Zero Trust & Relay
Reach machines with no inbound port open, hide credentials from the people using them, and approve access per request.
One relay sits behind each of these features. It brokers the connection; it is not a place your credentials live.
- Persistent sessions — Keep an SSH session alive on the relay so it survives your laptop closing.
- PAM Broker — Someone connects without ever being given the password. Works for SSH, RDP and VNC.
- One-time browser links — Share access to a host through a link that works once.
- Connect by ID — TeamViewer-style rendezvous for RDP, with no port forwarding.
- MangoSSH Direct — Reach a Windows machine that has no RDP server enabled at all.
- Private Network — A MangoFly overlay network between your machines.
Oversight
- PAM Dashboard — Fleet-wide view of privileged sessions, pending requests and credential rotation.
- Just-in-time access — Access is requested and approved per use, and expires. Policy can require a ticket reference and a one-time code from the approver.
- Fleet-wide policy — Rules applied by group, by tag or across the fleet rather than per host. A default policy can be overridden on a host; a mandatory one locks the control.
Step-by-step guides
How to set each of these up, one task per page.
- PAM Broker and browser access →Let people connect without ever seeing the password, from the app or a browser link.
- Just-in-time access →Time-boxed, approved access to sensitive hosts.
- Policies →One page to set recording, JIT, crypto and key rules across many hosts.
- Single sign-on (OIDC) →Sign in with your identity provider and map its groups to vault roles.
- Device posture →Require an encrypted disk before a device gets credentials.
- Self-hosting the relay →Run the relay that powers persistent sessions, Connect by ID and the PAM Broker.
Full detail
Step-by-step instructions, how to check each one worked, and what to do when it did not.