Skip to content

Web SSH terminal

Web SSH opens a terminal to your instance in a browser tab. No SSH client, no key files, no port forwarding: click the button and you are at a root shell.

  • The instance is running.
  • The instance runs a Linux image. The Web SSH button only appears for running Linux instances.
  • The guest agent is installed inside the OS. Cloud images include it by default; on a hand-built image you may need to install it yourself. Web SSH uses the agent to inject a temporary key for the session.

Open the instance manage page (Compute > Instances > Manage). On the Overview tab, the Connect card has a Web SSH button next to Console. The same action is in the … menu next to the header’s Console button.

Running instance overview with the Web SSH button

  1. Click Web SSH. A new browser tab opens with a terminal.

  2. Wait for the session to connect. You land at a shell on the instance.

    Web SSH terminal in a browser tab

Sessions are created on demand and cleaned up automatically when you close the tab. Each session starts from a single-use token that expires after 15 minutes if it is not used, so open the terminal soon after you click the button.

On a KVM instance the guest agent must answer when you click Web SSH, because the platform installs its temporary key through it. If you script this through the API, see the session endpoint in the API changelog for the WebSocket URL and the failure reasons.

  • “Failed to open SSH session.” The instance is not running, the guest agent is not installed or not running inside the OS, or a firewall inside the OS blocks SSH (TCP port 22 by default). Check the agent with systemctl status qemu-guest-agent inside the OS (via the console).
  • The terminal opens then immediately disconnects. The temporary key could not be injected or the SSH daemon rejected the login. Check the SSH daemon logs inside the OS (/var/log/auth.log or journalctl -u ssh).
  • There is no Web SSH button. The instance is stopped or is not a Linux image. Use the VNC console instead.