Work Cockpit Mac
App Store soon
Windows
Soon
iOS
Soon
Android
Soon
Docs Get the app

Work Cockpit

Work Cockpit is a desktop application for system administrators. It puts a whole fleet of servers in one window: connect over SSH, VNC or RDP, watch live CPU, memory and disk, manage Cloudflare DNS and firewall settings, schedule routine commands, scan for operating-system updates, and keep an audit log of what was run where. It runs on your own Mac — there is no account of ours in the middle, and your servers and credentials never reach our servers.

The cockpit

Your whole fleet,
in one window.

Add a server and reach it over SSH, VNC or RDP — with live CPU, memory and disk right on the card. No browser tab per box.

SSHVNCRDPLive metrics
Work Cockpit — Servers
upweb-01203.0.113.10
CPU24%
MEM41%
DISK33%
updb-01203.0.113.11
CPU56%
MEM45%
DISK38%
Proxmox control plane · next release

Every VM, without a
guest credential.

Point Work Cockpit at your Proxmox hosts and every guest lands in the grid with live metrics served by the hypervisor itself, many named clusters side by side. Built and validated against a real cluster — it ships in the release after this one.

Multi-PVEAuto tagsHypervisor info
Work Cockpit — DC1 Proxmox
runningmail-stalwartvmid 119
pveDC1 Proxmox
CPU12%
MEM63%
stoppedwp-t130vmid 130
pveDC1 Proxmox
Cloudflare

DNS and edge, in
the cockpit.

Browse zones, edit records, flip SSL modes and run batch operations across many domains at once — without leaving the app.

ZonesDNS recordsSSL / WAFBatch ops
Work Cockpit — Cloudflare
example.comSSL full
A · www · 203.0.113.10 · proxied
shop.ioWAF on
CNAME · api · shop.io · proxied
Automation

Schedule the routine,
patch on your terms.

Run commands and Cloudflare changes on a schedule, and scan every server for pending OS updates by package manager — with a badge on the card the moment updates land.

SchedulerPatch scanapt · dnf · winget
Work Cockpit — Patches
web-01! 5 updates
apt · 2 security · reboot required
Nightly log rotatedaily 03:30
2 servers · last run ok
Secure by default

Encrypted support,
pinned host keys.

One-time technical-support sessions run over a TLS connection pinned by the token itself — no relay, no cloud. Host keys are trust-on-first-use pinned, secrets live in your OS keychain.

TLS-pinned supportKnown-hostsKeychainProxyJump
Work Cockpit — Technical Support
● TLS session established — cert pinned
$ uptime
14:22:01 up 37 days, load 0.18 0.21 0.19
$  

Everything in one control room

A desktop app for the whole job — reach, monitor, operate and secure your fleet without a dozen tools.

Server fleet

Cards with live CPU / memory / disk, grouped and tag-filtered, with SSH, VNC and RDP built in.

Proxmox control plane Next release

Import VMs from many named PVE clusters; metrics and hypervisor info come from the host, no guest login. Built and tested against a real cluster — shipping after the first release.

Cloudflare

Zones, DNS records, SSL modes, WAF and always-HTTPS — plus batch operations across domains.

Scheduler

Schedule server commands and Cloudflare changes — once, on an interval, daily or weekly — with a run history.

Patch management

Per-server update scans by package manager (apt, dnf, zypper, apk, pacman, brew, winget) with a badge and one-click apply.

Logs & email alerts

A local event log for everything the app does, with rules that email you when something crosses a threshold.

Encrypted support

One-time, TLS-pinned remote-shell sessions with a full PTY — direct and peer-to-peer, never through a cloud relay.

Security built in

Trust-on-first-use host-key pinning, ProxyJump bastions, and every secret kept in your OS keychain.

Server tests

Ping, CPU / RAM / disk load benchmarks and an engine-aware database test, right from the server card.

Team server Max

Your own Mac serves its fleet to your colleagues. Grant each person the servers they may reach at read or read + write, send one invite, and their activity lands in your log. The connection is direct — no relay, no vendor in the middle. How it works

Local accounts

Users, roles and an organization profile that live on your machine — there is no cloud identity to depend on, and no password of yours on our servers.

Themes & fonts

A dozen colour themes and adjustable fonts — the whole cockpit reskins to your taste, light or dark.

AI & Docker Next release

Connect AI providers and discover Docker containers into the fleet — reach a container's shell like any server. Both follow the first release.

Per-seat pricing, billed by Apple

Every plan reaches every server over SSH, VNC and RDP. Free caps how many servers you keep, not what you can do with them. Both paid plans start with a 14-day free trial.

Free
$0
The whole cockpit, for a handful of machines.
  • Up to 5 servers
  • SSH, VNC & RDP
  • Live metrics, tags & bulk run
  • Encrypted export / import
  • Cloudflare, scheduling, patching
  • Support tickets
Get it from the App Store
Pro
$7 / month
$64.90 a year — two months off. Per seat.
  • Everything in Free, unlimited servers
  • Cloudflare DNS & firewall
  • Scheduler & patch management
  • Logs & email alerts
  • Domain expiry warnings
Start the 14-day trial
Max
$13 / month
$119.99 a year. Per seat, for teams.
  • Everything in Pro
  • Team server — your Mac serves the fleet
  • Teammates with read / write roles
  • Their activity in your own log
  • Use one subscription on all your machines
Start the 14-day trial

Joining a colleague’s team?

You do not need a plan or a seat. Install the same app everyone else does, choose Connect to a team server on the sign-in screen, and paste the invite they sent you.

Teammates do not need a seat. On Max, the people you invite install the app free and operate the servers you grant them. Only the person running the team server pays.

Support tickets are separate from the plan. No tier includes one: they are $5 each, or five for $25 — the same price per ticket, just fewer trips through the App Store. They never expire, and they are bought inside the app.

Yearly billing saves 23%. Everything is charged by Apple in your own currency; manage or cancel from System Settings › Apple ID › Subscriptions. We never see a card number.

Documentation

How the app works, what it does with your data, and how to put a team on it.

Getting started

Install Work Cockpit from the Mac App Store and open it. The first launch asks you to add an account — that account lives on your Mac. There is no cloud sign-up, no email confirmation, and no password of yours on our servers.

Only the organisation details you type at that point ever reach us, and only if you later open a support ticket.

Forgotten the password? There is no reset link, because there is nobody to reset it. The account is local, so start over: quit the app, remove its data folder, and register again. Your servers come back from an export if you kept one.

Adding servers

Servers › Add server. A server is a name, an address, and one or more ways in:

  • SSH — terminal, file upload, metrics, patching, scheduled commands.
  • VNC and RDP — a screen, for the machines that need one.

Credentials are stored in the macOS Keychain, never in the app’s own files. The first time you reach a host over SSH its key is pinned; if that key ever changes, the connection is refused rather than quietly accepted.

Free keeps up to five servers. The cap is on adding — an installation that is already over it keeps everything and is simply blocked from adding more.

Moving between machines

The quick way: Settings › Backup & transferMove to another device. The app seals everything and shows a QR plus a 25-character code; on the new device choose Arriving from another device and type it. The code is the key — it never reaches our servers, works once, and expires in 15 minutes. Afterwards the same username and password work on the new device, because your accounts travel inside the bundle.

The file way still exists: Backup & transfer writes one encrypted file with everything in it — servers, credentials, host-key pins, settings. Carry it anywhere, import it, and it is the same installation.

The file is sealed with a password you choose (Argon2id + XChaCha20-Poly1305) or to a certificate you hold. A wrong password and a tampered file fail the same way, with one message that does not say which — a file that told you which half was wrong would be a file that helps someone guess.

This is also how you get your fleet onto an iPhone: show a code on the Mac, type it on the phone. Mobile starts empty on purpose — nothing of yours lives in a cloud to pre-fill it.

One subscription, your own machines

The iPhone app and the Mac App Store app are one purchase — subscribe on either and the other is already paid up, at no extra cost. Nothing to do.

The direct download is the exception, because a copy installed outside the App Store has no receipt to read. Pair it once:

  1. In the App Store copy: Settings › Plan › Use this subscription on another computer. It shows a six-character code, good for ten minutes.
  2. In the direct copy: Settings › Plan › I bought this on the App Store. Type the code.

That is the whole thing. The paired machine checks Apple’s own signature on the purchase before it unlocks anything, and it keeps up with renewals by itself as long as you open the App Store copy now and then — you never type a code twice.

What travels is Apple’s receipt: a transaction and a product. Not a server, not an address, not a credential.

Team server Max

On the Max plan your Mac can serve its fleet to your colleagues. It is the part of this product that has no equivalent elsewhere: teams normally get this by pushing their infrastructure through a vendor’s cloud. Here the server is your machine, and we are not in the path at all.

  1. Team › Members — add a user for the person.
  2. Team › Team server — set the address colleagues should connect to, then Start.
  3. Grant — pick the servers that person may reach, and whether they get read or read + write.
  4. Invite — copy the four lines it gives you and send them however you normally talk.

About the port

The default is 8443, not 443. A sandboxed Mac app is not allowed to bind a port below 1024 — that needs administrator rights no App Store app has. If you want 443 reachable from outside, forward 443 to 8443 on your router; the connection is TLS either way.

Read and write

Read shows the server, its metrics and its logs. Write also opens sessions, uploads files and runs commands.

Revoking access

Revoke a device and it stops working the next time it connects. It does not depend on the person cooperating: every sync stamps a 14-day expiry, so a machine that cannot reach your Cockpit drops the servers you gave it and keeps only its own.

Joining a team

If a colleague runs the team server, you do not need a paid plan and you do not need a seat. Install Work Cockpit from the App Store like everyone else — there is no separate build. On the sign-in screen choose Connect to a team server instead of registering, and paste the four lines they sent you:

Address:     ops.example.com
Port:        8443
Invite code: ABCD-EFGH-JKMN
Fingerprint: 0b30557a9fc4e90e…

Add the username and password they added for you and press Connect. The app enrols, makes that username and password your local sign-in, and pulls down the servers and credentials you were granted — there is nothing to export and nothing to import. The transfer is encrypted end to end between the two machines.

The invite works once. The fingerprint is what stops someone else answering in your colleague’s place, and the code is what stops a stranger enrolling — neither is much use without the other. From then on you sign in with that same username and password, even with the team server unreachable.

Servers you added yourself stay yours. Leaving the team removes only what the team gave you.

What leaves your machine

Short version: your infrastructure does not.

  • Never sent: server addresses, hostnames, SSH keys, passwords, terminal output, metrics, logs.
  • No cloud channel between installations. Two copies of this app do not talk through us — a team connects directly to the machine serving it.
  • Sent, if you register: the organisation details you type. Nothing else.
  • Sent, if you open a ticket: the subject and description you write, plus that organisation name. We will never ask for a credential, and a ticket containing one is deleted rather than read.

Credentials do travel to the teammates you grant them to — that is what makes the team feature work, and it happens only because you chose that person and those servers. They go from your machine to theirs, directly. We never hold them and never see them.

Plans & billing

Everything is sold through Apple. There is no card form on this site, no invoice from us, and no licence key to keep safe — your plan follows your Apple ID, so a second Mac restores it rather than buying it again.

Both paid plans start with a 14-day free trial. Yearly billing saves 23%. Cancel any time from System Settings › Apple ID › Subscriptions.

If a subscription lapses, nothing is deleted. The app keeps every server you have and simply stops letting you add more, exactly as the Free tier does.

Installed the app directly rather than from the App Store? That copy cannot buy a plan — it hides the plan screen instead of showing a button that cannot work. It is the Free tier, which is all a teammate needs.

Support tickets

Tickets are bought, not included: no plan comes with one. They are $5 each or five for $25 — the same price per ticket, bought in one go rather than five — and they never expire, so an unused one is still there next year.

Open one from Support in the app. A ticket carries a subject and a description and nothing else; if we cannot answer without knowing more, we will ask you a question, not ask for access.

Work Cockpit

Work Cockpit is a desktop application for system administrators. It puts a whole fleet of servers in one window: connect over SSH, VNC or RDP, watch live CPU, memory and disk, manage Cloudflare DNS and firewall settings, schedule routine commands, scan for operating-system updates, and keep an audit log of what was run where. It runs on your own Mac — there is no account of ours in the middle, and your servers and credentials never reach our servers.

How Work Cockpit uses Google Drive. Connecting Google Drive is optional. Its only purpose is to keep a copy of your encrypted backup bundle — your server list, settings and credentials, sealed with a password only you hold — somewhere other than the machine you are working on. The app requests the drive.file scope, which grants access to only the files Work Cockpit itself creates; it cannot list, open or search anything else in your Drive. Uploads go straight from your machine to your Drive and never pass through us, and you can disconnect at any time in the app or at your Google account.