outstation

A terminal for when you're away from your desk.

SSH to a Mac, a Linux box, a VPS — whatever you already run — with tmux, a hardware keyboard and a font that already has your glyphs. And when the network drops, nothing is lost.

▸ get early access not released yet · iPadOS

on the iPad

the main part

It is an SSH client first.

A laptop gets warm on your lap after half an hour. An iPad doesn't.

Outstation puts your machine on the other end of the iPad, so the laptop can stay on the desk — or stay at home.

Give it a hostname, a port and a user. It connects to whatever is there — a Mac in the next room, a Linux box under the stairs, a VPS you rent by the month.

tmux is the default, not a requirement. Outstation runs tmux new -A on connect, and that is what makes what you left running still be there when you come back. Without tmux on the far end you get an ordinary shell and the shell's own tmux: command not found — usable, but nothing survives the connection dropping. Installing tmux is one command.

The key is generated on the iPad and cannot leave it. Outstation shows you the public half as one authorized_keys line; you paste that in once, and the private half stays in the Secure Enclave behind Face ID, where it was made.

  • a P-256 key made in the Secure Enclave — generated on the device, and not exportable from it
  • the machine's host key pinned on first connect and checked every time after, with no “accept once”
  • several machines saved and named, switched from the status rail — one of them live at a time
  • tmux new -A on connect, so what you left running at your desk is what you get back at the gate

saved

studio :22

lucas@studio.local

live
vps :2222

deploy@vps.example.net

saved
homelab :22

me@homelab.lan

saved

Machines you have saved, switched from the status rail. One connection at a time; the rest are entries, not connections. What you left running keeps running on the machine — the tmux server owns the session and the iPad is only a view of it.

what you type into

A real terminal, not a text box with a font.

nvim behaves. htop redraws. Truecolor is truecolor, the alternate screen works, and output streams without tearing because Outstation advertises synchronized output and tmux uses it.

The font ships inside the app, because iPadOS has no font directory a terminal can rely on: FiraCode Nerd Font Mono, regular and bold. Powerline separators, branch marks and devicons render on an iPad that has never seen your dotfiles — and every one of them is exactly one cell wide, because a character grid has only one legal width.

  • the whole Ctrl table, Esc, Shift-Tab, the F-keys, and arrows that honour application-cursor mode
  • arrows and Tab claimed with priority, so iPadOS's focus system cannot take them off you
  • Option sends Meta by default, so M-b and M-f work in readline
  • a twelve-key accessory bar with a sticky Ctrl, for when the keyboard is the on-screen one
  • pinch to change the type size mid-session; the far end is told the new size

the font

FiraCode Nerd Font Mono 3.4.0, bundled — coverage asserted in the suite
powerline, U+E0A0–E0A34 / 4
powerline extra, U+E0B0–E0C825 / 25
icons, U+F000–F2FF768 / 768
devicons, U+E5FA–E6B7190 / 190

Along the bottom is the on-screen accessory row — twelve keys, with Ctrl latched for the next one. At 13 pt a W, an i, a powerline separator and a Nerd Font icon all advance 8.000 pt, which is the difference between a grid and a paragraph.

the other mode

Dispatch draws every session as a card.

Turn Dispatch on for a machine and you stop getting one terminal. Outstation speaks tmux's control protocol over the same SSH connection and draws the sessions itself: a card each, what is running in it, and which ones have printed something in the last couple of seconds. tmux keeps the sessions and the iPad draws them — and they are the machine's sessions, not the iPad's.

It is a board for whatever you are running: builds, editors, shells, agents — started, renamed and closed from the board itself. The agent cards light up for Claude Code today. Its hooks run inside the pane, so a session already knows which pane it belongs to, and the card shows the question it is stuck on, not just that it is stuck. Everything else runs fine and stays quiet.

  • a per-machine setting, off until you turn it on — off, you get one plain terminal
  • a card per session: what is running, how many panes, what it wants
  • the pending question, quoted, before you switch to it
  • panes placed from tmux's own layout tree, not guessed
  • needs tmux 3.0 or newer on the machine you connect to

the board

claude 1

Claude is waiting for you

“Run the migration against prod?”

80×24
dev 2

2 panes · zsh, node

80×2480×23
notes 3

1 pane · nvim

162×48

A grid, not a tab bar — because that is the shape of a long-lived session: three or four things you keep running on the machine for weeks, and now and then one of them wants an answer.

getting to it

You probably already have a way in.

on the same network
Turn on remote login. That is the entire setup.
a machine with a public address
A VPS already has one. Type it in; there is nothing else to do.
a tunnel you already run
Tailscale, a Cloudflare Tunnel. Outstation is an SSH client, so it reaches your machine through whichever one you have.
Outstation Connect
The one being built: for a machine with no public address and no tunnel, behind a router you would rather not open. A helper on the machine holds a single outbound connection, so nothing of yours ever listens on the internet, and the pairing identifies the machine so there is no address to type. It is not finished — the relay is live and carries real SSH, but no iPad has completed a connection through it yet. It is meant to ship with the first release; until it does, one of the three above will get you in.

No port forwarding. No dynamic DNS. Nothing else to install on the iPad to reach a machine of your own.

what we can't see

Plenty of products promise not to look. These are the reasons we could not, written as properties of the thing rather than promises about it.

  1. Two pins, neither of them ours

    The machine's host key is pinned on the iPad on first connect, and there is deliberately no “accept once” button. Pair through Connect and the fingerprint travels with the pairing, so the iPad knows the machine's key before it ever connects.

  2. The agent dials 127.0.0.1, and that is compiled in

    The helper on your machine connects to its own SSH port and nothing else. It is not a setting, because a destination list a server can influence is an open proxy with extra steps — and it is why your sshd never has to listen on the network at all.

  3. An account could not unlock anything

    The key that reaches your machine is made in the iPad's Secure Enclave and cannot leave it. Whatever we do or do not ask you to sign up for, that key is not something we could ever be holding.

  4. Deliberately not a VPN

    Outstation creates no system tunnel and touches nothing in your device's network configuration. No traffic but its own is affected, which is how it should be for a terminal.

on its own

And it doesn't always need another machine.

An outstation is a post you connect to and a place that runs on its own. Outstation carries a Linux userland on the iPad itself — Alpine on aarch64, booting to a shell faster than the animation that reveals it. node, npm, git and python all run.

A browser beside the terminal

Start a dev server in that shell and open Preview: a browser panel next to the terminal, pointed at localhost:3000. Type a bare port and it works it out. Nothing is tunnelled and nothing is forwarded, because there is nothing to forward across — the Linux side runs inside the app and they share one loopback, so the page is simply there. A login that redirects back to localhost lands in the same panel.

This half installs outside the App Store. Its emulator core is GPLv3, which Apple's terms cannot accept, so it ships as a separate build you install yourself. The App Store app is the terminal and the link. Preview belongs to this half — it shows this iPad's own dev servers, never a remote machine's.

preview

The Linux side is threads inside the app, and a guest process that binds a port opens a real listening socket on the iPad's own loopback. That is the whole mechanism: the dev server and the panel showing it are one process apart.
iPad Pro 11-inch (M5), iPadOS 26.5
cold boot to a shell52 ms
emulation overhead14× native, median
md5sum1.0× native
directory traversal, offloaded99× faster
app size, this build~40 MB

Measured on hardware, not estimated. The slow parts of the guest — searching a tree, walking directories — are handed to native code and measured against themselves. Preview has no row: it is built and tested, but it has only ever run in the simulator.

Early access

Outstation isn't out yet. Leave an address and you'll get one email, when there is a build to install.

One message, then nothing. No list, no sequence, no partners. This site sets no cookies and loads nothing from anyone else.

Already have the agent? Setting it up walks the whole path, from the installer to a session on the iPad.

Found a vulnerability, or need to send a notice? Security and abuse — or security@quirl.co.

asked already

Which iPad?
Any iPad running iPadOS 18 or newer.
Is there an iPhone version?
No. It is built around the iPad's screen and a hardware keyboard; shrinking that to a phone would make it a worse, different app.
What can I connect to?
Anything you can SSH into — a Mac, a Linux server, a VPS, a homelab box; no Mac required anywhere. It runs tmux new -A on connect, so the session outlives you closing the iPad. Without tmux on the far end you still get a shell, but a fresh one every time the connection drops, and today Outstation does not warn you about that.
What is Dispatch?
A per-machine setting. Off, you get one terminal, exactly as any SSH client would. On, Outstation talks to tmux directly and draws the machine's sessions itself — a grid of cards instead of a screen. It ships off; you turn it on per machine.
Can I use my existing SSH key?
No. Outstation makes its own P-256 key in the Secure Enclave, where it cannot be read or copied out — that is the point of it. Its public key goes into authorized_keys once, beside the ones already there.
Can I connect to two machines at once?
Not yet. Several can be saved and switched between; one is live at a time.
Do I have to use your relay?
No, and today you cannot — it is the part still being built. It is meant to land with the first release; the other ways in are your own network, a public address, and any tunnel you already run.
Do I need an account?
Not to reach a machine on your own network — that path never touches us at all. Paying for anything, or managing which devices are paired to you, may well need one. That is not settled yet, and we would rather say so than promise either way.
What will it cost?
Not settled yet, and we would rather say that than invent a number. What is settled: reaching your own machine on your own network will never be the paid part.
outstation