Termetra logo
TERMETRA
[ official docs ]

READ. SHIP.
OWN YOUR STACK.

Quickstart to air-gapped licensing in five chapters. Search, copy-paste, deploy — everything runs offline except your own Docker.

Chapter 1

Quickstart & Session Management

Two unified modes: Profiles Manager (configure servers) and Active Terminal (operate). No account needed to start.

Creating your first SSH profile

  1. Launch Termetra or press Ctrl+N for a New Profile card.
  2. Enter Hostname / IPv4 / IPv6 and SSH port (default 22).
  3. Pick auth: Password, SSH Key (Ed25519 / RSA), or SSH Agent.
  4. Hit Connect to Server or Ctrl+Enter.

Multi-hop jump hosts

Expand Jump Host Settings in the profile editor. Termetra chains via SSH ProxyJump — intermediate bastions never hold your private keys. SOCKS5 dynamic tunnels and per-chain bandwidth meters included.

Chapter 2

Self-Hosted Sync Server

Ultra-lightweight zero-knowledge daemon as a Docker container. Stores only client-encrypted SQLCipher blobs — no plaintext passwords, keys, or hostnames visible server-side.

Docker Compose deployment

version: '3.8'
services:
  termetra-sync:
    image: registry.genthux.id/termetra-sync-server:latest
    container_name: termetra-sync
    restart: unless-stopped
    ports: - "8443:8443"
    environment:
      - PORT=8443
      - SYNC_STORAGE_DIR=/data/envelopes
      - LOG_LEVEL=info
      - ALLOW_REGISTRATION=true
    volumes:
      - /opt/termetra-data:/data/envelopes

CPace PAKE cryptographic pairing

Linking home PC + work laptop? Termetra uses CPace (Balanced Password-Authenticated Key Exchange): a short pairing code bootstraps an encrypted mutual handshake without ever transmitting the master password. Run termetra pair --code 482-910 on the new device.

Chapter 3

Migration & Import Guide

Switch from PuTTY, MobaXterm, or plain OpenSSH in under 30 seconds. Tags, jump inheritance, and key associations survive the trip.

Importing from PuTTY (.reg)

  1. Export sessions: reg export HKCU\Software\SimonTatham\PuTTY\Sessions putty_backup.reg
  2. In Termetra click Import… at the bottom of the Profiles list.
  3. Select putty_backup.reg — session names, ports, key paths, and usernames map to native profiles automatically.

Importing ~/.ssh/config

Termetra parses standard OpenSSH blocks: Host, HostName, User, Port, IdentityFile, ProxyJump — including wildcards and includes.

Chapter 4

Cryptographic Model & Local Storage

SQLCipher v3 with 256-bit AES-GCM. Every DB page individually encrypted with unique HMAC-SHA256 nonces; key material zeroized in RAM after each handshake.

Key derivation: Argon2id (Memory 64MB, Iterations 4, Parallelism 2) — GPU-brute-force resistant. Sync envelopes are encrypted client-side before they ever leave your machine.
Chapter 5

Air-Gapped License Activation

Unlock pay-once add-ons (e.g. Vault Screen Lock, Team Sync) with zero internet on the target machine:

  1. Download the .lic file from your Lemon Squeezy receipt on an online device.
  2. Sneaker-net it over via USB or internal share.
  3. Open Settings > Add-Ons → Load .lic.
  4. Verified fully offline via Ed25519 signatures. No phone-home, ever.

Verifying SHA256 checksums

# Windows PowerShell
Get-FileHash .\Termetra-Setup-v0.9.5.exe -Algorithm SHA256

# Linux
sha256sum termetra_0.9.5_amd64.deb

Compare against the published hashes on ./download.html before executing.

free forever — no card, no account to start

GET TERMETRA.
KEEP YOUR KEYS.

Windows 10/11 • Debian • Fedora • Arch • Flatpak — offline license, air-gap ready