Work Cockpit
Work Cockpit is a desktop application for system administrators. It puts a whole fleet of servers in one window: connect over SSH, VNC or RDP, watch live CPU, memory and disk, manage Cloudflare DNS and firewall settings, schedule routine commands, scan for operating-system updates, and keep an audit log of what was run where. It runs on your own Mac — there is no account of ours in the middle, and your servers and credentials never reach our servers.
How Work Cockpit uses Google Drive · Privacy policy · Terms of service · support@workcockpit.com
Everything in one control room
A desktop app for the whole job — reach, monitor, operate and secure your fleet without a dozen tools.
Server fleet
Cards with live CPU / memory / disk, grouped and tag-filtered, with SSH, VNC and RDP built in.
Proxmox control plane Next release
Import VMs from many named PVE clusters; metrics and hypervisor info come from the host, no guest login. Built and tested against a real cluster — shipping after the first release.
Cloudflare
Zones, DNS records, SSL modes, WAF and always-HTTPS — plus batch operations across domains.
Scheduler
Schedule server commands and Cloudflare changes — once, on an interval, daily or weekly — with a run history.
Patch management
Per-server update scans by package manager (apt, dnf, zypper, apk, pacman, brew, winget) with a badge and one-click apply.
Logs & email alerts
A local event log for everything the app does, with rules that email you when something crosses a threshold.
Encrypted support
One-time, TLS-pinned remote-shell sessions with a full PTY — direct and peer-to-peer, never through a cloud relay.
Security built in
Trust-on-first-use host-key pinning, ProxyJump bastions, and every secret kept in your OS keychain.
Server tests
Ping, CPU / RAM / disk load benchmarks and an engine-aware database test, right from the server card.
Team server Max
Your own Mac serves its fleet to your colleagues. Grant each person the servers they may reach at read or read + write, send one invite, and their activity lands in your log. The connection is direct — no relay, no vendor in the middle. How it works
Local accounts
Users, roles and an organization profile that live on your machine — there is no cloud identity to depend on, and no password of yours on our servers.
Themes & fonts
A dozen colour themes and adjustable fonts — the whole cockpit reskins to your taste, light or dark.
AI & Docker Next release
Connect AI providers and discover Docker containers into the fleet — reach a container's shell like any server. Both follow the first release.
Per-seat pricing, billed by Apple
Every plan reaches every server over SSH, VNC and RDP. Free caps how many servers you keep, not what you can do with them. Both paid plans start with a 14-day free trial.
- Up to 5 servers
- SSH, VNC & RDP
- Live metrics, tags & bulk run
- Encrypted export / import
- Cloudflare, scheduling, patching
- Support tickets
- Everything in Free, unlimited servers
- Cloudflare DNS & firewall
- Scheduler & patch management
- Logs & email alerts
- Domain expiry warnings
- Everything in Pro
- Team server — your Mac serves the fleet
- Teammates with read / write roles
- Their activity in your own log
- Use one subscription on all your machines
Joining a colleague’s team?
You do not need a plan or a seat. Install the same app everyone else does, choose Connect to a team server on the sign-in screen, and paste the invite they sent you.
Teammates do not need a seat. On Max, the people you invite install the app free and operate the servers you grant them. Only the person running the team server pays.
Support tickets are separate from the plan. No tier includes one: they are $5 each, or five for $25 — the same price per ticket, just fewer trips through the App Store. They never expire, and they are bought inside the app.
Yearly billing saves 23%. Everything is charged by Apple in your own currency; manage or cancel from System Settings › Apple ID › Subscriptions. We never see a card number.
Documentation
How the app works, what it does with your data, and how to put a team on it.
Getting started
Install Work Cockpit from the Mac App Store and open it. The first launch asks you to add an account — that account lives on your Mac. There is no cloud sign-up, no email confirmation, and no password of yours on our servers.
Only the organisation details you type at that point ever reach us, and only if you later open a support ticket.
Forgotten the password? There is no reset link, because there is nobody to reset it. The account is local, so start over: quit the app, remove its data folder, and register again. Your servers come back from an export if you kept one.
Adding servers
Servers › Add server. A server is a name, an address, and one or more ways in:
- SSH — terminal, file upload, metrics, patching, scheduled commands.
- VNC and RDP — a screen, for the machines that need one.
Credentials are stored in the macOS Keychain, never in the app’s own files. The first time you reach a host over SSH its key is pinned; if that key ever changes, the connection is refused rather than quietly accepted.
Free keeps up to five servers. The cap is on adding — an installation that is already over it keeps everything and is simply blocked from adding more.
Moving between machines
The quick way: Settings › Backup & transfer › Move to another device. The app seals everything and shows a QR plus a 25-character code; on the new device choose Arriving from another device and type it. The code is the key — it never reaches our servers, works once, and expires in 15 minutes. Afterwards the same username and password work on the new device, because your accounts travel inside the bundle.
The file way still exists: Backup & transfer writes one encrypted file with everything in it — servers, credentials, host-key pins, settings. Carry it anywhere, import it, and it is the same installation.
The file is sealed with a password you choose (Argon2id + XChaCha20-Poly1305) or to a certificate you hold. A wrong password and a tampered file fail the same way, with one message that does not say which — a file that told you which half was wrong would be a file that helps someone guess.
This is also how you get your fleet onto an iPhone: show a code on the Mac, type it on the phone. Mobile starts empty on purpose — nothing of yours lives in a cloud to pre-fill it.
One subscription, your own machines
The iPhone app and the Mac App Store app are one purchase — subscribe on either and the other is already paid up, at no extra cost. Nothing to do.
The direct download is the exception, because a copy installed outside the App Store has no receipt to read. Pair it once:
- In the App Store copy: Settings › Plan › Use this subscription on another computer. It shows a six-character code, good for ten minutes.
- In the direct copy: Settings › Plan › I bought this on the App Store. Type the code.
That is the whole thing. The paired machine checks Apple’s own signature on the purchase before it unlocks anything, and it keeps up with renewals by itself as long as you open the App Store copy now and then — you never type a code twice.
What travels is Apple’s receipt: a transaction and a product. Not a server, not an address, not a credential.
Team server Max
On the Max plan your Mac can serve its fleet to your colleagues. It is the part of this product that has no equivalent elsewhere: teams normally get this by pushing their infrastructure through a vendor’s cloud. Here the server is your machine, and we are not in the path at all.
- Team › Members — add a user for the person.
- Team › Team server — set the address colleagues should connect to, then Start.
- Grant — pick the servers that person may reach, and whether they get read or read + write.
- Invite — copy the four lines it gives you and send them however you normally talk.
About the port
The default is 8443, not 443. A sandboxed Mac app is not allowed to bind a port below 1024 — that needs administrator rights no App Store app has. If you want 443 reachable from outside, forward 443 to 8443 on your router; the connection is TLS either way.
Read and write
Read shows the server, its metrics and its logs. Write also opens sessions, uploads files and runs commands.
Revoking access
Revoke a device and it stops working the next time it connects. It does not depend on the person cooperating: every sync stamps a 14-day expiry, so a machine that cannot reach your Cockpit drops the servers you gave it and keeps only its own.
Joining a team
If a colleague runs the team server, you do not need a paid plan and you do not need a seat. Install Work Cockpit from the App Store like everyone else — there is no separate build. On the sign-in screen choose Connect to a team server instead of registering, and paste the four lines they sent you:
Address: ops.example.com Port: 8443 Invite code: ABCD-EFGH-JKMN Fingerprint: 0b30557a9fc4e90e…
Add the username and password they added for you and press Connect. The app enrols, makes that username and password your local sign-in, and pulls down the servers and credentials you were granted — there is nothing to export and nothing to import. The transfer is encrypted end to end between the two machines.
The invite works once. The fingerprint is what stops someone else answering in your colleague’s place, and the code is what stops a stranger enrolling — neither is much use without the other. From then on you sign in with that same username and password, even with the team server unreachable.
Servers you added yourself stay yours. Leaving the team removes only what the team gave you.
What leaves your machine
Short version: your infrastructure does not.
- Never sent: server addresses, hostnames, SSH keys, passwords, terminal output, metrics, logs.
- No cloud channel between installations. Two copies of this app do not talk through us — a team connects directly to the machine serving it.
- Sent, if you register: the organisation details you type. Nothing else.
- Sent, if you open a ticket: the subject and description you write, plus that organisation name. We will never ask for a credential, and a ticket containing one is deleted rather than read.
Credentials do travel to the teammates you grant them to — that is what makes the team feature work, and it happens only because you chose that person and those servers. They go from your machine to theirs, directly. We never hold them and never see them.
Plans & billing
Everything is sold through Apple. There is no card form on this site, no invoice from us, and no licence key to keep safe — your plan follows your Apple ID, so a second Mac restores it rather than buying it again.
Both paid plans start with a 14-day free trial. Yearly billing saves 23%. Cancel any time from System Settings › Apple ID › Subscriptions.
If a subscription lapses, nothing is deleted. The app keeps every server you have and simply stops letting you add more, exactly as the Free tier does.
Installed the app directly rather than from the App Store? That copy cannot buy a plan — it hides the plan screen instead of showing a button that cannot work. It is the Free tier, which is all a teammate needs.
Support tickets
Tickets are bought, not included: no plan comes with one. They are $5 each or five for $25 — the same price per ticket, bought in one go rather than five — and they never expire, so an unused one is still there next year.
Open one from Support in the app. A ticket carries a subject and a description and nothing else; if we cannot answer without knowing more, we will ask you a question, not ask for access.
Work Cockpit
Work Cockpit is a desktop application for system administrators. It puts a whole fleet of servers in one window: connect over SSH, VNC or RDP, watch live CPU, memory and disk, manage Cloudflare DNS and firewall settings, schedule routine commands, scan for operating-system updates, and keep an audit log of what was run where. It runs on your own Mac — there is no account of ours in the middle, and your servers and credentials never reach our servers.
How Work Cockpit uses Google Drive. Connecting Google Drive is optional. Its only purpose is to keep a copy of your encrypted backup bundle — your server list, settings and credentials, sealed with a password only you hold — somewhere other than the machine you are working on. The app requests the drive.file scope, which grants access to only the files Work Cockpit itself creates; it cannot list, open or search anything else in your Drive. Uploads go straight from your machine to your Drive and never pass through us, and you can disconnect at any time in the app or at your Google account.