Free, open-source MobaXterm alternative built with Rust
SSH • SFTP/SCP • terminal tabs & splits • remote editing • tunnels • reviewed automation
⬇️ Download · 🎬 Watch the app · 🌐 Website · 🧭 Roadmap · 📖 Docs · 🤝 Contribute
mobarust-desktop-demo.mp4
From a shell to a working remote workspace. A real macOS ARM64 application recording: independent terminal panes, an authenticated SSH session, SFTP browsing and editing, a completed file download, an HTTP request through an SSH tunnel, reusable snippets, and light/dark themes.
▶ Watch / download the full walkthrough · Recording details & chapters
The server, keys, files and HTTP service are disposable loopback fixtures. The recording shows working product flows; it is not evidence of production-server or cross-platform compatibility.
| Platform | Download | Available version |
|---|---|---|
| 🍎 macOS · Apple Silicon | ARM64 DMG | 0.1.31 |
| 🍎 macOS · Intel | x64 DMG | 0.1.31 |
| 🪟 Windows · x64 | Installer | 0.1.12 |
| 🐧 Ubuntu / Debian · x64 | DEB | 0.1.12 |
| 🐧 Other Linux · x64 | AppImage | 0.1.12 |
Preview distribution: no publisher signing; macOS is ad hoc signed and not notarized. Windows/Linux installers are older and do not include the latest main changes. RDP is excluded from normal installers.
📝 Mac release notes & SHA-256 files · Windows/Linux release files · Installation help
On Mac, move MobaRust to Applications. On Debian/Ubuntu, use sudo apt install ./MobaRust-0.1.12-linux-x64.deb. AppImage prerequisites vary by distribution. Checksums verify downloaded bytes; they do not establish publisher identity.
- Live tunnel traffic: local, SOCKS5 and remote forwards now show payload bytes while clients remain connected.
- Accurate stopped totals: Stop and copy errors retain accepted bytes; completed copies count once and SOCKS5 framing is excluded.
- Native checks: the ARM64 installer copy passed live/stopped totals, SSH-tab Close and normal Quit with eight byte-matched clients and clean fixture shutdown.
- Locally checked release: the full suite passed, including 114 desktop tests, four forwarding cases and 25 OpenSSH cases. Both Mac packages passed mounted layout, architecture, signature and CLI checks.
All four published assets matched anonymous downloads byte for byte. This fixes the v0.1.30 active/cancelled counter defect. Broader workloads, Intel GUI and Windows/Linux acceptance remain open. Windows/Linux downloads remain v0.1.12; the walkthrough remains v0.1.17. Native checks · Release limits.
Known v0.1.31 issue: Files can retain a busy error after a successful Refresh. A source correction scopes listing errors and clears them on a new request; corrected native acceptance and a new installer remain pending.
Updated 2026-10-03. The roadmap has 57 of 76 checked items (75%). This is checklist completion, not production readiness: implementation, tests, downloadable binaries and hardware evidence are separate milestones.
| Area | Verified so far | Next acceptance gate |
|---|---|---|
| ✅ SSH reliability | OpenSSH lab covers keys, jumps, agent, IPv6 and recovery. Earlier Mac authentication/reconnect receipts remain available. The v0.1.29 ARM64 copy passed Escape before connection, approved startup, replacement startup timeout with no further retry, and normal local-PTY Quit. Receipts · v0.1.29 check. | Release-copy successful startup/output ordering, queued expiry/overflow, prompt/backpressure/resize acceptance, Windows/Linux, OpenSSH password/PAM and sustained workloads. |
| ✅ Native workflow demo | macOS ARM64 terminals, SSH, remote edit/save, file download and local tunnel. | Wider keyboard, failure-recovery and GUI coverage across all three OSes. |
| ✅ Editor recovery | Mac candidate passed conflict/reopen recovery and both Save as policies. The v0.1.26 ARM64 copy passed encoding Save/new Save as; the v0.1.27 copy passed explicit legacy Open/Save/reopen and UTF-8 conversion, with exact bytes/modes and normal-Quit cleanup. Receipts. | Windows/Linux, saved-with-warning focus and uncertain promotion recovery. |
| ✅ Quality baseline | One complete green Ubuntu/macOS/Windows run on source ac70e39; local checks continue. |
New repeated Windows startups and Linux zsh/fish runtime evidence. GitHub CI is disabled by request. |
| 🟡 Native dialogues | Mac lab verified file policies, reconnect-safe approvals, settings imports and visible error focus. Included in the v0.1.25 Mac preview. | Broader collision/recovery checks and native Windows/Linux acceptance. Evidence. |
| 🟡 Distribution | Mac ARM64/x64 0.1.31 previews; Windows/Linux 0.1.12 downloads. | Align versions, clean install/uninstall, signing and notarization. |
| 🧪 RDP / VNC / X11 / serial | Isolated helpers and controlled fixtures exist. | Real servers, physical adapters and platform interoperability. RDP security gates remain open. |
Next priorities: sustained failure/recovery and transfer-control acceptance → current Windows/Linux installers → signing and notarization. Wider SSH authentication/recovery remains open.
📍 Detailed roadmap & completion criteria · Platform evidence · SSH lab · Benchmark receipt
Rust owns protocols, processes, saved credentials and persistence. Unknown SSH host keys are not silently accepted. Multiline paste and remote execution have explicit review boundaries. VNC TCP and Telnet are unencrypted; experimental support is documented separately.
Local test safety: protocol fixtures listen only on 127.0.0.1 or ::1, with disposable data and generated credentials. They do not enable Remote Login, change firewall/router rules or expose a home-network port. Native checks use an isolated app copy; owned test processes are stopped afterwards. Testing boundaries.
Threat model · Dependency audit · Private vulnerability reporting
🛠️ Build and contribute
Use Rust stable 1.90+, Node.js 22, pnpm 10, and the native Tauri prerequisites.
git clone https://github.com/OthmaneBlial/MobaRust.git
cd MobaRust
pnpm install --dir apps/desktop --frozen-lockfile
cargo xtask check
pnpm --dir apps/desktop tauri devcargo xtask test-ssh # Disposable OpenSSH lab on Unix
cargo xtask check-rust # Native workspace tests and ClippyThe full check covers frontend, Rust, isolated protocol helpers, package layouts and fuzz compilation. Fixtures use disposable state and generated credentials.
Build your next remote workspace with us.
Report a bug · Explore the roadmap · Star MobaRust ⭐
Independent project; not affiliated with Mobatek or MobaXterm. Licensed under Apache-2.0.

