Dendrite wordmark

Terminal access your security team can actually approve.

Dendrite is the collaborative terminal platform for engineering teams. Share live shell sessions with authenticated colleagues - self-hosted, air-gap capable, and audit-ready by design.

Community edition is free · macOS, Linux & Windows

dendrite - session: @sshxdev-sg1-app-01 - 2 collaborators
Two engineers collaborating in a shared Dendrite terminal session with integrated chat
Self-hostedyour infrastructure, your data
Air-gap capableno cloud dependency required
Full audit loggingevery session, on the record
Platform

Built for teams, engineered for compliance

Dendrite gives engineering managers visibility and CTOs a defensible security posture - without slowing the people in the shell.

Live shared sessions

Multiple authenticated engineers work in the same shell in real time - pairing on deploys, debugging incidents together, or reviewing changes side-by-side. No screen sharing, no credential handoffs.

LDAP & SSO integration

Authenticate against your existing directory. Identity, group membership, and access policies flow from your LDAP or SSO provider - no parallel user database to secure or reconcile.

Just-in-time approvals

Access is granted for the session that needs it, not permanently. Session hosts approve collaborators on demand, and view-only mode lets reviewers observe without touching production.

Complete audit logging

Session creation, joins, approvals, and view-only changes are recorded server-side. Export audit trails for compliance evidence, incident reviews, and change-management processes.

Least-privilege by default

Every session runs on a host you designate, enforced server-side. View-only locks apply instantly to all attached clients - observers watch, but cannot type, paste, or scroll beyond policy.

Deploy anywhere

Self-hosted in your VPC, on bare metal, or fully air-gapped. Dendrite's coordination layer never executes commands on your behalf - your hosts stay behind your firewall.

Install

One command to your first session

No daemons to babysit. No config files to decipher. The full guide lives in the documentation.

$ curl -fsSL https://dendrite.sh/install.sh | sh

Also available via brew install kazlabs/tap/dendrite and winget install KazLabs.Dendrite

Product tour

Every screen, one product

From sign-in to live collaboration - the workflow your engineers already know, with the controls your auditors expect.

dendrite - live session
Two engineers collaborating in a shared Dendrite terminal with integrated chat
Live collaborationTwo authenticated users share the same shell in real time, with session chat alongside - plus network latency visibility for every participant.
dendrite - home
Dendrite home screen with session list
Session dashboardActive and recent sessions at a glance. Notifications and sign-out in one place.
dendrite - new session
Dendrite host picker for starting a new session
Host selectionPick the registered host where the session runs. Commands execute only on machines your team controls.
dendrite - terminal settings
Dendrite terminal settings: display name, color palette, scrollback, and view-only toggle
Session controlsDisplay name from the directory, color palettes, scrollback depth - and the server-enforced view-only lock.
dendrite - sign in
Dendrite sign-in page
Authenticated from the startSign-in ties every session to a real directory account. No anonymous access, no shared links.

View all screenshots →

Pricing

Plans that scale with your rollout

Start free with your core team. Add directory integration when you need it. Enterprise covers regulated and air-gapped environments.

Community

For small teams and evaluation

$0

Free, forever

  • Up to 5 hosts and 5 users
  • Live shared sessions & chat
  • View-only mode
  • 7-day audit log retention
  • LDAP / SSO integration
Get Started

Small Teams

For growing engineering orgs

$10 /user/mo

15 hosts, plus $10 per extra user

  • 15 hosts, unlimited users
  • Everything in Community
  • Just-in-time approvals
  • LDAP integration
  • 30-day audit log retention
Get Started

Enterprise

For regulated and critical infrastructure

Custom

Annual agreements

  • Unlimited hosts and users
  • All the bells and whistles
  • Self-hosted & air-gap capable
  • Custom retention & policies
  • Dedicated support & SLA
Talk to Sales
FAQ

Frequently asked questions

Where does Dendrite run? Do commands touch your cloud?

No. Sessions execute only on hosts you register - in your VPC, on-prem, or fully air-gapped. Dendrite's coordination layer brokers authenticated connections; it never executes commands on your behalf.

How does Dendrite integrate with our identity provider?

Professional and Enterprise plans authenticate against your LDAP directory or SSO provider, so user lifecycle is managed where it already is. Enterprise adds SCIM for automated provisioning and de-provisioning.

What does the audit log capture?

Session creation, collaborator joins and approvals, view-only changes, and sign-in events are recorded server-side and exportable - the evidence trail your compliance processes need.

Can we restrict who can type in a session?

Yes. The session host can enable view-only mode, enforced on the server immediately - all attached observers lose input capability at once. Just-in-time approvals control who joins at all.

Is Dendrite suitable for telco and critical infrastructure (CII) environments?

That is a design goal. Self-hosted and air-gap-capable deployment, directory-based authentication, least-privilege session controls, and audit logging are built for compliance-sensitive operators. Compliance certifications are on the roadmap as the platform matures.

What does the free Community edition include?

Up to 5 hosts and 5 users with live shared sessions, chat, and view-only mode - free forever. Directory integration and audit exports are Professional features.

Roll out secure terminal collaboration this quarter

Install the Community edition in minutes, or talk to us about a production deployment.