-e2ee-sync-and-mcp.txt", "jsonld": "https://wpnews.pro/news/shellit-open-source-ssh-client-with-self-hosted-e2ee-sync-and-mcp.jsonld"}}