Skip to content
User Guide

Resource → SSH Terminal

An interactive SSH terminal opens in its own connection pin. The session runs entirely in the browser and is streamed through a MisterShell worker in the resource’s location — no direct network path from your workstation to the device is required.

How an interactive session connects

Click the Connect terminal icon beside the resource in the location tree. Connection options appear when needed, then the session opens in its own pin. No snapshot is required.

Each pin keeps its own terminal, history, and AI context. Switch between pins or browse other pages while your sessions stay open. Closing a live connection pin asks for confirmation and ends only that session; other connections stay open. Removing a resource-page pin does not close its separate connection pins.

Shells share a limit of three per user/resource by default, across browser and native SSH sessions and all shell modes. An administrator can change this limit. Select an existing connection pin to return to it without opening another shell.

For access from your own terminal, see SSH gateway and Text UI.

What you can do

  • Open a live shell session on the resource.
  • Enable AI assistance to get real-time guidance as you type.
  • Share the session with teammates or external guests, with in-session chat.
  • Disconnect cleanly when you are done.

Choosing an SSH resource type

During onboarding, choose SSH as the connection method and either detect the type automatically or select the expected type. Palo Alto Panorama is supported separately from Palo Alto firewalls. If automatic detection cannot identify a specific supported system after a successful connection, MisterShell uses Generic SSH. An explicitly selected native type must match the target; selecting Generic SSH keeps it generic.

Detection happens during onboarding. Later sessions, checks, and snapshots use the saved type, without repeating automatic discovery.

SSH host key verification

Strict Host Key Verification checks the server’s SSH host key against the saved fingerprint. It is enabled by default for new SSH resources. During onboarding, review the observed fingerprint before creating the resource; creation saves it for later connections.

A changed host key appears as Invalid signature. This is separate from Identity mismatch, which compares the resource’s external identifier with the stored identity. A device can accept your credentials while still presenting an unexpected key or identity.

To restore verification on a resource showing Signature not configured, or review an intentional host-key replacement:

  1. Open the resource’s ⋮ menu → Edit.
  2. Enable Strict Host Key Verification if it is off, then click Verify.
  3. Review the observed fingerprint and any expected fingerprint. Confirm the observed key through a trusted source, such as the device administrator.
  4. If an acceptance action is offered and the key is correct, select Accept new signature, then click Save changes.
  5. The next manual or scheduled check verifies the saved key. Saving the acceptance itself does not run another live check or mark unperformed stages as passed.

If no candidate key was observed, resolve the connection problem and re-check first. See editing and re-checking resources for verification expiry and identity acceptance.

Common tasks

Start a session

  1. Click the Connect terminal icon beside the resource in the location tree.
  2. The terminal panel activates as soon as the remote prompt is received.

If the resource’s credential is configured to require your personal credential for interactive sessions, you can save your credentials under Account → Personal Vault. If no saved credential for the template exists, Authentication required lets you enter credentials or choose a compatible personal/team entry with Use vault. See providing credentials when connecting.

End a session

Click Disconnect. The remote session is closed cleanly and the terminal is frozen in a dimmed state. Use Connect in the location tree to start a fresh session.

Copy terminal text

Click Copy all, beside Invite, to copy the current terminal text and retained scrollback to your clipboard. No selection is required. Formatting codes are excluded, and wrapped lines are joined. Output discarded by the scrollback limit is no longer available; full-screen applications copy their current screen.

The same button is available in every browser shell, including database, Kubernetes, AWS and Azure sessions.

Copy-on-select continues to work as before. Copy all reports whether the copy succeeded. Browser clipboard access requires HTTPS (or localhost) and permission from your browser.

Enable AI Assistance

Once a session is connected, an Enable AI Assistant button appears (purple). Clicking it attaches an AI agent to your session:

  • The agent sees what you type and the command output.
  • It surfaces hints and suggestions in a chat overlay beside the terminal.
  • Click the same button (now red, Disable AI Assistant) to detach the agent.

The button appears once the session is connected, you have permission to use AI, and the built-in Session Assist agent is functional — that is, it has an AI model to run on (its own or the workspace default). If it is missing, ask your administrator to assign a model under Settings → AI → Agents.

Share the session

Once connected, open the Invite menu in the toolbar to share the live session with internal users or external guests. In a text shell every participant can both watch and type — everyone shares the same terminal — and a collapsible chat pane lets you coordinate. Closing your session ends the shared view for everyone.

See Sharing a session & external guests for the full walkthrough — inviting internal users, one-time guest join links, and removing participants. (Single-controller hand-off applies to graphical sessions — RDP, VNC, Web — not text shells.)

Conditions and blockers

  • You do not have permission to open SSH sessions — you lack the app.resources.execute permission.
  • Authentication required — enter credentials or choose a compatible personal/team entry with Use vault. To avoid the prompt for future connections, save your credential for the template in Account → Personal Vault.

Permissions

  • Open an interactive session: app.resources.execute.
  • Share a session and invite participants: app.session.execute.
  • Attach AI assistance: app.ai.execute and a configured Session Assist agent with an available model.