# Devzat: chat over SSH, and what self-hosting it actually involves

> Devzat turns an SSH connection into a chat room, so any device with an SSH client can join. It is a small Go server with rooms, DMs and a plugin API, and the interesting question is whether you should run your own.

**quackduck/devzat** — The devs are over here at devzat, chat over SSH!

- Repository: https://github.com/quackduck/devzat
- Stars: 4,071 · Forks: 149
- Language: Go
- License: MIT
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/quackduck-devzat

## The problem Devzat solves: a chat room behind an SSH handshake

Most chat tools assume a browser, a desktop app or a phone app. Devzat assumes the opposite: that you already have an SSH client, and that it is the only tool you need. The README describes it as "a custom SSH server that takes you to a chat instead of a shell prompt", and the practical consequence is that the client is whatever terminal you already have. That matters on locked-down machines where you cannot install software, on servers you are already logged into, and on phones with an SSH app. The project's own help text makes the same point: "Because there's SSH apps on all platforms, even on mobile, you can join from anywhere."

The audience is narrow on purpose. This is a chat for developers and people comfortable in a terminal, which is why the topics list reads chat, devchat, developer-chat, ssh-chat. If your colleagues would need a tutorial before they could send a message, Devzat is not the tool for them. If they already have `~/.ssh/config` entries, it fits without any new client at all.

## How Devzat works: an SSH server that renders a chat, not a shell

The architecture is visible in the repository layout. The entry point is `main.go`, and the SSH listener comes from `github.com/gliderlabs/ssh`, which handles the transport and hands Devzat a session instead of a shell. Everything the user sees is rendered in the terminal: `github.com/charmbracelet/glamour` and `github.com/alecthomas/chroma` handle Markdown and syntax highlighting, and `github.com/fatih/color` plus `github.com/jwalton/gchalk` handle terminal colour. That is why the help text can promise "Markdown support! Tables, headers, italics and everything" and "Code syntax highlighting. Use Markdown fences to send code."

State lives in memory and in files. `devzat-data/` is a top-level directory in the repository, and `logs.go` is a separate file, so message logs and per-user data are persisted to disk rather than held only in RAM. `config.go` and `mainserver.yml` cover configuration, and `rpc.go` plus the `devzatapi/` directory and `compile-protobuf.sh` indicate a gRPC surface: `google.golang.org/grpc` is a direct dependency. That RPC layer is what the plugin API sits on, and `plugin/` has its own README. `slack.go` and `twitter.go` are the other integrations, using `github.com/slack-go/slack` and the `dghubble` Twitter libraries respectively.

Identity is by public key. The README is explicit that "Devzat uses public keys to identify users", which is why a missing key pair produces `Permission denied (publickey)`. There is a deliberate escape hatch: port 443 "does not require a key", so a user behind a restrictive firewall or without a key can still get in. That is a real design trade-off rather than a footnote, and it should shape how you think about who is in your room.

## Joining devzat.hackclub.com and your first commands

The fastest way to see what Devzat is is the public instance. The README gives this as the first command, and it is what you would type to join:

```bash
ssh devzat.hackclub.com
```

On first login the SSH username becomes your display name, so `ssh wenjie@devzat.hackclub.com` gets you in as wenjie. If you are behind a firewall that blocks the default port, the README offers port 443 as an alternative:

```bash
ssh devzat.hackclub.com -p 443
```

Once connected you are in a chat, not a shell. The help text tells you to run `cmds` for the command list; the same list appears in the README under Commands. Rooms work through `cd`, so `cd #foo` joins a room and a bare `cd` lists them. Direct messages use `=` for a one-off, or `cd @user` to stay in a DM. `nick <name>` changes your display name after the first login, and `tz Asia/Dubai` sets your timezone. If you want to avoid typing the host every time, the README suggests an SSH config entry:

```ssh
Host chat
    HostName devzat.hackclub.com
```

After that, `ssh chat` connects. The README also notes a Slack bridge on the Hack Club Slack in the `#ssh-chat-bridge` channel, and a status site for checking whether the main server is up.

## Self-hosting: build, run, and the default port 2221

Devzat is a Go program, and the README's quick start is four commands. They clone, build, and run a server with the default configuration:

```bash
git clone https://github.com/quackduck/devzat && cd devzat
go build
./devzat
```

The README states that the default config is "used & written automatically", and that the server listens on port 2221, described as the default port, which you change by setting `$PORT`. So a fresh instance is reachable at `ssh localhost -p 2221` before you touch any configuration file. The README points to the Admin's Manual for "complete self-host documentation", and that document is a top-level file in the repository, alongside `mainserver.yml`, which is the configuration the project itself uses for its main server.

Two things are worth flagging before you expose an instance. First, the automatic config write means the server creates state on first run; read what it wrote before you invite anyone. Second, the README says self-hosted instances "can integrate with Slack and/or Discord to bridge messages, and Twitter to post new-user announcements", with details in the Admin's Manual. Those bridges are the point where a terminal chat touches the rest of your tooling, and they are also the point where credentials and message duplication become your problem.

## Where Devzat is the wrong tool

The port 443 behaviour is the clearest limitation, and it is a security property rather than a bug. The README says port 443 "does not require a key", which means anyone who can reach that port can join without proving possession of a key pair. Key-based identity in the README is therefore not a universal guarantee; it depends on which port the user arrives on. If your threat model requires every participant to be authenticated by key, the README does not document a way to enforce that across both ports, and the Admin's Manual is where you would have to look.

There is also no documented end-to-end encryption. Messages are rendered server-side and, per the repository layout, persisted in `devzat-data/` and handled by `logs.go`. The server operator can read everything. That is normal for a hosted chat and it is still a reason not to treat Devzat as a place for secrets.

Finally, the client is a terminal. Markdown rendering, syntax highlighting and games like `tic` and `hang` are pleasant in a terminal and useless to someone on a phone without an SSH app. The README itself notes that newline replacement is awkward enough that the author uses an external site for it, which tells you the input model has rough edges. If your team wants threads, reactions, file uploads or search, Devzat's command list does not offer them.

## Devzat compared with a general SSH chat server

The closest comparison in the README's own topic list is ssh-chat, and the difference is in what happens after you connect. A general SSH chat server gives you a shared text channel and little else. Devzat layers a command surface on top: rooms via `cd`, DMs via `=` and `cd @user`, per-user timezones, pronouns, syntax-highlighted code blocks, a syntax theme command, and two built-in games. It also ships integrations that a plain SSH chat does not have, in `slack.go` and `twitter.go`, plus a plugin API documented in `plugin/README.md` and an RPC layer in `rpc.go` and `devzatapi/`.

The cost of that extra surface is more moving parts. A minimal SSH chat server is a single binary with almost no configuration. Devzat has a config file, a data directory, a YAML file used by its own main server, optional bridge credentials, and a plugin system with a protobuf build script. You are trading simplicity for a chat that behaves more like a small product. Whether that trade is worth it depends on whether you want the integrations; if you only want a shared text channel for a handful of people, the extra pieces are weight you will maintain and never use.

## Maintenance, upgrades and the MIT licence

The repository is not archived, and the last push was on 2026-07-23. The most recent release listed is release-a4a1be9, built on 2026-07-23, following release-abf6dd2 on 2026-07-15 and release-f959958 on 2026-06-25. Those three dates are close together, which suggests a period of active work around the middle of 2026, but the README does not document a release cadence, a support window or a migration process between versions.

Upgrade cost is mostly a Go concern. `go.mod` declares `go 1.24.0`, so building from source requires a toolchain at least that new. The dependency list is moderate and includes `golang.org/x/crypto`, `google.golang.org/grpc`, and the Charm libraries, all of which move independently. The README does not document rollback, and it does not describe how `devzat-data/` behaves across versions, so back that directory up before you upgrade and read the release notes rather than assuming compatibility. The README also does not describe a database migration path, because the layout suggests file-based storage rather than a database.

The licence is MIT, stated in the repository's `LICENSE` file. MIT is permissive: it allows commercial use, modification and redistribution provided the copyright notice and permission notice are kept. That is a summary of the licence text, not legal advice; if you plan to redistribute a modified Devzat or run it as part of a commercial service, have your own counsel read the file.

## Conclusion

Adopt Devzat if your team already lives in terminals, wants a chat they can reach from any SSH client, and is willing to run a Go server and read the Admin's Manual before exposing it. Do not adopt it if you need message history guarantees, end-to-end encryption, or a chat your non-technical colleagues will use without a terminal. Before you invite anyone, verify three things on your own instance: that PORT binds where you expect, that the Slack or Discord bridge credentials are configured if you enable them, and what the config file the server writes on first run actually contains.

## FAQ

### What is Devzat?

Devzat is a custom SSH server that takes you to a chat instead of a shell prompt, written in Go and released under the MIT licence. Because SSH clients exist on every platform, the README argues you can join from any device, including phones.

### How do I log in to Devzat?

Run ssh devzat.hackclub.com, and on your first login the SSH username becomes your display name, so ssh wenjie@devzat.hackclub.com joins as wenjie. If a firewall blocks the default port, the README gives ssh devzat.hackclub.com -p 443 as the alternative.

### Why do I get Permission denied (publickey) when connecting to Devzat?

Devzat uses public keys to identify users, so the error usually means you do not have an SSH key pair; the README suggests generating one with ssh-keygen. You can also log in on port 443, which the README says does not require a key.

### Can I host my own Devzat instance?

Yes. The README's quick start clones the repository, runs go build, and then runs ./devzat, which uses and writes the default config automatically. The server listens on port 2221 by default, changed by setting $PORT, and the Admin's Manual covers complete self-host documentation.

## Sources

- [Issues](https://github.com/quackduck/devzat/issues)
- [License: MIT](https://github.com/quackduck/devzat/blob/main/LICENSE)
- [quackduck/devzat on GitHub](https://github.com/quackduck/devzat)
- [README](https://github.com/quackduck/devzat/blob/main/README.md)
- [Releases](https://github.com/quackduck/devzat/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/quackduck-devzat
