awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
jumpserver avatar

jumpserver/jumpserver

0
View on GitHub↗
30,595 stars·5,701 forks·Python·GPL-3.0·19 viewsjumpserver.com↗

Jumpserver

JumpServer is a privileged access management platform designed to manage and audit secure access to SSH, RDP, Kubernetes, and database endpoints. It functions as a centralized gateway that brokers remote terminal and graphical sessions to isolate users from critical infrastructure.

The system utilizes a web-based protocol gateway to translate remote connections into browser-compatible streams and a protocol-based proxy layer to isolate end-user devices from target assets. It incorporates security watermarking to deter unauthorized screen captures and provides a Kubernetes access gateway for controlling administrative cluster access.

Identity governance is handled through integration with external directory services, multi-factor authentication, and biometric identity verification via facial recognition. The platform also includes access activity monitoring to track security events and session lifetime management to control user expiration.

The application supports a pluggable database backend for managing system configuration and logs.

Features

  • Privileged Access Management - Provides a centralized platform for securing and monitoring access to sensitive administrative accounts across various infrastructure endpoints.
  • Session Brokering - Functions as a centralized gateway that brokers remote terminal and graphical sessions to isolate users from critical infrastructure.
  • Access Gateways - Provides a management layer for controlling and auditing administrative access to Kubernetes clusters via a web interface.
  • Protocol Isolation Layers - Routes traffic through dedicated connectors to isolate user devices from target infrastructure endpoints.
  • Remote Desktop Streaming - Launches and manages secure sessions for remote applications and graphical interfaces directly within a web browser.
  • Web-Based Terminal Gateways - Translates SSH, RDP, and database protocols into web-compatible streams for browser-based access.
  • Database Access Control - Manages and monitors administrative connections to remote databases using a web-based interface and proxy layer.
  • Proxy Gateways - Provides a web-based proxy to interface with, control, and monitor interactions with remote databases.
  • Database Query Security - Intercepts and monitors database connections to ensure all queries are authenticated and audited.
  • Identity and Access Management - Integrates external directory services and multi-factor authentication to govern privileged system access.
  • Remote Access Proxies - Implements a protocol-based proxy layer to isolate users from critical infrastructure assets during remote sessions.
  • Secure Database Access - Establishes secure sessions to database endpoints using a web-based interface and proxy connectors.
  • Infrastructure Isolation Proxies - Routes SSH, RDP, and database connections through a secure proxy to isolate end-user devices from target assets.
  • Protocol Proxies - Implements a secure gateway that brokers SSH and RDP sessions to isolate users from critical infrastructure.
  • Remote Desktop Environments - Provides browser-based remote desktop and streaming solutions that isolate end-user devices from critical infrastructure.
  • Biometric Authentication - Provides identity verification using facial recognition services to secure access to infrastructure.
  • Biometric Face Verification - Uses facial recognition to authenticate users before granting access to privileged systems.
  • Identity Provider Integrations - Synchronizes user identities and group memberships from external directory services.
  • Identity Synchronization - Automates the synchronization of user identities from external directory services to maintain consistent authentication.
  • Multi-Factor Authentication - Secures account access by requiring one-time passwords or facial recognition during login.
  • Browser-Based Streaming - Offers a centralized web portal for launching and streaming remote sessions for various operating environments directly to the browser.
  • System Activity Monitoring - Tracks and visualizes system operations and security events through integrated monitoring dashboards.
  • Media Watermarking Tools - Injects dynamic identifiers onto the interface to deter unauthorized screen captures of privileged sessions.

Star history

Star history chart for jumpserver/jumpserverStar history chart for jumpserver/jumpserver

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does jumpserver/jumpserver do?

JumpServer is a privileged access management platform designed to manage and audit secure access to SSH, RDP, Kubernetes, and database endpoints. It functions as a centralized gateway that brokers remote terminal and graphical sessions to isolate users from critical infrastructure.

What are the main features of jumpserver/jumpserver?

The main features of jumpserver/jumpserver are: Privileged Access Management, Session Brokering, Access Gateways, Protocol Isolation Layers, Remote Desktop Streaming, Web-Based Terminal Gateways, Database Access Control, Proxy Gateways.

What are some open-source alternatives to jumpserver/jumpserver?

Open-source alternatives to jumpserver/jumpserver include: fosrl/pangolin — Pangolin is a zero-trust remote access platform designed to provide secure, identity-aware connectivity to private… octelium/octelium — Octelium is a zero-trust network access platform and identity-aware proxy designed to secure private HTTP, SSH, and… kanidm/kanidm — Kanidm is a centralized identity management server designed to handle authentication, authorization, and directory… bitwarden/android — This project is an Android password manager application that provides an end-to-end encrypted vault for storing and… thehive-project/thehive — TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security… netbirdio/netbird — NetBird is a zero-trust networking platform that builds secure, encrypted peer-to-peer overlay networks using the…

Open-source alternatives to Jumpserver

Similar open-source projects, ranked by how many features they share with Jumpserver.
  • fosrl/pangolinfosrl avatar

    fosrl/pangolin

    21,255View on GitHub↗

    Pangolin is a zero-trust remote access platform designed to provide secure, identity-aware connectivity to private network resources. It functions as a cloud-native network controller that orchestrates encrypted tunnels, traffic routing, and access policies across distributed environments. By leveraging WireGuard for secure data transport, the platform enables authenticated access to internal web applications, terminal sessions, and remote desktops without exposing services to the public internet. The platform distinguishes itself through a declarative infrastructure model that synchronizes n

    TypeScriptcrowdsecdockerhome-lab
    View on GitHub↗21,255
  • octelium/octeliumoctelium avatar

    octelium/octelium

    3,371View on GitHub↗

    Octelium is a zero-trust network access platform and identity-aware proxy designed to secure private HTTP, SSH, and SQL resources. It functions as a secure gateway that validates human and workload identities using OIDC, SAML, and FIDO2 passkeys before granting access to internal applications and SaaS APIs. The system is distinguished by its secretless access broker, which injects credentials—such as API keys, passwords, and AWS Sigv4 signatures—at the gateway level so users can access databases and cloud resources without managing secrets. It further specializes in AI gateway administration,

    Goabacai-gatewayapi-gateway
    View on GitHub↗3,371
  • kanidm/kanidmkanidm avatar

    kanidm/kanidm

    4,595View on GitHub↗

    Kanidm is a centralized identity management server designed to handle authentication, authorization, and directory services across distributed infrastructure. It provides a comprehensive framework for managing human and service accounts, utilizing a schema-driven database to store identity records, group memberships, and system attributes. The platform supports a wide range of authentication methods, including passkeys, passwords, and standard protocols like OAuth2, OIDC, LDAP, and RADIUS. The system distinguishes itself through a granular access control engine that enforces security policies

    Rustauthenticationiamidentity
    View on GitHub↗4,595
  • bitwarden/androidbitwarden avatar

    bitwarden/android

    8,457View on GitHub↗

    This project is an Android password manager application that provides an end-to-end encrypted vault for storing and synchronizing login credentials, secure notes, and identities. It functions as a secure storage system using zero-knowledge encryption to ensure that only the user can decrypt their stored data. The application integrates directly with the Android system to provide an autofill service that populates usernames and passwords into mobile apps and browser login fields. It also serves as a passkey management wallet for FIDO2 cryptographic passkeys and a time-based one-time password a

    Kotlinandroidbitwardencompose
    View on GitHub↗8,457
See all 30 alternatives to Jumpserver→