Work Cockpit
One window for your whole server fleet.
Work Cockpit is a desktop application for system administrators: it puts every server in one window, on your own machine — no account of ours in the middle, and your servers and credentials never reach our servers.
- SSH · VNC · RDP
- Live CPU / memory / disk
- Cloudflare DNS & firewall
- Scheduled commands
- OS update scans
- File Compass on macOS
- Audit log
How Work Cockpit uses Google Drive · Privacy policy · Terms of service · support@workcockpit.com
Everything in one control room
A desktop app for the whole job — reach, monitor, operate and secure your fleet without a dozen tools.
Server fleet
Cards with live CPU / memory / disk, grouped and tag-filtered, with SSH, VNC and RDP built in.
Proxmox control plane Next release
Import VMs from many named PVE clusters; metrics and hypervisor info come from the host, no guest login. Built and tested against a real cluster — shipping after the first release.
Cloudflare
Zones, DNS records, SSL modes, WAF and always-HTTPS — plus batch operations across domains.
File Compass Mac
A full dual-pane file manager built into the cockpit — Finder shortcuts, tabs, folder notes, transfers and scheduled backups. Every server card opens a two-pane SFTP window: your machine on one side, the server on the other.
One licence, all platforms
macOS, Windows and Linux from one purchase. Bought on the App Store? A pairing code unlocks your other machines. Bought a licence key on the web? It activates on up to 10 of your own machines.
Scheduler
Schedule server commands and Cloudflare changes — once, on an interval, daily or weekly — with a run history.
Patch management
Per-server update scans by package manager (apt, dnf, zypper, apk, pacman, brew, winget) with a badge and one-click apply.
Logs & email alerts
A local event log for everything the app does, with rules that email you when something crosses a threshold.
Encrypted support
One-time, TLS-pinned remote-shell sessions with a full PTY — direct and peer-to-peer, never through a cloud relay.
Security built in
Trust-on-first-use host-key pinning, ProxyJump bastions, and every secret kept in your OS keychain.
Server tests
Ping, CPU / RAM / disk load benchmarks and an engine-aware database test, right from the server card.
Team server Pro
Your own Mac serves its fleet to your colleagues. Grant each person the servers they may reach at read or read + write, send one invite, and their activity lands in your log. The connection is direct — no relay, no vendor in the middle. How it works
Local accounts
Users and roles stay on your machine. Organization contact details, license records and aggregate usage are synchronized separately; local passwords and server credentials stay on your devices.
Themes & fonts
A dozen colour themes and adjustable fonts — the whole cockpit reskins to your taste, light or dark.
AI & Docker Next release
Connect AI providers and discover Docker containers into the fleet — reach a container's shell like any server. Both follow the first release.
Plans & pricing — availability pending
Pro licences are available for Windows, Linux and the direct macOS download. The Mac App Store listing, Apple subscriptions and 14-day trial are not available yet. See licence options.
- Up to 5 servers
- SSH, VNC & RDP
- Live metrics, tags & bulk run
- Encrypted export / import
- Cloudflare, scheduling, patching
- Support tickets
- Everything in Free, unlimited servers
- Cloudflare DNS & firewall
- Scheduler & patch management
- Logs & email alerts
- Team server — your Mac serves the fleet
- Teammates with read / write roles
- Use one subscription on all your machines
Joining a colleague’s team?
You do not need a plan or a seat. Install the same app everyone else does, choose Connect to a team server on the sign-in screen, and paste the invite they sent you.
Downloads
The direct macOS DMG is signed and notarized. It is a universal build for Apple silicon and Intel Macs and runs outside Apple’s App Sandbox. The separate App Store build runs in Apple’s sandbox. Windows and Linux packages are not yet code-signed; Windows SmartScreen may warn on first run.
Teammates do not need a seat. On Pro, the people you invite install the app free and operate the servers you grant them. Only the person running the team server pays.
Support tickets are separate from the plan. No tier includes one: they are $25 each, or five for $124.99. They never expire, and they are bought inside the app.
Apple billing and subscription management will be available if and when the Mac App Store listing launches. It is not available yet.
Documentation
How the app works, what it does with your data, and how to put a team on it.
Getting started
Download Work Cockpit from this site and open it. Your server account is local to your Mac. Organization activation uses a Work Cockpit account and sends organization name and contact details, an installation identifier, reported plan, app version, and aggregate server/authentication counts and module names for organization, licensing and product usage records. Local passwords and server credentials are not sent. The Mac App Store listing is not available yet.
Forgotten the password? There is no reset link, because there is nobody to reset it. The account is local, so start over: quit the app, remove its data folder, and register again. Your servers come back from an export if you kept one.
Adding servers
Servers › Add server. A server is a name, an address, and one or more ways in:
- SSH — terminal, file upload, metrics, patching, scheduled commands.
- VNC and RDP — a screen, for the machines that need one.
Credentials are stored in the macOS Keychain, never in the app’s own files. The first time you reach a host over SSH its key is pinned; if that key ever changes, the connection is refused rather than quietly accepted.
Free keeps up to five servers. The cap is on adding — an installation that is already over it keeps everything and is simply blocked from adding more.
Moving between machines
Settings › Backup & transfer writes an encrypted file containing your servers, credentials, SSH host-key pins and settings. Save it locally, carry it to another computer, or upload the encrypted file to your own Google Drive.
The file is sealed with a password you choose (Argon2id + XChaCha20-Poly1305) or to a certificate you hold. Keep the password or matching private key separately; it is needed to import the backup. A full backup includes local accounts, so share it only with someone who should own that installation.
For teammates, use a scoped team file instead of a full backup. Windows and Linux release work follows the macOS release.
Subscription sharing (planned)
Apple subscription sharing between the iPhone and Mac App Store apps is planned. Neither App Store listing is available yet, so the purchase and pairing steps below are not currently available.
When App Store versions are available, the direct download will be able to pair a subscription because an installation outside the App Store has no store receipt. The planned flow uses the app’s Subscriptions tab:
- In the App Store copy: open Subscriptions and choose Use this subscription on another computer. It shows a six-character code, good for ten minutes.
- In the direct copy: open Subscriptions, choose I bought this on the App Store, and type the code.
The direct copy checks Apple’s signed purchase and refreshes it periodically. This pairing feature is not available until the App Store release launches.
What travels is Apple’s receipt: a transaction and a product. Not a server, not an address, not a credential.
Team server Pro
On the Pro plan your Mac can serve its fleet to your colleagues. It is the part of this product that has no equivalent elsewhere: teams normally get this by pushing their infrastructure through a vendor’s cloud. Here the server is your machine, and we are not in the path at all.
- Team › Members — add a user for the person.
- Team › Team server — set the address colleagues should connect to, then Start.
- Grant — pick the servers, features and read or write access for that person.
- Invite — copy the four lines it gives you and send them however you normally talk.
About the port
The default is 8443, not 443. A sandboxed Mac app is not allowed to bind a port below 1024 — that needs administrator rights no App Store app has. If you want 443 reachable from outside, forward 443 to 8443 on your router; the connection is TLS either way.
Read and write
Read permits only the selected Metrics, Logs and Files features. Live metrics and read-only files are served by the team host without sharing credentials. Files are confined to the remote login home and downloads to 4 MiB. Write may also grant Terminal, Commands or Patch and share the credentials needed for those features.
Revoking access
Revoke a device and it stops working the next time it connects. Every sync stamps a 14-day expiry. An expired snapshot loses its imported fleet inside the app. Credentials already shared with a write member can still be used outside the app; rotate server credentials when that access must end.
Joining a team
If a colleague runs the team server, you do not need a paid plan and you do not need a seat. Install the current direct macOS release from this site. Choose Connect to a team server and paste the four lines they sent you:
Address: ops.example.com Port: 8443 Invite code: ABCD-EFGH-JKMN Fingerprint: 0b30557a9fc4e90e…
Add the username and password they added for you and press Connect. The app enrols, makes that username and password your local sign-in, and pulls down the servers and credentials you were granted — the live connection synchronizes the scoped fleet. The transfer is encrypted end to end between the two machines.
The invite works once. The fingerprint is what stops someone else answering in your colleague’s place, and the code is what stops a stranger enrolling — neither is much use without the other. From then on you sign in with that same username and password, even with the team server unreachable.
Servers you added yourself stay yours. Leaving the team removes only what the team gave you.
Without a network connection to the team host, its administrator can export a password-protected .wcteam file for a signed-in colleague to import. It expires after 14 days, has no early revocation channel, and does not support the live read-only proxies. Verify the sender separately; the file has password-based integrity protection and no issuer signature.
What leaves your machine
Short version: your infrastructure does not.
- Never sent: server addresses, hostnames, SSH keys, passwords, terminal output, metrics, logs.
- No cloud channel between installations. Two copies of this app do not talk through us — a team connects directly to the machine serving it.
- Sent for organization and licensing records: organization name and contact details, installation identifier, reported plan, app version, and aggregate server/authentication counts and module names. Apple and Freemius process purchases for their respective channels. A reported plan is not proof of a purchase.
- Sent, if you open a ticket: the subject, description, category, plan and organization name you provide. Do not include infrastructure details unless you intend to share them with support.
Credentials do travel to the teammates you grant them to — that is what makes the team feature work, and it happens only because you chose that person and those servers. They go from your machine to theirs, directly. We never hold them and never see them.
Plans & billing
The Mac App Store listing, Apple billing and subscription management are not available yet. Pro licences for the direct macOS download, Windows and Linux are available through the licence page.
The 14-day trial and Apple subscription sharing will be available only if the relevant App Store releases launch.
If a subscription lapses, nothing is deleted. The app keeps every server you have and simply stops letting you add more, exactly as the Free tier does.
The current direct download is the available macOS release. App Store purchases and subscription pairing are not available yet.
Support tickets
Tickets are bought, not included: no plan comes with one. They are $5 each or five for $25 — the same price per ticket, bought in one go rather than five — and they never expire, so an unused one is still there next year.
Open one from Support in the app. A ticket includes its subject, description, category, plan and organization name. If we cannot answer without knowing more, we will ask you a question, not ask for access.
Work Cockpit
Work Cockpit is a desktop application for system administrators. It puts a whole fleet of servers in one window: connect over SSH, VNC or RDP, watch live CPU, memory and disk, manage Cloudflare DNS and firewall settings, schedule routine commands, scan for operating-system updates, and keep an audit log of what was run where. It runs on your own Mac — there is no account of ours in the middle, and your servers and credentials never reach our servers.
How Work Cockpit uses Google Drive. Connecting Google Drive is optional. Its only purpose is to keep a copy of your encrypted backup bundle — your server list, settings and credentials, sealed with a password only you hold — somewhere other than the machine you are working on. The app requests the drive.file scope, which grants access to only the files Work Cockpit itself writes; it cannot list, open or search anything else in your Drive. Uploads go straight from your machine to your Drive and never pass through us, and you can disconnect at any time in the app or at your Google account.