wetty

Flags

WeTTY can be run with the --help flag to get a full list of flags.

Server Port

WeTTY runs on port 3000 by default. You can change the default port by starting with the --port or -p flag.

Server Host

By default WeTTY listens on 0.0.0.0 (all interfaces). You can change this with the --host flag, for example --host 127.0.0.1 to only listen on localhost.

Unix Socket

Instead of listening on a TCP port, WeTTY can listen on a unix socket using the --socket flag. This is mutually exclusive with --host and --port.

SSH Host

If WeTTY is run as root while the host is set as the local machine it will use the login binary rather than ssh. If no host is specified it will use localhost as the ssh host.

If instead you wish to connect to a remote host you can specify the host with the --ssh-host flag and pass the IP or DNS address of the host you want to connect to.

Default User

You can specify the default user used to ssh to a host using the --ssh-user. This user can overwritten by going to http://yourserver:3000/ssh/<username>. If this is left blank a user will be prompted to enter their username when they connect.

SSH Port

By default WeTTY will try to ssh to port 22, if your host uses an alternative ssh port this can be specified with the flag --ssh-port.

WeTTY URL

If you’d prefer an HTTP base prefix other than /, you can specify that with --base.

Do not set this to /ssh/${something}, as this will break username matching code.

Allowed WebSocket Origins

WeTTY only accepts Socket.IO connections from its own browser origin. Requests with a foreign, missing, malformed, or null Origin header are rejected.

If a separate frontend needs to connect, add its complete origin with --allowed-origin, for example:

wetty --allowed-origin https://terminal.example.com

Repeat the flag to allow multiple origins. The ALLOWEDORIGINS environment variable accepts a comma-separated list. Reverse proxies should preserve the original Host header and set X-Forwarded-Proto to the browser-facing scheme.

Allow connections without an Origin header

Non-browser clients such as CLI tools, scripts, and certain reverse proxies do not send an Origin header. By default WeTTY rejects these requests.

To allow them, use --allow-missing-origin:

wetty --allow-missing-origin

The ALLOWMISSINGORIGIN=true environment variable has the same effect.

Note: null origins (sent by sandboxed iframes) are always rejected, even when --allow-missing-origin is set.

Allow Remote Hosts

By default WeTTY does not allow the host and port URL parameters to be used as the SSH destination. To enable this, use the --allow-remote-hosts flag.

Allow Remote Command

By default WeTTY does not allow the command and path URL parameters to specify the command and working directory on the SSH host. To enable this, use the --allow-remote-command flag.

Socket.IO Ping Interval / Timeout

WeTTY’s browser terminal rides on a Socket.IO connection, kept alive with a heartbeat: the server pings the client every --ping-interval milliseconds (default 3000) and expects a pong back within --ping-timeout milliseconds (default 7000), or it closes the transport (shown to the user as a “transport close” error requiring reconnect).

These defaults are tight compared to Socket.IO’s own defaults (25000/20000). On a high-latency or lossy network path, a single delayed pong can exceed the 7 second timeout and force a reconnect even though the underlying connection is otherwise healthy. If you see frequent “transport close” errors, try raising both, e.g. --ping-interval 25000 --ping-timeout 20000.

Both flags also accept the PINGINTERVAL and PINGTIMEOUT environment variables.

Log Level

You can set the log level of the WeTTY server using the --log-level flag. Accepts standard log levels (e.g. debug, http, info, warn, error).