Access · Connector
Reach a server behind NAT or a firewall — no open port.
A Termalin Connector is a one-line agent you install on a private server. It dials out to Termalin and holds the link open, so you reach the box from a browser or an AI agent with no inbound port, no port forwarding, and no long-lived key on the server. Perfect for a Raspberry Pi behind home NAT, a VM behind CGNAT, or a locked-down cloud box.
Outbound only · no inbound port · Pro (or 14-day trial)
01 / how it works
The server dials out. Nothing dials in.
A reverse tunnel or an exposed port means something on your server has to listen — and that’s the thing NAT, CGNAT and firewalls block, and the thing attackers scan for. The Connector flips it around:
- ▸Outbound only. The agent opens a connection to Termalin and keeps it alive. It never listens on a port, so there’s nothing inbound to allow, forward or scan.
- ▸It sees nothing. The agent moves opaque SSH bytes between Termalin and the host’s own
sshdon localhost — it never sees your credentials or plaintext. - ▸It stays up. Installed as a service, it reconnects on its own after a network blip or a reboot.
02 / one line to install
Enroll a server in one command.
Sign in at termal.in/account, click Add Connector to get an enrollment token, and run this on the server you want to reach:
curl -fsSL https://termal.in/tunnel-install.sh | sudo TERMALIN_TOKEN=<token> sh
It downloads a small static binary (Linux x86_64 or arm64), enrolls the host, installs a service and connects. Re-running it later without a token just updates the binary in place. That’s the whole setup — no router changes, no security-group edits.
03 / keyless, per-tenant
No key left on the box.
Enrollment makes the server’s sshd trust Termalin’s SSH certificate authority, and every login then uses a short-lived certificate issued just-in-time — there’s no long-lived private key stored on the server to steal. Certificates are scoped to your account: sshd is told to accept only your tenant’s principal, so a certificate minted for anyone else is refused even though the host trusts the shared CA.
04 / what you reach through it
A terminal, files, databases — and agents.
Once a server is enrolled, everything hosted reaches it keylessly:
- ▸A web terminal. Open a real SSH session from the browser — phone, tablet or a machine that isn’t yours. See the web SSH client.
- ▸Files over SFTP. Browse, edit and transfer files (up to 100 MB) through the same link.
- ▸Private databases. Reach a database that only listens on localhost, through the database client in the cabinet.
- ▸AI agents. The hosted MCP endpoint — and the ChatGPT and claude.ai connectors — run commands on enrolled servers with no key handed out. See SSH for AI agents.
Questions
How do I SSH into a server behind NAT or a firewall?
Install a Termalin Connector on the server with one line — it dials out to Termalin and holds the link open, so nothing has to accept an inbound connection. After that you reach the box from the web terminal or an AI agent, with no port opened and no port forwarding on your router.
Do I have to open a port or forward one on my router?
No. The Connector makes an outbound connection only and never listens on a port. That’s the whole point — it works behind NAT, CGNAT and a strict firewall, on a home Raspberry Pi or a locked-down cloud VM, without touching the router or the security group.
Is there an SSH key sitting on the server?
No long-lived one. On enrollment the Connector makes the server’s sshd trust Termalin’s SSH certificate authority, and each login uses a short-lived certificate issued for your account only — a certificate for another tenant is refused. The Connector moves opaque SSH bytes; it never sees your credentials or plaintext.
What can I do through a Connector?
A full terminal and SFTP file browser in the browser, your private databases, and keyless access for AI agents through the hosted MCP endpoint — the same servers ChatGPT and claude.ai reach. It reconnects on its own after a reboot.
What does it cost, and which systems does it run on?
The Connector is a hosted feature, so it needs a Termalin account on Pro or the 14-day trial. The agent is a small static binary for Linux x86_64 and arm64; the client side (the browser terminal or the agent) runs anywhere.
Any server, wherever it hides.
One line on the box, no inbound port, no key left behind. Reach it from the browser or hand it to an agent.
Pro (or 14-day trial) · Behind-NAT guide · Reach a home server