Working
Tunnels and other connections
Forward ports, jump through other servers, connect to serial devices, preview a web app running on a server, and import servers and containers automatically.
Port forwarding
Every connected session can open a local port forward: open Port forwarding
(More menu, command palette, or its shortcut) and give it a local port and a destination
host and port. Synapse listens on 127.0.0.1 on your computer and forwards
through the session (ssh -L); the tunnel stops when the session closes. Active
tunnels are listed with a live status and a Stop button.
Advanced tunnels
Switch on the Advanced tunnels service for two more forwarding types and tunnels that start on their own:
| Type | What it does |
|---|---|
| Remote (-R) | The server listens on a port and forwards each connection back to a host and port on your side. Useful for letting something on the server reach a service on your computer. |
| SOCKS (-D) | Starts a SOCKS5 proxy on your computer; point a browser or tool at it and its connections leave from the server. |
Saved tunnels live in a host's Advanced settings: pick a type, fill in its ports, and turn on "Start when connected" to have it come up automatically every time you connect to that host. If the session carrying an auto-started tunnel closes, Synapse moves it to another open session on the same host rather than dropping it.
X11 forwarding is a per-host toggle that shows graphical programs from the
server on your computer. On Windows you need an X server such as VcXsrv or X410 running;
set its address once in Settings (default 127.0.0.1:6000).
Advanced SSH
The Advanced SSH service adds a set of options for more complex networks and hardware keys, in the host editor's Advanced section:
- Jump hosts - chain through other saved hosts in order (ProxyJump), checking each host key along the way.
- Proxy - connect through an HTTP (CONNECT) or SOCKS5 proxy, with its own optional credentials.
- Agent forwarding - lets the server use the keys in your local SSH agent or Pageant. Synapse warns that anyone with root on that server could then use your keys while you're connected, so only turn it on for servers you trust.
- Shared identities - manage reusable username/password/key combinations in the Identities window and assign one to a host, or to a whole host group, instead of the host's own credentials.
- Per-host environment variables - sent when the session starts (most servers only accept
LANGandLC_*unless configured otherwise). - Login script - a sequence of "wait for this text, then send this command" steps, each with its own timeout, useful for menus or prompts a plain shell doesn't expect.
- SSH certificates - paste a signed
-cert.pubfor the host, or place one next to a vault key and it's picked up automatically.
Security keys (FIDO2) work without a toggle: when a host's key is a
sk- hardware-backed key, Synapse automatically connects through System OpenSSH
instead of the built-in engine, since that's what talks to the hardware key. A notice tells
you when this happens, and that proxy, environment, login-script and certificate options
are skipped in that case (they need the built-in engine).
Open a session's Connection security details to see, for every hop, the key exchange, cipher, MAC, host key and fingerprint, whether strict key exchange is in use, and whether the connection used a post-quantum or classical key exchange.
Serial and Telnet
Covered in Terminal features: the Serial and Telnet service adds a Protocol choice to the host editor for connecting to network gear and other devices directly, rather than over SSH.
Web preview
The Web preview service opens a web app running on a server in a built-in browser window, without leaving Synapse:
- Choose Server port (pick the session, a port, a path and the host name to use on the server side) or Address (any URL).
- Pick a window size - Desktop, Laptop, Tablet, Phone or Small phone presets.
- Open the preview. For a server port, Synapse starts a local port forward for you automatically, so the app opens at a local address that reaches the server.
The preview window has its own address bar, back, forward and reload, a device-size picker, and buttons to save a screenshot or send a screenshot straight to Relay - handy for asking the AI about something you're looking at. "System browser" opens the same address in your normal browser instead.
Cloud and containers
The Cloud and containers service finds servers and containers for you instead of adding them by hand:
- Import from cloud providers (in the host import menu) lists your servers from AWS EC2, DigitalOcean, Hetzner Cloud, Linode or Vultr using an API credential you add to the vault, and imports the ones you tick as saved hosts. Importing again shows which imported hosts changed address, are no longer found, or came back, so you can review and apply just those changes.
- A Docker tab in a connected session's side panel lists running Docker containers and Kubernetes pods on that host, with a button to open a shell inside any of them in a new pane.