TA
SOFTWARE

Tabby

Tabby is a cross-platform terminal, SSH and serial client for local shells, remote hosts, split panes, port forwarding, jump hosts, SFTP and encrypted configuration.

Version 1.0.235Windows x64/ARM64macOS Intel/Apple SiliconLinux x64/ARMMIT

What Tabby is for

Tabby organizes local shell, SSH, SFTP and serial sessions on Windows, macOS and Linux using tabs, panes, groups, jump hosts and port forwarding. It is a terminal and session manager rather than a permission boundary: commands, keys and remote sessions still inherit the actual shell, account and server policy.

Version and platform packages

Version 1.0.235 provides Windows x64 and ARM64 installers or portable ZIPs, Intel and Apple Silicon macOS packages, and x64, arm64 and armv7 Linux packages. It adds fixed tabs and nested groups and fixes Windows SFTP path traversal, shell injection, SSH keepalive and transfer issues.

Remote connections and credentials

Verify the host key on the first SSH connection, and treat SFTP filenames and remote responses as untrusted input. An encrypted configuration vault protects stored data but not an unlocked session. Plugins, login scripts, agent forwarding and port forwarding can each expand privilege or network exposure, so enable them only for a defined task and revoke credentials when no longer needed.

Maintenance note

This page was reviewed on 2026-08-23 against Tabby 1.0.235, its platform packages, session features, security advisories and MIT licensing.

SAVE TO CLOUD

Save to your cloud drive

Open the cloud drive to get the file directly, or save it for convenient access on another device.

Links checked 2026-08-06
Save first, access when you need itOn desktop, scan with the matching cloud-drive app. On mobile, tap the save button.
GUIDE

Tabby 1.0.235 installation, SSH/SFTP and terminal setup

Install the matching package, verify a normal local shell, then add one trusted test host and enable SFTP, forwarding, jump hosts or serial features step by step.

Before you start

  • Select Windows x64/ARM64, macOS Intel/Apple Silicon or Linux architecture. Windows portable mode needs a writable `data` directory beside Tabby.exe.
  • Prepare the test host, port, username and trusted host-key fingerprint. Restrict private-key permissions and use a strong independent vault password.
  • Back up configuration without sharing passwords, keys, jump-host addresses or login scripts in tickets, chat or public repositories.
01

Installation steps

  1. 01

    Install or enable portable mode

    Use the package for the current system. For Windows portable mode, extract to a stable directory, create `data` and confirm settings are written there rather than to the user profile.

  2. 02

    Configure a local shell

    Select an installed PowerShell, WSL, Git Bash or system shell, open a normal-permission tab and test encoding, font, copy/paste and close behavior.

  3. 03

    Create an encrypted profile and test connection

    Set a vault password, add one SSH profile and compare the host-key fingerprint before enabling SFTP, proxy, jump-host or forwarding features.

02

Quick start

  1. 01

    Verify the SSH host identity

    Compare the first-connection fingerprint with the operator's trusted record. If a key changes, investigate reinstall, DNS or interception before accepting it.

  2. 02

    Organize groups and tabs

    Group sessions by environment, project or customer, use clear names and colors for production, and recheck host and account before a high-impact command.

  3. 03

    Use SFTP and forwarding deliberately

    Upload and download a small test file, verify paths, bind forwarding to the narrowest address and close proxy, jump-host and agent-forwarding features after use.

Usage tips

  • Version 1.0.235 contains SFTP path-traversal and shell-injection fixes; remote filenames and returned content remain untrusted after upgrading.
  • Plugins and themes execute local code and can see terminal content. Review maintenance and permissions, and disable third-party plugins when troubleshooting.
  • Agent forwarding lets a remote host request signatures from the local agent. Prefer ProxyJump, separate keys or short-lived credentials when they meet the task.
  • Binding a forwarded port to 0.0.0.0 can expose a local service to a network. Prefer loopback and verify firewall rules.
Troubleshooting and uninstall

Why does SSH time out or fail through a jump host?

Verify address, port, DNS and keys with the system SSH client, then inspect Tabby's proxy, jump order and keepalive settings. Remove scripts and forwarding before restoring them one by one.

Why did an SFTP download appear outside the chosen directory?

Stop the connection, upgrade to 1.0.235 or later, inspect the unexpected path and download log, and verify server trust. Do not reconnect an old client to the same suspicious host.

  1. Export sanitized settings and revoke credentialsKeep aliases, groups and necessary parameters while removing passwords, keys and scripts from exports. Revoke short-lived keys, tokens and unused access on the server.
  2. Remove the program and local dataUninstall the app or delete the portable directory, then decide whether encrypted settings and cache need secure cleanup. Shared shells, agents and keys may be used by other clients.
FAQ

Frequently asked questions

Is Tabby a shell or only a terminal interface?

It provides terminal, SSH, serial and session management. Local commands still run through installed PowerShell, CMD, WSL, Git Bash, Bash or another shell.

Why should I use at least version 1.0.235?

It fixes a Windows SFTP path-traversal issue, a shell-injection issue and several SSH and transfer problems. This matters especially when connecting to hosts that are not fully trusted.

Does an encrypted vault make SSH keys absolutely safe?

No. Protection also depends on the vault password, unlocked session, device account and system state. Agent forwarding can let a remote host request signatures from the local agent.

Does the download require an extraction code?

The Quark entry does not require one; the four-character code for the Baidu entry is shown beside its download entry.