More than 30 protocols turn one app into an operations console
uniTerm puts SSH, Telnet, Mosh, serial, raw TCP, file transfer, remote desktop, databases, and container tools behind one Wails desktop interface. The point is consolidation. A developer can open an SSH shell, browse SFTP files, inspect PostgreSQL, and view Kubernetes resources without keeping separate connection lists in four clients. The README documents Windows, macOS, Linux, and Android builds, plus a nine-language interface.
Breadth also creates a large trust surface. Saved identities can hold passwords, private-key paths, or pasted private-key text. Cloud sync can move encrypted connection records, AI settings, tunnels, identities, and proxies through a private Git repository or WebDAV. The guide says sync uses AES-256-GCM, derives a key with PBKDF2-SHA256, and stores that derived key in the operating-system keychain. You still control the repository token, master password, and remote accounts.
The 2-second build was cleaner than the 29-package test run
commit 6542f4f contained 803 files, about 169,022 lines of source, and occupied 10 MB before installation. Our scan found 5 CI workflow files, no Dockerfile, and no top-level tests directory. Go tests live beside the packages they cover, so the missing directory does not mean there are no tests. The codebase spans a Go backend and a Vue 3 frontend inside a Wails 3 desktop app.
The source instructions ask for Go 1.26 or newer, Node.js 20+, and Wails 3.0.0 beta 27. Linux builds need GTK 3 and WebKitGTK 4.1 development packages. Android work adds JDK 21, platform 35, build tools 35.0.0, and NDK 26.3.11579264. Our supplied sandbox image used Go 1.24 and still completed its measured install and build, but the documented version remains the safer baseline for contributors.
What happened when we ran it
Our sandbox installed commit 6542f4f in 51 seconds and added 249 packages. The build succeeded in 2 seconds. The container had 3 CPUs, 8 GB of RAM, no secrets, and no elevated privileges. Those results cover repository setup in the stated Go 1.24 Debian image. They do not test a signed installer, desktop rendering, remote servers, or an Android package.
The test command ran for 86 seconds and exited 1. Go reported 24 passing and 5 failing packages out of 29. The supplied tail shows successful packages such as backend/k8s, backend/mcp, backend/session, and backend/store. It names TestWebDAVPasswordRoundTrip under backend/sync as a failure. The other four failing package details are absent from the tail, so assigning them a cause would be guesswork.
That WebDAV name matters because release 1.10.0 added WebDAV as a cloud-sync source. It does not prove that every WebDAV account loses passwords, nor does it tell us why the round trip failed in the container. It does mean the exact checkout did not clear its available Go suite in our environment. Test Git and WebDAV recovery with disposable credentials before trusting sync with the only copy of a connection set.
MCP keeps credentials local but gives agents real shell reach
Version 1.10.0 added a loopback MCP server at 127.0.0.1, using one bearer token per client. The guide says plaintext tokens appear once, only a SHA-256 hash is stored, and every call goes to a JSONL audit log. Claude Code, Codex, Gemini CLI, and other clients can list saved SSH connections, open sessions, execute commands, poll output, interrupt work, and transfer files. Credentials stay inside uniTerm.
The default MCP policy confirms every command, connection, and transfer. Other modes confirm writes or dangerous commands, while bypass still prompts for commands classified as dangerous. A request times out as denied after 110 seconds. Local transfers are restricted to bookmarked directories, symlinks are resolved before the check, commands have a 5-minute limit, and execution concurrency is capped at 8. These are meaningful controls, but risk classification is still code that your production policy must verify.
The built-in AI assistant has a different mode table, including Bypass All, and can run up to 20 autonomous rounds by default or unlimited rounds when set to 0. It needs an Anthropic or OpenAI-compatible endpoint, model, and API key. Use confirmation on systems that matter. A polished chat sidebar does not change what a remote shell command can delete.
Unsigned binaries and hobby maintenance set the support ceiling
The v1.10.0 release shipped on October 4, 2026, the same day as the repository's last push. GitHub showed 679 stars and 46 open issues and pull requests combined, with an active pull request updated that day. The release added Android, MCP, WebDAV sync, and more container work while fixing SSH, SMB, FTP, S3, MongoDB, terminal, and Linux desktop problems. That pace shows active maintenance.
The README also calls uniTerm a personal hobby project maintained in spare time, with no commercialization or sponsorship plans. Official Windows executables are unsigned and may trigger antivirus warnings. Those facts do not make the app unsafe. They do rule out assumptions about paid support, code-signing guarantees, or a staffed response path. For personal infrastructure and a testable set of protocols, uniTerm is unusually capable. For a controlled enterprise workstation, those gaps need an explicit exception.

