RelayBar

RelayBar is a tiny native macOS menu-bar app for local SSH port forwards. It has no external dependencies and runs macOS's built-in /usr/bin/ssh directly.

Download the latest release

Download the latest release

Screenshots

RelayBar tunnel list

RelayBar new tunnel form

What it does

Imports common commands such as ssh -N -L 8080:localhost:3000 user@host

Adds tunnels manually with five small fields

Starts and stops each tunnel with one click

Starts a tunnel and opens its local URL in the default browser with one click

Retries unexpected disconnects up to 10 times with exponential backoff

Shows startup failures directly beside the tunnel

Stores tunnel definitions in local UserDefaults

Stops child SSH processes when RelayBar quits

RelayBar intentionally manages one local (-L) forward per item. Safe connection options such as -p, -J, -i, and a restricted set of -o values are preserved when importing a command. Options that can execute local commands, select arbitrary configuration files, or write logs are rejected. RelayBar never invokes a shell.

RelayBar is distributed outside the Mac App Store and is intentionally not sandboxed. Its SSH process behaves like the command-line client: it reads the user's normal ~/.ssh/config and known_hosts, can use configured identity files, and inherits access to the user's SSH agent. SSH still runs non-interactively, so password prompts are not supported. On recent macOS versions, the first connection to a .local or LAN host may ask for Local Network access.

System specs

The concise architecture and behavior archive starts at docs/system-specs.

docs/system-specs

Build

Requires macOS 13 or newer and the Xcode command-line tools.

The packaged app is written to .build/RelayBar.app. The build script automatically finds the first valid Developer ID Application certificate in the login keychain and signs with the hardened runtime.

To create a signed ZIP:

This writes .build/RelayBar.zip. A Developer ID signature identifies the publisher, but a downloaded app should also be notarized to pass Gatekeeper without warnings. After storing one notarytool keychain profile, notarize and staple with:

Set SIGNING_IDENTITY only when a Mac has multiple Developer ID certificates and the automatic choice is not the one you want.

Test