Everything in sudoterm.
Built for the kind of person who SSHes into 4 VPSes a day and still memorizes tmux shortcuts. We removed the shortcuts.
The terminal
A real web terminal — xterm.js, tmux behind the scenes, mobile-aware UI.
tmux persistence
Every tab is a tmux session. Survives SSH drops, browser closes, and VPS reboots (via systemd).
Multi-tab + multi-window
New tabs spawn fresh sessions. Switch between them without losing scrollback.
Mobile-first input
Floating keyboard bar (Esc, Tab, arrows, Ctrl-C, pipe), system clipboard copy/paste, responsive layout that drops sidebars into bottom sheets.
Live system stats
CPU, RAM, disk, network rates, uptime — pushed over WebSocket every second. Status bar at all times.
Block-based command output
Spec §8.5 — our signature UX. Every command is a unit.
Visual block grouping
A subtle left-edge accent bar marks the boundary of each command + its output. No more scrolling for the start of "that thing I ran."
Per-block actions
Hover any command to copy the entire block, ask AI about it, or rerun it. No context-switching to a sidebar.
Configurable prompt detection
Default regex handles bash, zsh, fish, and starship. Custom PS1? Override the regex in settings.
AI sidebar — all 4 providers
Anthropic, OpenAI, Gemini, Deepseek — pluggable from day one.
Bring your own key
Paste an API key per provider. Stored AES-256-GCM-encrypted at rest. We never see it.
Streaming responses
Server-Sent Events all the way through. Tokens arrive as they come from the provider.
Block-to-prompt
One click on a command block pre-fills the AI composer with "explain this." Context-shift without typing.
Swap providers per conversation
Claude for hard problems, Deepseek for cheap ones. Your preferences persist.
Notes & cheat sheet
Your runbook lives next to your terminal.
Markdown notes
Quick CRUD from the sidebar. Autosave, image uploads, pin a note to a session.
100+ command cheat sheet
Curated commands across tmux, git, ssh, systemd, docker, networking, and more. Click any one to insert into the active terminal.
Searchable
Fuzzy search across all categories. Find that obscure `find` flag in 2 seconds.
Self-hosted infra
Your VPS. Your keys. Your data.
One-command install
`curl -fsSL sudoterm.com/install | bash` provisions tmux, cloudflared, sudoterm itself, registers a free subdomain, and installs a systemd unit. ~60s on a clean VPS.
cloudflared tunnel
No inbound ports, no static IP, no firewall config. Public HTTPS via outbound Cloudflare Tunnel.
sudoterm CLI
`sudoterm start | stop | status | logs | doctor | config | subdomain change <new> | uninstall`. Tiny single-binary, bundled with esbuild.
sudoterm doctor
11 health checks (tmux, cloudflared, port reachability, tunnel state, file perms, etc.). Run any time.
Security model
Defaults that match a single-user, sensitive box.
Argon2id passwords
memCost 19_456, t=2, p=1 — current OWASP defaults.
Session cookies
HttpOnly, Secure, SameSite=Strict, 30-day expiry, refreshed on use. "Log out everywhere" works.
Per-provider API key encryption
AES-256-GCM at rest with a master key under ~/.sudoterm/master.key (chmod 600).
Rate-limited login
5 attempts per 15min per IP. No more.