SinaXhpm/Submarine

▲ 40 stars today★ 364⑂ 27

Modern SSH & SFTP client — terminal, SFTP, port forwarding, folder mirror, encrypted sync. Windows · macOS · Linux · Android.

About SinaXhpm/Submarine

SinaXhpm/Submarine is an open-source project on GitHub, mainly written in TypeScript. Modern SSH & SFTP client — terminal, SFTP, port forwarding, folder mirror, encrypted sync. Windows · macOS · Linux · Android. It currently holds 364 stars and 27 forks with 20 open issues, and was last pushed on 2026-08-22 (repository created 2026-05-27).

Project Overview

Git Homed tracks it on the Today's Trending board, currently at rank #54 with 40 new stars today.

GitHub Repository Details

Repository SinaXhpm/Submarine · default branch main · size 44818 KB · watchers 5 · source: GitHub REST API and repository README

README

https://github.com/SinaXhpm/Submarine/blob/HEAD/Submarine logo

Submarine — Modern SSH & SFTP Client

A fast, secure SSH and SFTP client for Windows, macOS, Linux — and now Android.

Manage servers, edit remote files, forward ports, and sync folders from one native window. Built with Rust and Tauri.

https://github.com/SinaXhpm/Submarine/blob/HEAD/release https://github.com/SinaXhpm/Submarine/blob/HEAD/downloads https://github.com/SinaXhpm/Submarine/blob/HEAD/ci https://github.com/SinaXhpm/Submarine/blob/HEAD/platforms https://github.com/SinaXhpm/Submarine/blob/HEAD/license

---

https://github.com/SinaXhpm/Submarine/blob/HEAD/Submarine main window — terminal session with dual-pane SFTP browser open on the right
TL;DR — Submarine is a fast, free, open-source SSH and SFTP client for Windows, macOS, Linux, and Android. It replaces the typical PuTTY + WinSCP + tunnel-manager stack with one tabbed window per server: terminal, SFTP, port forwarding (SOCKS / HTTP / local / remote), folder mirror, and end-to-end encrypted profile sync. Built with Rust + Tauri. MIT licensed.

At a glance

Screenshots

https://github.com/SinaXhpm/Submarine/blob/HEAD/Port forwarding panel: local, remote, and dynamic SOCKS tunnels with live connection counters
Port forwarding — local / remote / dynamic SOCKS tunnels, live active-connection counters, autostart with the app
https://github.com/SinaXhpm/Submarine/blob/HEAD/Folder Mirror setup with local/remote paths, excludes, and conflict resolution
Folder mirror — two-way sync, excludes, per-mirror conflict resolution, soft delete to .submarine-trash/
https://github.com/SinaXhpm/Submarine/blob/HEAD/Per-server command library with Run / Paste / Edit on each snippet, plus a Notes tab
Quick commands & notes — per-server snippet library and a Notes tab for runbook / contacts
https://github.com/SinaXhpm/Submarine/blob/HEAD/Logins panel: saved passwords and SSH keys with Add Password / Add Key / Generate Key
Logins — saved passwords and SSH keys, with built-in key generation; all credentials encrypted in the vault
https://github.com/SinaXhpm/Submarine/blob/HEAD/Live monitoring grid: per-server CPU, memory, network-in and network-out sparklines
Monitoring — per-node SSH polling for CPU, RAM, and live network in/out with sparklines
https://github.com/SinaXhpm/Submarine/blob/HEAD/Server details form: folder, tag colour, host/port, login method, proxy, tunnels, mirrors, autostart
Server details — folder, tag colour, host, auth, proxy, tunnels, mirrors, and autostart in one form

Looking for an alternative to…

If you're searching for one of these, Submarine is a direct fit:

Why Submarine

Most SSH clients feel like they were built a decade ago and never updated. Submarine is a clean, modern alternative for developers and sysadmins who connect to remote servers every day.

Key Features

Terminal

SFTP File Browser

Folder Mirror

Pick a local folder, pick a remote folder, and Submarine keeps them in sync.

Server Info Panel

A read-only inspection pane for the active session — no terminal commands required.

Docker Manager

Manage Docker on any session host without typing a single docker command.

Port Forwarding

End-to-End Encrypted Profile Sync

Productivity

Install

Pick a binary from the latest release and you're done — no extra dependencies.

| OS | File | |---|---| | Windows 10 / 11 | .exe installer or .msi | | macOS (Apple Silicon, or Intel via Rosetta) | .dmg or .app.zip | | Debian / Ubuntu / Mint | .deb — sudo apt install ./submarine_*.deb | | Fedora / RHEL / openSUSE | .rpm — sudo dnf install ./submarine-*.rpm | | Arch / Manjaro / EndeavourOS | .pkg.tar.zst — sudo pacman -U submarine-*.pkg.tar.zst | | Any Linux | .AppImage — chmod +x and double-click | | Android 8.0+ | .apk — sideload, no Play Store required |

Builds are currently unsigned. Windows SmartScreen will prompt — click "More info → Run anyway". On macOS you may need xattr -d com.apple.quarantine /Applications/Submarine.app. Android sideloading needs "Install unknown apps" enabled for the installer source.

Android

Submarine on Android is a true native build of the same Rust core — same SSH stack, same encrypted vault, same profile sync. Reach a server from your phone with the same credentials you saved on your desktop.

Tested on Android 8.0+ (API 26+). Phones, tablets, and Android-on-ChromeOS.

Security

Your data is encrypted on your machine before anything leaves it. Submarine and the sync server never see your passwords, private keys, or profile content.

How it works:

1. Your master password becomes a vault key — on your device. When you unlock, your password is run through Argon2id to derive a key. The password is wiped from memory the moment derivation finishes. It never goes anywhere. 2. Profiles are sealed with AES-256-GCM — on your device. Every saved server (credentials, keys, tunnels, notes, mirrors) is compressed and encrypted with that key. What hits disk is opaque ciphertext. 3. Sync uploads that same ciphertext — byte for byte. When you turn cloud sync on, the bytes uploaded are exactly the encrypted blob from your disk. The server stores ciphertext plus a random nonce. Nothing else.

Why the sync server can't read your profiles:

Other defences:

FAQ

Is Submarine free?

Yes. MIT-licensed. Use it personally, use it at work, fork it, redistribute it.

Does it work offline?

Yes. Cloud sync is opt-in. All profiles, mirrors, and tunnels live locally and are encrypted at rest.

How is it different from PuTTY, WinSCP, or MobaXterm?

PuTTY and WinSCP are two separate apps you alt-tab between. MobaXterm bundles them but feels dated and is Windows-only. Submarine puts terminal, SFTP, tunnels, and folder mirror in one modern tabbed window per server — and runs natively on Windows, macOS, and Linux.

Does it support keys with passphrases?

Yes. File-based keys and pasted PEM/OpenSSH keys, with or without passphrase.

Can I sync profiles between Windows and macOS?

Yes. The encrypted vault is platform-portable. Enable sync on one machine, unlock on another with the same master password.

Why Rust and Tauri instead of Electron?

Smaller installer (around 10 MB vs ~100 MB for an Electron equivalent), lower RAM, faster startup, native window controls, and no Chromium per app.

Where are my profiles stored?

In a single encrypted file under your OS app-data directory. Nothing in plaintext. Nothing in a global Keychain or registry hive.

Does Submarine collect telemetry or analytics?

No. There's no analytics SDK, no crash reporter that sends data home, no "phone home" call on launch. The only outbound network call beyond your SSH targets is the optional cloud-sync endpoint at api.sinaxhpm.com, and that endpoint only ever receives opaque ciphertext.

Can I use Submarine on my Android phone with the same servers as my desktop?

Yes. Install the APK, unlock with the same master password you use on desktop, and the encrypted vault syncs. Every server, key, and saved tunnel appears on the phone. Folder mirror is desktop-only for now; everything else (terminal, SFTP, port forwarding) works on Android.

Is Submarine on the Play Store?

No. Distribution is via sideloadable APK from the releases page. This keeps the same untouched binary running on every platform with no store-mandated changes.

Build from Source

Requirements: Node 20+, Rust stable, Tauri prerequisites for your OS. Windows additionally needs Strawberry Perl for the vendored OpenSSL build (winget install StrawberryPerl.StrawberryPerl).

git clone https://github.com/sinaxhpm/submarine
cd submarine
npm install
npm run tauri dev          # run in development
npm run tauri build        # build release bundle

Android build

Extra requirements: Android SDK + Platform-Tools, NDK 27, and JDK 17. scripts/android-env.ps1 sets JAVA_HOME, ANDROID_HOME, and NDK_HOME for the current PowerShell session.

. .\scripts\android-env.ps1
npm run android:init       # one-time per checkout
npm run android:dev        # build + install on the connected device
npm run android:build      # produce a signed-with-debug-key APK

Device must be plugged in over USB with debugging enabled.

npm run android:dev runs scripts/android-dev.ps1, which:

1. Verifies adb is on PATH and at least one device is listed. 2. Applies adb reverse tcp:1420 tcp:1420 and tcp:1421 tcp:1421 (Vite dev + HMR) so the WebView reaches the host via USB loopback. 3. Runs tauri android dev --host 127.0.0.1 so the WebView's devUrl bakes in 127.0.0.1, matching what adb reverse exposes.

This path works whether Wi-Fi is on or off — only USB matters. If you still see failed request for http://127.0.0.1:1420 while debugging, USB has dropped or the reverse mapping was cleared (re-plug, reboot, or adb kill-server all clear it). Re-run npm run android:dev and it'll re-apply the mapping. To bypass the helper, use npm run android:dev:raw (calls tauri android dev directly — Tauri then picks the host's LAN IP).

Tech Stack

Frontend — React 18 · TypeScript · Tailwind CSS · xterm.js Backend — Rust · Tauri 2 · russh · rusqlite · aes-gcm · argon2 · zstd

Credits

Designed and built by Sina in collaboration with Claude. Every line of code in this repo was written together with Anthropic's Claude.

License

MIT — see LICENSE.

---

Keywords: SSH client, SFTP client, terminal emulator, port forwarding, SOCKS proxy, HTTP proxy, folder mirror, folder sync, remote file edit, encrypted profile sync, zero-knowledge cloud, Argon2id, AES-256-GCM, TOFU host keys, Rust, Tauri, React, xterm.js, Windows SSH client, macOS SSH client, Linux SSH client, Android SSH client, open source SSH, MIT licensed, PuTTY alternative, WinSCP alternative, MobaXterm alternative, Bitvise alternative, Termius alternative, SecureCRT alternative, Royal TSX alternative, ConnectBot alternative, JuiceSSH alternative, rsync GUI, sshfs alternative, Tabby alternative.

Bitvise, forever in my heart.

GitHub Stars & Activity

364Stars
27Forks
20Open issues
TypeScriptLanguage

GitHub Popularity

GitHub stars364
Forks27
Open issues20
Primary languageTypeScript
LicenseMIT
Stars gained today40
Created2026-05-27
Last pushed2026-08-22

Trending History

Daily boardrank #54 · ▲ 40 stars

Related GitHub Projects

1

freeCodeCamp / freeCodeCamp

TypeScript★ 456,393⑂ 47,645▲ 100 stars
→
2

paperclipai / paperclip

TypeScript★ 90,688⑂ 15,722▲ 2,401 stars
→
3

heygen-com / hyperframes

TypeScript★ 53,715⑂ 4,895▲ 304 stars
→
4

calcom / cal.diy

TypeScript★ 48,700⑂ 15,226▲ 24 stars
→
5

dream-num / univer

TypeScript★ 20,765⑂ 1,762▲ 895 stars
→
6

freemocap / freemocap

TypeScript★ 10,339⑂ 970▲ 31 stars
→
7

mobile-next / mobile-mcp

TypeScript★ 8,002⑂ 686▲ 577 stars
→
8

vercel-labs / scriptc

TypeScript★ 5,494⑂ 142▲ 102 stars
→

More Trending Repositories