Keyless SSH
Engineers connect to any server in one click — the broker injects the credential on the wire. No keys on laptops, nothing to lose, nothing to rotate.
Scoped, time-boxed access to any server or cluster — granted per session, never standing. The credential stays sealed on the broker, and every session is recorded.
One broker for SSHKubernetesDatabasesRDPOIDC SSOSCIM
ssh app-prod-01.tessera.local
→ connecting to app-prod-01 …
Last login: Sun Aug 17 16:04:11 2026 from 10.0.0.4
[tessera] Read-only session — the following commands are blocked:
apt, chmod, chown, dd, mv, rm, shutdown, systemctl, useradd
also blocked: scripts, output redirection (> / >>), sftp/scp.
root@app-prod-01:~$ rm -rf /var/log/api
[tessera] blocked — 'rm' is not allowed in read-only mode
root@app-prod-01:~$
Runs on your infrastructure — wherever it lives
Agentless and self-hosted — Tessera brokers SSH, Kubernetes, database and RDP access, injecting credentials on the wire and recording every session, without changing how engineers work.
SSH · k8s · DB · RDP roles · approval · injection server · cluster Click Connect and keep using your normal SSH, kubectl, SQL and RDP tools. No new workflow to learn.
The broker checks the user's role and any just-in-time approval, then injects the real credential on the wire. For SSH, Kubernetes and databases the secret never touches the laptop.
Commands, queries and full replay land in an append-only log and stream to your SIEM as they happen — compliance evidence, automatically.
The controls security teams demand and the simplicity engineers want — across every protocol, in one self-hosted broker, with none of the enterprise bloat.
Engineers connect to any server in one click — the broker injects the credential on the wire. No keys on laptops, nothing to lose, nothing to rotate.
Add a cluster once and your team gets governed access through their existing tooling — commands, logs, exec and port-forward all work, every call audited.
PostgreSQL and MySQL with credentials injected. Read-only is enforced at the SQL layer — writes and DDL are rejected before they ever reach the database.
Brokered RDP to Windows hosts. Connect opens the native client against a loopback port on your own machine; the credential is passed to it over stdin, never shown in the UI and never written to disk, and every issuance is audited.
Zero standing access. Engineers request the access they need, for as long as they need it; you approve in one tap and the grant auto-expires on its own.
Full session replay and per-command history — plus shadow any live session and force-close it the instant something looks wrong.
Grant view / read-only / read-write and downgrade live with no reconnect. Every login, command and approval streams to your SIEM as it happens — a copy that lives outside the broker.
Tessera is the control point between your engineers and production — so it's engineered to earn that position.
Access should be granted for a reason, scoped to a task, and gone the moment it's done. Tessera makes that the default — not a process people route around.
Most access tools control who can connect. Tessera also controls what happens once you're inside the session.
| Tessera | Teleport | StrongDM | Boundary | |
|---|---|---|---|---|
| Where Tessera goes further | ||||
| Kill write access mid-session — no reconnect flip a live session RW → RO in one tap — on SSH, Kubernetes and SQL alike | ||||
| Nothing installed — and nothing reconfigured — on your targets your servers, clusters and databases stay exactly as they are | ||||
| Fully self-hosted control plane no vendor cloud anywhere in the access path | ||||
| One read-only switch across SSH · Kubernetes · SQL same policy, every protocol — not a per-protocol reimplementation | ||||
| And everything you'd expect | ||||
| Credentials injected on the controller — never on the user's machine SSH · Kubernetes · SQL | ||||
| Session recording + live watch & force-close | ||||
| Just-in-time access · RBAC · SSO · SCIM | ||||
| Audit export to your SIEM | ||||
Checked against each vendor's own published documentation on 14 August 2026; products change, so verify before relying on it. A cross means the vendor does not document the capability, not that we tested and it failed. Capabilities vary by edition: several Boundary rows are partial because the capability requires Boundary Enterprise or HCP rather than the open-source edition; Teleport's SQL read-only covers PostgreSQL and is granted for the life of a connection, and its Kubernetes access runs an agent inside the cluster. StrongDM has been part of Delinea since March 2026. Half-circle = partial (supported with limits or extra setup). SSH command filtering is best-effort for interactive shells; Kubernetes and SQL read-only are enforced at the protocol layer.
Row by row, with where each of them beats us: Tessera vs Teleport Tessera vs StrongDM Tessera vs Boundary
Free to self-host, forever. Pay per seat only when you need the team controls — predictable pricing that's an easy win versus tools that charge per server.
Pay yearly and save up to 20% vs. monthly. Launch offer: start an annual Ultimate plan within the first 6 months and lock in $30/seat/mo instead of $36. Bigger teams and multi-year terms get deeper discounts.
Deploy Tessera in minutes and broker your first connection today.
We would like to count visits with Google Analytics, which needs a cookie. Nothing is loaded and nothing is stored unless you accept. What this sets.