Skip to content
Scoplen

In development

SSH client and bastion, in one.You choose how each host is reached.

Fully self-hosted. Direct hosts never wait on a server; hosts that need control go through the bastion.

Nothing to download yet. The pages describe the intended product.

From the host list, prod-api-01 is chosen. Scoplen connects directly to 10.0.1.24, checks that the host key matches the one it remembers, signs in as deploy with a key held in the Secure Enclave, and opens a terminal and file access on one connection. In the terminal, the api service is active and the disk is 39 percent full.

Start small

Three fields, then you are connected.

Everything else appears only when you reuse it.

Adding a host asks for an address, a user, and a key. Behind it, Scoplen creates a login, a key, and a direct route, which are not shown. When the same key is used for a second host, the key appears under Keys, where it can be managed on its own.

Routes

Gateways only where you choose.

Each host is reached its own way. Only a route that sees the session can record it.

A host is reached directly, through jump hosts, or through an edge and a gateway, chosen per host. Only the gateway route passes through something that sees the session, so only it can record. Both routes record who was allowed and why. Only the gateway route can record every connection authoritatively, keep a full terminal recording, and end a session from the server.

Bastion

A bastion for the hosts that need one.

Assigned host by host. The password never reaches the person, every session is recorded, and any session can be ended.

Ivy connects to prod-db-01, a host assigned to the bastion. Her single-use ticket is checked, the edge relays the connection without reading it, and the gateway checks the access rule again. The gateway signs in to the host with a credential from the organization's store, which never reaches Ivy, and records the session. In the console, Mia sees the live session and ends it.

Teams

Access that expires on its own.

Certificates name the host and user they allow, and last minutes, not years.

An access rule lets the ops group connect to production hosts as deploy for up to 30 minutes. Ivy receives a certificate that names prod-db-01 and the user deploy and expires in 30 minutes, and connects to the host directly. When Ivy leaves the ops group, her next request for a certificate is refused, and the certificate she holds runs out on its own.

Reachable

When a server fails, only what depends on it waits.

Direct and jump connections keep working. Hosts you put behind the bastion wait for the gateway, and sync pauses.

The Scoplen server and its gateway become unreachable. Hosts you put behind the bastion wait until the gateway returns, and sync between devices pauses. Direct connections, jump hosts, files and tunnels keep working, because they never went through the server.

Sync

Encrypted before it leaves.

Your server keeps your hosts in order without being able to read them.

A host named prod-api-01 is added on a laptop. Before it leaves the laptop it is encrypted and signed by that device, so the server stores only ciphertext it cannot read. On your desktop it is decrypted again and shows the same name, address, and user.

Self-hosting

One command, one port.

Start alone on SQLite. Grow into a team or an organization without reinstalling.

Running spl-server with a host name generates a deployment key, obtains a TLS certificate automatically, listens on port 443 for everything, and prints a one-time setup link. This is the Personal profile, with one process, SQLite, and local files. Enabling organizations makes it a Team deployment; moving data with splctl migrate-storage makes it an Organization deployment with PostgreSQL, object storage, and a key management service.

OpenSSH

Plain ssh keeps working.

Your config is read, never rewritten. What cannot be imported is reported, not dropped.

Scoplen reads your ~/.ssh/config without changing it. Two hosts are imported, one with a jump route. A Match block it cannot represent is reported rather than silently dropped. Scoplen writes one file of its own, which your config includes, so plain ssh prod-api-01 keeps working in any terminal.

Self-hosted only

Every part runs on servers you operate.

No paid tier

Every feature, in every deployment.

Leave any time

Export to documented JSON or plain OpenSSH files.