Tecknicos
Wemote · by Tecknicos

Infrastructure access, finally browser-native.

Connect to every endpoint from one governed workspace. SSH, RDP, VNC, VM consoles, HTTP and HTTPS — all brokered through identity-aware policy, recorded end-to-end, and driven by an API your CI can use.

Protocols supported
SSH RDP VNC VM Console HTTP HTTPS
Capabilities

One workspace. Every protocol. Full governance.

Wemote does not bolt audit and policy onto a remote session — it brokers the session itself. That changes what's possible at the edge of your infrastructure.

Browser-only

No agent, no driver, no installed client. Any modern browser, with WebRTC and WebSocket transport.

Policy-enforced

Time-bound access, role-aware brokerage, just-in-time elevation, revocable per-session.

Recorded end-to-end

Full session capture with searchable transcript, replay UI, and immutable audit log.

API + CLI

Every action you can take in the UI is one API call away. CI can open sessions, rotate access, query logs.

Session brokerage

Sessions through policy, not around it.

Traditional bastions sit beside your policy. Wemote sits inside it. Every connection is a brokered session — auth happens at the edge, policy evaluates per-request, and the broker rejects anything that fails. There's no broad network access to bypass — every session is authorized per-request, not per-network.

Sessions can be time-bound, role-aware, scoped to a single target, and revoked mid-session if policy changes. It works the same whether your user is in the office or on a coffee shop wifi — because trust isn't network-shaped.

wemote · endpoints live
Endpoints view listing hosts, protocols, policies, and per-row reachability status.
wemote · CLI terminal
$wemote sessions open prod-db-01 --role=read-only
session opened · ws://wemote.io/s/8f3aa9
$wemote sessions list --active
3 active · chris, sam, jordan
$wemote policy revoke --user sam --reason "shift end"
2 sessions terminated · audit logged
CLI & API

Operational primitives, not a closed dashboard.

The Wemote dashboard runs on the same API that ships with the CLI. There's no privileged UI-only action. That means anything you'd want to script — opening sessions, rotating credentials, revoking access at shift change, exporting audit transcripts — is just an API call.

Webhooks fire on session lifecycle events so your SIEM, ticketing system, or approval bot can react in real time. GraphQL on top for the analytics use case.

See it in action

Click. Connect. Recorded.

Watch a real session: an HTTP/S endpoint opens through the broker, Wemote injects the stored credential, the operator works inside the app, and the entire session is captured for playback — credentials never leave the vault.

wemote · nginx session · auto-login → recorded demo
Walkthrough: searching for the nginx endpoint, picking a stored credential, auto-logging into Nginx Proxy Manager, navigating its UI, then opening the endpoint profile and playing back the recorded session.
End-to-end: endpoint search → stored credential picker → auto-login to Nginx Proxy Manager → session recording → playback. The operator never sees or types the destination's password.
01

Stored credential, not shared secret

The user picks a credential by name. The actual password lives in Wemote's vault and is injected at session start — never exposed to the operator's browser.

02

Auto-login into HTTP/S apps

Nginx Proxy Manager, Grafana, Netdata, internal admin panels — anything with a login form can be brokered. The operator lands on the dashboard, already authenticated.

03

Recording is always on

Every brokered session is captured with a searchable replay. Reopen the endpoint profile, jump to the Recordings tab, and scrub through exactly what happened — frame-perfect.

Inside the workspace

Everything that governs access, in one place.

Approvals, the audit log, and platform settings all live in one governed console — no separate admin tools, no jumping between systems.

Audit Log
Audit log filtered by event type, user, and outcome.
Filterable, immutable activity stream covering every session, policy decision, and admin action.
Approvals
Pending access requests awaiting approval, with user, endpoint, and elapsed wait time.
Pending access requests with full context — approve, deny, or escalate without leaving the surface.
Settings
Platform settings for stores, agents, identity providers, and policy.
Identity, stores, agents, and policy in one place — no per-protocol admin tools.
Where Wemote fits

Use cases worth replacing.

Replacing bastion hosts

One broker instead of a constellation of jump boxes. Identity-aware, recorded, revocable — and you don't need to SSH twice to get anywhere.

Auditable third-party access

Bring contractors and vendors onto specific targets, time-bound and recorded, without provisioning a standing account that outlives the work.

Just-in-time production access

Engineers request a session against production, approval workflow fires, access opens for 30 minutes, expires automatically. No standing admin.

Compliance-friendly remote ops

SOC 2, HIPAA, internal audit — Wemote captures the artifact (recorded session, immutable log, policy decision) without manual ceremony.

Self-hosted trial

Bring Wemote onto your infrastructure today.

Enter your work email and we'll send trial credentials and a link to the self-host quickstart — no sales call required.