Raycast + extension
⌘ Space · “Manage Tunnels” A list, one switch per tunnel System ssh, your keys Free, open source ~1,200 installs
The “SSH Tunnel Manager” extension manages tunnels with your system’s ssh, for free, inside a launcher you already hit a hundred times a day. If you have two tunnels and nothing else, it is enough, and this page says so before selling you anything.
macOS 11+ · Windows soon
Two different objects
The difference is not the feature list: it is what remains once you close the window.
Raycast + extension
⌘ Space · “Manage Tunnels” A list, one switch per tunnel System ssh, your keys Free, open source ~1,200 installs
Kestro
An icon, all the time Green only once the port answers Reopens when the Mac wakes Answers ssh’s questions in place Cloud SQL, IAP, Session Manager one payment, per machine
Point by point
| Raycast extension | Kestro | |
|---|---|---|
| Price | free, open source | €29.99$29.99£25.99CHF 25.90CA$40.99A$45.99 once, per machine |
| What it is | a command inside a launcher | a menu bar application |
| SSH tunnels | yes, with the system ssh | yes, with the system ssh |
| Google Cloud SQL | not advertised | yes, via the official proxy |
| Google VMs over IAP | not advertised | yes, via gcloud |
| EC2 over Session Manager | not advertised | yes, via the aws CLI |
| Visible without opening anything | no: you have to call the command | the icon changes the moment a tunnel drops |
| Beyond tunnels | nothing: that is the advertised scope | Git repos, scripts, monitoring, sharing a port |
| Access for an AI assistant | no | yes, within limits you set |
| Who maintains it | one author, on their own time | a vendor, and an address to write to |
Recorded on 7 August 2026 from the extension’s listing and repository: a single command, “Manage tunnels with system ssh command”, around 1,200 installs. The rows below cover what each one advertises; everything else takes ten minutes to try, and trying is the right way to decide.
What Kestro adds
None of them show on a screenshot. All of them show the day a tunnel drops while you were doing something else.
An ssh -L takes one to three seconds to authenticate and then listen. During that window the process is alive and the port still refuses connections: the exact moment you believe your tunnel is open and psql answers “connection refused”. Kestro probes the local port and only shows “open” on the first successful connect.
Closing a laptop kills tunnels, and nothing says so on wake: you come back to a list claiming all is well. Kestro reopens them, backing off progressively, and writes it on the row.
A passphrase, an unknown host fingerprint, a password: all of it runs in a real pseudo-terminal, and the row offers a field to answer on the spot. A program launched through a pipe never asks these questions, it fails silently.
A Cloud SQL database through Google’s official proxy, a VM with no public address over IAP, an EC2 instance over Session Manager. Three tools, three syntaxes, and one list, with one switch.
On your machine
Your connections run from your computer to your servers, never through us.
Nothing to create, no password.
SSH, Google Cloud, AWS: Kestro uses your own tools, locally.
We don’t know what you open, or when.
Your licence renews with us. Nothing else leaves.
When the extension is enough
They are common, and there is no reason to pay to cover them.
A short list you open in the morning and never touch again: the extension does exactly that, for free, and you will never need the rest. Keep it.
If everything goes through ⌘ Space and one more menu bar icon clutters rather than helps, Kestro’s format works against you, and a format you dislike is not redeemed by features.
Kestro only runs on macOS; the Windows version is in progress. The extension has the same limit, but it costs you nothing.
Pricing
A tool you open forty times a day shouldn’t send an invoice every month.
Kestro licence
1 computer · one-time
Or download it for free first →
Refunded within 14 days, no questions asked.
Questions we get asked
Yes, as long as they do not open the same local port at once. Both launch your system’s ssh with your keys and store nothing of their own on the server side. Kestro will in fact tell you a port is already taken before trying.
For the part that is not “open a tunnel”. Opening is easy: it is one command line, and the extension composes it well. What costs time is knowing a tunnel is genuinely open, finding it alive after the machine slept, answering ssh when it asks for something, and having Cloud SQL and Session Manager in the same list as the rest. If none of that has ever happened to you, the extension is enough, and that is an honest answer.
One is in progress, and it will be free: it drives the app from the launcher, for people who would rather never leave ⌘ Space. The two do not compete, one is a door, the other is what holds the tunnels open behind it.
It was recorded on 7 August 2026 from the extension’s public listing and repository. We have not audited its code: the rows cover what each one advertises, and “not advertised” means that and nothing more. Write to us if you find a discrepancy and we will correct it.