Comparison of SSH clients
Page Module:Message box/ambox.css has no content.
This article may contain original research. (April 2026) |
Page Module:Message box/ambox.css has no content.
This article or section possibly contains original synthesis. Source material should verifiably mention and relate to the main topic. (April 2026) |
Template:Short description Script error: No such module "labelled list hatnote".
An SSH client is a software program which uses the secure shell protocol to connect to a remote computer. This article compares a selection of notable clients.
General
Page Template:Reflist/styles.css has no content.
Platform
The operating systems or virtual machines the SSH clients are designed to run on without emulation include several possibilities:
- Partial indicates that while it works, the client lacks important functionality compared to versions for other OSs but may still be under development.
The list is not exhaustive, but rather reflects the most common platforms today. Template:Sort-under
| Name | macOS | Windows | Cygwin | BSD | Linux | Solaris | OpenVMS | z/OS | AIX | HP-UX | iOS | Android | Maemo | Windows Phone |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Template:Rh| AbsoluteTelnet | No | Yes | No | No | No | No | No | No | No | No | No | No | No | ? |
| Template:Rh| Bitvise SSH Client | No | Yes | No | No | No | No | No | No | No | No | No | No | No | No |
| Template:Rh| ConnectBot | No | No | No | No | No | No | No | No | No | No | No | Yes | No | No |
| Template:Rh| Dropbear | Yes | No | Yes | Yes | Yes | Yes | ? | ? | Yes | Yes | Yes[a] | No | Yes | ? |
| Template:Rh| lsh | Yes | No | No | Partial[b] | Yes | Yes | ? | ? | No | No | No | No | No | ? |
| Template:Rh| OpenSSH[c] | Included | Included[d] | Included | Included | Included[e] | Yes | Yes | Yes | Yes | Yes | Yes[a] | Yes | Yes | ? |
| Template:Rh| PuTTY | Partial | Yes | ? | Yes | Yes | Yes | ? | ? | No | No | No | No | No | Beta |
| Template:Rh| SecureCRT | Yes | Yes | No | No | Yes | No | No | No | No | No | Yes | No | No | ? |
| Template:Rh| SmartFTP | No | Yes | No | No | No | No | No | No | No | No | No | No | No | ? |
| Template:Rh| Tera Term | No | Yes | No | No | No | No | No | No | No | No | No | No | No | ? |
| Template:Rh| TN3270 Plus | No | Yes | No | No | No | No | No | No | No | No | No | No | No | ? |
| Template:Rh| WinSCP | No | Yes | No | No | No | No | No | No | No | No | Yes[a] | No | No | ? |
| Template:Rh| wolfSSH | Yes | Yes | Yes | Yes | Yes | Yes | No | No | No | No | No | No | No | No |
| Template:Rh| ZOC Terminal | Yes | Yes | No | No | No | No | No | No | No | No | No | No | No | ? |
| Name | macOS | Windows | Cygwin | BSD | Linux | Solaris | OpenVMS | z/OS | AIX | HP-UX | iOS | Android | Maemo | Windows Phone |
Page Template:Reflist/styles.css has no content.
- ^ a b c Only for jailbroken devices.
- ^ lsh supports only one BSD platform officially, FreeBSD.
- ^ Also known as OpenBSD Secure Shell.
- ^ Included and enabled by default since windows 10 version 1803. Win32-OpenSSH can be installed as an optional component in the Windows versions before Windows 10 version 1803 to Windows 10 version 1709. Portable version can be download from Win32-OpenSSH for other versions.
- ^ The majority of Linux distributions have OpenSSH as an official package, but a few do not.
Technical
| Name | SSH1 (insecure) |
SSH2 | Additional protocols | Port forwarding and Tunneling | Session multiplexing [a] |
Kerberos | IPv6 | Terminal | SFTP/SCP | Proxy client[b] | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| TELNET | rlogin | Port forwarding |
SOCKS [c] |
VPN [d] | |||||||||
| Template:Rh| AbsoluteTelnet | Yes | Yes | Yes | No | Yes | Yes | No | Yes | Yes | Yes | Yes | Yes | SOCKS 4, 5; HTTP |
| Template:Rh| Bitvise SSH Client | No | Yes | No | No | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | SOCKS 4, 5 |
| Template:Rh| Dropbear | No | Yes | No | No | Yes | No | No | No | No | Yes | Yes | Yes | ? |
| Template:Rh| lsh | No | Yes | Yes | No | Yes | Yes | No | Yes | No | Yes | Yes | Yes | ? |
| Template:Rh| OpenSSH[e] | No[f] | Yes | No | No | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | ProxyCommand |
| Template:Rh| PuTTY | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes | Yes[g] | Yes | Yes | Yes[h] | SOCKS 4, 5; HTTP; Telnet; Local |
| Template:Rh| SecureCRT | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes | Yes | Yes | Yes | Yes | SOCKS 4, 5; HTTP; Telnet; Generic |
| Template:Rh| SmartFTP | No | Yes | Yes | No | No | No | No | No | Yes | Yes | Yes | Yes | SOCKS 4, 5; HTTP |
| Template:Rh| Tera Term | Yes | Yes | Yes | No | Yes | No | No | No | No | Yes | Yes | SCP | SOCKS 4, 5; HTTP; Telnet |
| Template:Rh| TN3270 Plus | Yes | Yes | Yes | No | No | Yes | No | Yes | No | Yes | Yes | No | SOCKS 4 |
| Template:Rh| WinSCP [i] | No[j] | Yes | No | No | limited[k] | No | No | No | Yes | Yes | simple | Yes | SOCKS 4, 5; HTTP; Telnet; Local |
| Template:Rh| wolfSSH | No | Yes | No | No | Yes | No | No | No | No | Yes | simple | Yes | No |
| Template:Rh| ZOC Terminal | Yes | Yes | Yes | Yes | Yes | Yes | No | No | Yes | Yes | Yes | Yes[l][m] | SOCKS 4; 5; HTTP; Jumpserver |
| Name | SSH1 (insecure) |
SSH2 | Additional protocols | Tunneling | Session multiplexing [a] |
Kerberos | IPv6 | Terminal | SFTP/SCP | Proxy client[b] | |||
| TELNET | rlogin | Port forwarding |
SOCKS [c] |
VPN [d] | |||||||||
Page Template:Reflist/styles.css has no content.
- ^ a b Accelerating OpenSSH connections with ControlMaster.
- ^ a b Can the SSH client connect itself through a proxy? This is distinct from offering a SOCKS proxy or port forwarding.
- ^ a b The ability for the SSH client to perform dynamic port forwarding by acting as a local SOCKS proxy.
- ^ a b The ability for the SSH client to establish a VPN, e.g. using TUN/TAP.
- ^ Also known as OpenBSD Secure Shell.
- ^ OpenSSH deleted SSH protocol version 1 support in version 7.6 (2017-10-03)
- ^ The version 0.63 supports GSSAPI. Successfully tested on Win 8 using Active Directory
- ^ The PuTTY developers provide SCP and SFTP functionality as binaries for separate download.
- ^ WinSCP bundles a number of software components including PuTTY. [1].
- ^ WinSCP Version history.
- ^ WinSCP connection tunneling.
- ^ SCP and SFTP through terminal.
- ^ SCP and SFTP according to ZOC features page.
Features
| Name | Keyboard mapping | Template:Verth | Template:Verth | Template:Verth | Template:Verth | Template:Verth | URL hyperlinking | Template:Verth | Template:Verth | Hardware encryption | Template:Verth | Template:Verth | Template:Verth | Template:Verth | Template:Verth |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Template:Rh| AbsoluteTelnet | full | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes[a] | Yes | Yes | ? | ? | ? |
| Template:Rh| Bitvise SSH Client | ? | No | No | No | Yes | Yes | No | Yes | No | ? | Partial | Yes | No | Yes | No |
| Template:Rh| OpenSSH[b] | ? | No | No | ? | Yes[c] | Yes | not native[d] | Yes | Yes | Yes | Partial[e] | No | No | ? | Yes[f] |
| Template:Rh| PuTTY | No | No[g] | No | No | Yes | Yes | No[h] | Yes | No | Yes | No | No | No | No | No[i] |
| Template:Rh| SecureCRT | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes | Yes | No | ? | ? |
| Template:Rh| SmartFTP | Partial | Yes | No | Yes | Yes | Yes | Yes | Yes | Yes | AES-NI | Yes | No | ? | ? | ? |
| Template:Rh| Tera Term | Yes | Yes | Yes | No | Yes | Yes | Yes | Yes | No | No | No | Yes | No | ? | ? |
| Template:Rh| TN3270 Plus | Yes | Yes | No | No | No | No | Yes | Yes | No | No | No | Yes | ? | ? | ? |
| Template:Rh| wolfSSH | No | No | No | No | No | Yes | No | Yes | No | Yes | Yes | No | No | No | Yes |
| Template:Rh| ZOC Terminal | full | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes[j] | No | Yes | ? | ? | Yes[k] |
Page Template:Reflist/styles.css has no content.
- ^ AbsoluteTelnet/SSH supports hardware-backed Secure Keys via FIDO2/WebAuthn (ed25519-sk and ecdsa-sk) beginning with Version 13.14. [1]
- ^ Also known as OpenBSD Secure Shell.
- ^ Only when the terminal itself supports mouse input. Most graphical ones do, e.g. xterm.
- ^ No native URL highlighting; however most graphical consoles support URL highlighting.
- ^ Validated when running OpenSSH 2.1 on Red Hat Enterprise Linux 6.2 in FIPS mode or when running OpenSSH 1.1 on Red Hat Enterprise Linux 5 in FIPS mode
- ^ OpenSSH supports the minimal certificate format since v5.4. Page Module:Citation/CS1/styles.css has no content."OpenSSH Release Notes: 5.4". OpenBSD Project. 2010-03-08. Retrieved 2021-08-30.
- ^ PuTTY does not support tabs directly, but many wrappers are available that do.
- ^ PuTTY does not support hyperlinks, but some forks of PuTTY do.
- ^ Putty v71.0 does not support OpenSSH certificates. See Ben Harris' 2016-04-21 wish.[2][3]
- ^ ZOC supports FIDO/sk keys with Version 9, see Version history and FIDO2 Instructions.[4][5]
- ^ ZOC supports OpenSSSH style CA Keys, see ZOC feature list (SSH features).[6]
Authentication key algorithms
This table lists standard authentication key algorithms implemented by SSH clients. Some SSH implementations include both server and client implementations and support custom non-standard authentication algorithms not listed in this table.
| Name | ssh-dss[a] | ssh-rsa | RSA with SHA-2 | ECDSA with SHA-2 | EdDSA | Security keys | |||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| rsa-sha2-256 | rsa-sha2-512 | ecdsa-sha2-nistp256 | ecdsa-sha2-nistp384 | ecdsa-sha2-nistp521 | ssh-ed25519 | ssh-ed448 | sk-ecdsa-sha2-nistp256 | sk-ssh-ed25519 | |||
| Template:Rh| AbsoluteTelnet | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes | Yes |
| Template:Rh| Bitvise SSH Client | ? | ? | ? | ? | ? | ? | ? | ? | ? | ||
| Template:Rh| Dropbear | Yes | Yes | Yes | No | Yes | Yes | Yes | Yes | ? | ||
| Template:Rh| lsh | ? | ? | ? | ? | ? | ? | ? | ? | ? | ||
| Template:Rh| OpenSSH[b] | Yes[c] | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes | Yes |
| Template:Rh| PuTTY | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No[d] | No[d] |
| Template:Rh| SecureCRT | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | ? | ||
| Template:Rh| SmartFTP | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No | No |
| Template:Rh| Tera Term | ? | ? | ? | ? | ? | ? | ? | ? | ? | ||
| Template:Rh| TN3270 Plus | ? | ? | ? | ? | ? | ? | ? | ? | ? | ||
| Template:Rh| WinSCP | No | Yes | Yes | Yes | Yes | Yes | Yes | ? | ? | ||
| Template:Rh| wolfSSH | No | Yes | Yes | Yes | Yes | Yes | Yes | No | No | No | No |
| Template:Rh| ZOC Terminal[e] | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes[f] | Yes[f] |
Page Template:Reflist/styles.css has no content.
- ^
ssh-dssis based on Digital Signature Algorithm which is sensitive to entropy, secrecy, and uniqueness of its random signature value. - ^ Also known as OpenBSD Secure Shell.
- ^ By default, disabled at run-time since OpenSSH 7.0 released in 2015.
- ^ a b PuTTY does not support security keys / FIDO tokens, but is supported in PuTTY-CAC
- ^ ZOC' SSH is based on OpenSSH and supports the same encryptions.
- ^ a b ZOC supports FIDO/sk keys with Version 9, see Version history and FIDO2 Instructions.[4][5]
See also
References
Page Template:Reflist/styles.css has no content.
- ^ Page Module:Citation/CS1/styles.css has no content."AbsoluteTelnet/SSH Release Notes".
- ^ Page Module:Citation/CS1/styles.css has no content."ssh2-openssh-certkeys.html".
- ^ Page Module:Citation/CS1/styles.css has no content."ssh2-openssh-certkeys".
- ^ a b Page Module:Citation/CS1/styles.css has no content."ZOC Version History".
- ^ a b Page Module:Citation/CS1/styles.css has no content."Using FIDO2/SK Keys with ZOC Terminal on Windows for Access to Linux Servers".
- ^ Page Module:Citation/CS1/styles.css has no content."ZOC Feature List (SSH)".