# VsTerm puts an SFTP pane, a route diagram and a desk pet in one SSH client

> A native Rust SSH terminal that folds file transfers, elevated SFTP, network path tracing and IP reputation checks into the session, whose repository publishes documentation and release notes but no source, and whose licence is recorded as unasserted.

**vesaaa/vsterm** — Cross-platform SSH terminal in native Rust — WindTerm + Termius + FinalShell strengths in one: pro shell UX, sessions & vault, SFTP/ops built-in. Simple, polished, and a little fun (desk pets). 跨平台 SSH 终端（Rust 原生）——集合 WindTerm / Termius / FinalShell 之长：专业终端体验、会话与凭据、文件与运维一体。简单好用有乐趣

- Repository: https://github.com/vesaaa/vsterm
- Stars: 359 · Forks: 14
- Language: Unknown
- License: NOASSERTION
- Published: 2026-09-17 · Updated: 2026-09-17 · Language: en
- Canonical page: https://hysenlabs.com/projects/vesaaa-vsterm

## The repository is documentation, changelog and assets

Start with what is not here, because it shapes every other decision. The repository's top level is CHANGELOG.md, LICENSE, README.md, README.zh-CN.md and an assets/ directory. There is no Cargo.toml, no src/, no lockfile. The primary language is not even identified by the repository metadata.

So this is not a project you can read, fork or build from the source repository. VsTerm is distributed as packaged builds through the Releases page, and the website is the product's front door. Anyone deciding whether to depend on it is trusting a binary, not a commit history.

The licence deserves a note of its own. A LICENSE file exists in the tree, while the package metadata records the licence as NOASSERTION, which means the automated record does not assert one. That is not the same as a permissive licence, and it is the first document to resolve before this goes near a work device.

Maintenance is visible from the release dates alone: v1.3.3 on 2026-09-19, v1.3.4 on 2026-09-22 and v1.3.5 on 2026-09-29, with the last push on 2026-09-29. The one inconsistency worth flagging is that the README's highlight section is still titled around v1.1.13, so the feature summary trails the shipped version by a fair margin.

## egui over wgpu, alacritty for the grid, russh for the wire

The stack is stated as four lines, and each one is a deliberate choice.

The interface is `egui` with `eframe`, rendering through `wgpu`, which means DirectX 12 on Windows, Metal on macOS and Vulkan on Linux. The terminal itself is `alacritty_terminal`, so the grid, selection and rendering come from the same library Alacritty uses rather than from a terminal emulator written for this project. SSH is a built-in `russh` implementation, and the note that matters is what it shares: the PTY, remote commands and SFTP all ride one authenticated session rather than opening separate connections.

Configuration is YAML. Credentials go to the OS keyring plus an encrypted vault, so secrets are not sitting in a config file next to your host list.

Two absences are as informative as the presences. There is no Electron, which is the point of the whole project and the reason the comparison table lists implementation language as the first row. And there is a software-render fallback for VM and RDP-style environments, along with a lower frame cadence when no hardware GPU is available, which is the difference between a terminal client that works over Remote Desktop and one that does not.

## Transfers show their queue instead of hiding behind a dialog

The first thing the project claims is that terminal and files live in one flow rather than two windows. Shell tabs sit above a bottom SFTP pane, and ZMODEM transfers with `rz` and `sz` are part of that same workflow rather than an add-on.

The specific complaint being answered is about visibility. Both SFTP and ZMODEM expose progress and queue state, instead of a transfer disappearing into a blocking modal or running invisibly in the background where a stalled upload looks identical to a finished one. For someone moving a database dump over SSH, that is the difference between watching and guessing.

Two rows of the project's own comparison table are marked as capabilities nothing else in that comparison has. Terminal and file-pane path sync, so navigating on one side moves the other. And elevated SFTP that can follow `sudo -i` or `su`, which is the ordinary case on a Linux server where your SSH user cannot read /etc and the files you need are behind sudo.

That second one is the feature to test first if you are trialling this. Elevation handling is where file managers over SSH usually give up, and a pane that cannot follow sudo is a pane you will keep falling back to a separate SFTP client for.

## Route diagrams and IP reputation live in the session

The second cluster is network diagnostics, and it is unusual for a terminal client to carry at all.

Ops panels are described as first-class rather than side utilities, and the list is specific: routes, connections, path trace, IP quality, system info and live host metrics. The path trace adds per-hop geo and ASN enrichment, and the IP quality panel runs fraud, datacenter and blacklist checks. Routing diagrams and connection charts are available without leaving the session.

The comparison table marks route diagram and policy-routing topology, geo and ASN path trace, and built-in IP quality and reputation checks as capabilities where VsTerm is the only product with a first-class entry. Every other tool in that table, WindTerm, Termius, FinalShell, MobaXterm, SecureCRT, Xshell and Tabby, is marked as not having them as a headline built-in workflow.

The same applies to the connection and socket monitoring panel and the CPU, memory and storage graphical monitor, which only FinalShell shares, and to a live host metrics view for the machine you are actually sitting on.

What none of this replaces is knowing your network. These panels tell you what the path looks like from where you are; they do not tell you whether the hop in the middle is doing something you would want it to be doing.

## The comparison table states its own bias before you read it

Most vendor comparison tables are worth discounting. This one tells you how to read it, which is rarer.

The legend defines three marks: built in and surfaced as a first-class workflow, supported in a narrower or companion-tool or plugin-style way, and not a headline built-in capability in the usual product workflow. The notes then say the table is intentionally strict, favouring built-in, documented, end-user-visible workflows over anything possible via shell commands or scriptable externally, and that several cells are the middle mark because some commercial tools split file transfer into a companion app or a separate tab.

Read that way, the table's claims are narrow and checkable. VsTerm is the only entry with path sync, elevated SFTP following `sudo -i`, route topology, geo and ASN tracing, IP reputation checks, connection effects and a desk pet. It is not alone in proxy support: SSH over SOCKS5 or HTTP CONNECT proxy is marked present for every product in the table, which is the honest baseline.

The scrollback row is handled with the same care. Where a figure is not clearly documented the table prints a dash rather than a guess, and VsTerm's own limit is described as dynamic: 100,000 lines on Standard, 500,000 on Pro, against documented maxima elsewhere of 25,000, 128,000, 360,000, unlimited and roughly 2.1 billion lines.

## Standard is offline SSH; Pro is cloud sync and a deeper scrollback

The product splits cleanly, and the split is not about SSH features.

Both tiers get local SSH sessions, SFTP, ZMODEM, the ops panels, the encrypted local credential vault, Personal Cloud account and devices, and the dog desk pet. The differences are Pro only: cloud sync covering sessions, commands, layouts, preferences and credentials, the monkey desk pet, scrollback raised from 100,000 to 500,000 lines, and what the table calls future enhancements, listed as not supported on Standard.

VsTerm runs fully offline for SSH work, and Personal Cloud with its account login, entitlement and encrypted sync is optional. Pro unlocks through a binding-checked cloud entitlement, the examples given being a GitHub Star promo or a redeem code, and the purchase runs through Preferences, Account, which opens the buy page in your browser.

The cloud part is the part worth reading closely, because sync of credentials deserves scepticism by default. Uploads are client-side encrypted and the server stores ciphertext only. Device identity is an Ed25519 key pair whose private key stays in the OS keyring and is never uploaded. Sync objects are encrypted with AES-256-GCM using a key derived from your master password through Argon2id, stored as a VSC2 blob. The credential vault is already encrypted locally, so sync wraps the sealed vault.enc rather than plaintext passwords. Without the master password and the derived key the blobs are not decryptable, the README states, including by VsTerm operators.

## Import brings hosts and groups, never passwords

Migrating in is a first-class feature rather than an afterthought, and it covers the tools the project positions itself against.

File, then Import from Others handles WindTerm through its `.wind` files or `profiles/` directory, Xshell through `Sessions` or `.xsh`, FinalShell through its data directory or `conn/`, MobaXterm through `MobaXterm.ini` or `.mxtsessions`, Tabby through `config.yaml`, OpenSSH through `~/.ssh/config`, and SecureCRT through `Sessions` or `.ini`. SSH hosts and groups come across, two folder levels deep.

Two limits are stated rather than discovered later. Encrypted passwords are not copied, so you type them on the first connect to each host. And a private-key file path keeps public-key authentication working, while named keys stored inside Xshell or FinalShell are not resolved, which means those users re-add key material by path.

First launch creates `~/.vsterm/` including a demo session tree, which is a reasonable way to see the layout before importing anything over it.

The remaining friction is the one the README treats as expected: packages are not yet notarised by Microsoft or Apple, so the operating system warns once. It opens with Windows SmartScreen guidance, and the copy here stops in the middle of the first numbered step.

## Conclusion

Adopt VsTerm if you want SFTP, elevated file access and host diagnostics inside the same window as the shell, and if you are willing to install a build that the OS will warn about once. Do not adopt it expecting to read or build the source: the repository publishes a README, a changelog and assets, not code, and the package metadata records the licence as unasserted. Verify the release you download against the changelog, since the README's highlight section still describes v1.1.13 while releases are at v1.3.5.

## FAQ

### What is VsTerm built with?

The interface is egui with eframe over wgpu, using DirectX 12 on Windows, Metal on macOS and Vulkan on Linux. The terminal grid is alacritty_terminal, SSH is a built-in russh implementation where PTY, remote commands and SFTP share one authenticated session, configuration is YAML, and credentials go to the OS keyring plus an encrypted vault. There is no Electron.

### Does VsTerm need an account to work?

No. It runs fully offline for SSH work, and Personal Cloud with account login, entitlement and encrypted sync is optional. Pro unlocks after a binding-checked cloud entitlement, such as a GitHub Star promotion or a redeem code, purchased from Preferences, Account.

### Can VsTerm import my sessions from WindTerm or Xshell?

Yes, through File, Import from Others, which covers WindTerm, Xshell, FinalShell, MobaXterm, Tabby, OpenSSH and SecureCRT with their own paths. Hosts and groups come across two folder levels, but encrypted passwords are not copied and named keys held inside Xshell or FinalShell are not resolved.

### How does VsTerm store credentials, including in cloud sync?

An encrypted local vault backed by the OS keyring. In sync, device identity is an Ed25519 key pair whose private key stays in the keyring, sync objects use AES-256-GCM with a key derived from the master password via Argon2id, and the vault is uploaded as a sealed blob rather than plaintext.

### What do I get without Pro in VsTerm?

Local SSH sessions, SFTP, ZMODEM, the ops panels, the encrypted local vault, the Personal Cloud account and devices, the dog desk pet, and 100,000 lines of scrollback. Pro raises scrollback to 500,000 lines and adds the monkey desk pet and cloud sync of sessions, commands, layouts, preferences and credentials.

## Sources

- [Issues](https://github.com/vesaaa/vsterm/issues)
- [README](https://github.com/vesaaa/vsterm/blob/main/README.md)
- [Releases](https://github.com/vesaaa/vsterm/releases)
- [vesaaa/vsterm on GitHub](https://github.com/vesaaa/vsterm)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/vesaaa-vsterm
