Guides · RDP-FIDO-GATE

An SSH terminal with an AI assistant that can run on your own model

Asking a chatbot for a command and pasting it into a root shell works, but the chatbot does not know your server, and you carry its output — and sometimes your secrets — back and forth by hand. An assistant inside the terminal fixes the first part. Whether it is acceptable depends on the second: what it sees, and where that goes.

Updated

What the console does

The SSH console in the RDP FIDO client is a terminal with a side panel. On the “Assistant” tab you describe a task in words — “find what is filling the root partition” — and get commands back, each in a block with three buttons: “Insert” types the command into the terminal without Enter, “Run” executes it, “+ Save” keeps it in your list of commands.

Underneath it runs your system ssh, so keys, ssh-agent and ~/.ssh/config work as they always did. The console is part of the client for Windows 10 / 11 and Linux, the free edition included.

Connect it to a local model

  1. Start a server that speaks the OpenAI API. Ollama serves it at http://HOST:11434/v1, LM Studio at http://HOST:1234/v1. If the model runs on another machine, make the server listen on the network and not only on localhost.
  2. Open the console: click an SSH tile in the client, or run RdpFidoClient.exe console --host 203.0.113.10 --user admin (on Linux: rdpfido console SESSION).
  3. On the “Assistant” tab press the gear, choose the OpenAI-compatible service and enter the address. The console asks the server for its models and shows them as a list; an API key is optional.
  4. If the model is slow, raise “Wait for the answer, seconds” in the same settings: the default is 600, the maximum 3600.
# Ollama on a machine in your LAN
OLLAMA_HOST=0.0.0.0 ollama serve
ollama pull qwen2.5-coder:14b

# address for the console:  http://192.168.1.50:11434/v1

With a model inside your network neither your questions nor the terminal text leave it: requests go from your computer straight to the address you entered, not through our servers.

For Claude, choose the Anthropic service and enter an API key; the address and the model are already filled in.

What the model sees — and what it never sees

One caution no program can remove: what is on the screen is on the screen. If you print a file with secrets and then ask a question with “Sees the console” ticked, those lines go to the model. With a cloud model, untick it first — or use a local one.

Who presses Enter

The assistant is instructed not to open with a destructive command and to warn before one that removes data, restarts a service or changes access. It is still a language model, and small local models make more mistakes than large ones: read a command before you run it.

Describe the server once

Prompts are standing notes for the assistant: which distribution this is, what is installed, what must not be touched. Ticked prompts go with every question — for this server or for all of them. Conversations are saved per session, so yesterday's investigation can be continued today; opening an old conversation types nothing into the terminal.

What it does not do

RDP-FIDO-GATE

RDP-FIDO-GATE keeps SSH and other admin ports closed and opens them for one IP, for about 90 seconds, only after a FIDO2 key touch or an authenticator code. Its client includes an SSH console with saved passwords, saved commands and an AI assistant that works with Claude or with your own local model. The Free edition covers 10 saved sessions.

Frequently asked questions

Which models work?

Claude through the Anthropic API, and any model behind an OpenAI-compatible API: Ollama, LM Studio or a gateway of your own. The console lists the models the server reports; a model name can also be typed by hand.

Do my requests pass through your servers?

No. They go from your computer directly to the address you entered — the Anthropic API or your own server.

Can I try it without a server to connect to?

Yes. RdpFidoClient.exe console with no arguments opens the console on a local shell, with the same panel and the same assistant.

Does the console require the FIDO gate?

No. A session without a gate is a plain SSH console with saved passwords, commands and the assistant. The gate adds the part that matters for exposed servers: an SSH port that is closed to everyone else.

Is it free?

The console is part of the client, including the free edition with up to 10 saved sessions. The model is paid for separately to its provider — or costs nothing if it is your own.

Related guides