Everything in one control room
A desktop app for the whole job — reach, monitor, operate and secure your fleet without a dozen tools.
Server fleet
Cards with live CPU / memory / disk, grouped and tag-filtered, with SSH, VNC and RDP built in.
Proxmox control plane Next release
Import VMs from many named PVE clusters; metrics and hypervisor info come from the host, no guest login. Built and tested against a real cluster — shipping after the first release.
Cloudflare
Zones, DNS records, SSL modes, WAF and always-HTTPS — plus batch operations across domains.
Scheduler
Schedule server commands and Cloudflare changes — once, on an interval, daily or weekly — with a run history.
Patch management
Per-server update scans by package manager (apt, dnf, zypper, apk, pacman, brew, winget) with a badge and one-click apply.
Logs & email alerts
A local event log for everything the app does, with rules that email you when something crosses a threshold.
Encrypted support
One-time, TLS-pinned remote-shell sessions with a full PTY — direct and peer-to-peer, never through a cloud relay.
Security built in
Trust-on-first-use host-key pinning, ProxyJump bastions, and every secret kept in your OS keychain.
Server tests
Ping, CPU / RAM / disk load benchmarks and an engine-aware database test, right from the server card.
Team server Max
Your own Mac serves its fleet to your colleagues. Grant each person the servers they may reach at read or read + write, send one invite, and their activity lands in your log. The connection is direct — no relay, no vendor in the middle. How it works
Local accounts
Users, roles and an organization profile that live on your machine — there is no cloud identity to depend on, and no password of yours on our servers.
Themes & fonts
A dozen colour themes and adjustable fonts — the whole cockpit reskins to your taste, light or dark.
AI & Docker Next release
Connect AI providers and discover Docker containers into the fleet — reach a container's shell like any server. Both follow the first release.
Per-seat pricing, billed by Apple
Every plan reaches every server over SSH, VNC and RDP. Free caps how many servers you keep, not what you can do with them. Both paid plans start with a 14-day free trial.
- Up to 5 servers
- SSH, VNC & RDP
- Live metrics, tags & bulk run
- Encrypted export / import
- Cloudflare, scheduling, patching
- Support tickets
- Everything in Free, unlimited servers
- Cloudflare DNS & firewall
- Scheduler & patch management
- Logs & email alerts
- One support ticket a month
- Everything in Pro
- Team server — your Mac serves the fleet
- Teammates with read / write roles
- Their activity in your own log
- One support ticket a month
Joining a colleague’s team?
You do not need a plan or a seat. Install the same app everyone else does, choose Connect to a team server on the sign-in screen, and paste the invite they sent you.
Teammates do not need a seat. On Max, the people you invite install the app free and operate the servers you grant them. Only the person running the team server pays.
Extra support tickets are $5 each, or five for $25 — the same price per ticket, just fewer trips through the App Store. They never expire. Free includes none.
Yearly billing saves 23%. Everything is charged by Apple in your own currency; manage or cancel from System Settings › Apple ID › Subscriptions. We never see a card number.
Documentation
How the app works, what it does with your data, and how to put a team on it.
Getting started
Install Work Cockpit from the Mac App Store and open it. The first launch asks you to create an account — that account lives on your Mac. There is no cloud sign-up, no email confirmation, and no password of yours on our servers.
Only the organisation details you type at that point ever reach us, and only if you later open a support ticket.
Forgotten the password? There is no reset link, because there is nobody to reset it. The account is local, so start over: quit the app, remove its data folder, and register again. Your servers come back from an export if you kept one.
Adding servers
Servers › Add server. A server is a name, an address, and one or more ways in:
- SSH — terminal, file upload, metrics, patching, scheduled commands.
- VNC and RDP — a screen, for the machines that need one.
Credentials are stored in the macOS Keychain, never in the app’s own files. The first time you reach a host over SSH its key is pinned; if that key ever changes, the connection is refused rather than quietly accepted.
Free keeps up to five servers. The cap is on adding — an installation that is already over it keeps everything and is simply blocked from adding more.
Moving between machines
Settings › Backup & transfer writes one encrypted file with everything in it: servers, credentials, host-key pins, settings. Carry it to another Mac, import it there, and it is the same installation.
The file is sealed with a password you choose (Argon2id + XChaCha20-Poly1305) or to a certificate you hold. A wrong password and a tampered file fail the same way, with one message that does not say which — a file that told you which half was wrong would be a file that helps someone guess.
This is also how you get your fleet onto an iPhone: export on the desktop, import on the phone. Mobile starts empty on purpose.
Team server Max
On the Max plan your Mac can serve its fleet to your colleagues. It is the part of this product that has no equivalent elsewhere: teams normally get this by pushing their infrastructure through a vendor’s cloud. Here the server is your machine, and we are not in the path at all.
- Team › Members — create a user for the person.
- Team › Team server — set the address colleagues should connect to, then Start.
- Grant — pick the servers that person may reach, and whether they get read or read + write.
- Invite — copy the four lines it gives you and send them however you normally talk.
About the port
The default is 8443, not 443. A sandboxed Mac app is not allowed to bind a port below 1024 — that needs administrator rights no App Store app has. If you want 443 reachable from outside, forward 443 to 8443 on your router; the connection is TLS either way.
Read and write
Read shows the server, its metrics and its logs. Write also opens sessions, uploads files and runs commands.
Revoking access
Revoke a device and it stops working the next time it connects. It does not depend on the person cooperating: every sync stamps a 14-day expiry, so a machine that cannot reach your Cockpit drops the servers you gave it and keeps only its own.
Joining a team
If a colleague runs the team server, you do not need a paid plan and you do not need a seat. Install Work Cockpit from the App Store like everyone else — there is no separate build. On the sign-in screen choose Connect to a team server instead of registering, and paste the four lines they sent you:
Address: ops.example.com Port: 8443 Invite code: ABCD-EFGH-JKMN Fingerprint: 0b30557a9fc4e90e…
Add the username and password they created for you and press Connect. The app enrols, makes that username and password your local sign-in, and pulls down the servers and credentials you were granted — there is nothing to export and nothing to import. The transfer is encrypted end to end between the two machines.
The invite works once. The fingerprint is what stops someone else answering in your colleague’s place, and the code is what stops a stranger enrolling — neither is much use without the other. From then on you sign in with that same username and password, even with the team server unreachable.
Servers you added yourself stay yours. Leaving the team removes only what the team gave you.
What leaves your machine
Short version: your infrastructure does not.
- Never sent: server addresses, hostnames, SSH keys, passwords, terminal output, metrics, logs.
- No cloud channel between installations. Two copies of this app do not talk through us — a team connects directly to the machine serving it.
- Sent, if you register: the organisation details you type. Nothing else.
- Sent, if you open a ticket: the subject and description you write, plus that organisation name. We will never ask for a credential, and a ticket containing one is deleted rather than read.
Credentials do travel to the teammates you grant them to — that is what makes the team feature work, and it happens only because you chose that person and those servers. They go from your machine to theirs, directly. We never hold them and never see them.
Plans & billing
Everything is sold through Apple. There is no card form on this site, no invoice from us, and no licence key to keep safe — your plan follows your Apple ID, so a second Mac restores it rather than buying it again.
Both paid plans start with a 14-day free trial. Yearly billing saves 23%. Cancel any time from System Settings › Apple ID › Subscriptions.
If a subscription lapses, nothing is deleted. The app keeps every server you have and simply stops letting you add more, exactly as the Free tier does.
Installed the app directly rather than from the App Store? That copy cannot buy a plan — it hides the plan screen instead of showing a button that cannot work. It is the Free tier, which is all a teammate needs.
Support tickets
Pro and Max include one ticket per calendar month. Free includes none. Extra tickets are $5 each or five for $25 — the same price per ticket, bought in one go rather than five — and they never expire.
Open one from Support in the app. A ticket carries a subject and a description and nothing else; if we cannot answer without knowing more, we will ask you a question, not ask for access.