JumpServer is the world's most widely deployed open-source Privileged Access Management platform — over 500,000 deployments and 30,000+ GitHub stars across 10+ years of production use. It gives DevOps and IT teams secure, on-demand access to SSH, RDP, Kubernetes, database, and RemoteApp endpoints — all through a single web browser, with no client installation.
The Enterprise Edition adds multi-tenancy, enterprise SSO (SAML2/OIDC/OAuth2), RADIUS/LDAP HA, custom RBAC roles, JIT access approval, cloud asset sync, password auto-rotation, Oracle/SQL Server support, and SLA-backed support — on top of the free Community Edition.
Unlike SaaS PAM, JumpServer is 100% self-hosted: all credentials, session recordings, and audit logs stay on your own infrastructure. Enterprise Edition is available on AWS Marketplace and as an on-premise subscription.
How it works — PAM access gateway
JumpServer acts as a centralised access gateway between users and all target systems. Users authenticate through JumpServer and never connect directly to servers, databases, or containers — every session is proxied, recorded, and auditable. Access is protocol-aware: SSH for Linux, RDP for Windows, VNC for graphical desktops, SQL for databases, kubectl for Kubernetes, and browser-based RemoteApp/VirtualApp for enterprise desktop applications.
Four PAM pillars
JumpServer organises its capabilities into four integrated pillars — Authentication, Authorization, Account Management, and Audit — covering the complete PAM lifecycle from identity verification to compliance reporting.
Enterprise Edition — exclusive features
Enterprise Edition adds the following capabilities on top of the free Community Edition.
Custom RBAC roles — fine-grained permission sets tailored to your organisation
Multi-tenant organisation — isolate teams, business units, or clients in one deployment
SSO (OIDC / SAML2 / OAuth2) — integrate with any enterprise identity provider
RADIUS / LDAP HA — high-availability authentication for critical environments
Oracle & Microsoft SQL Server — database access management for enterprise DBs
JIT access with ticket approval — request, approve, and auto-expire privileged sessions
Cloud asset auto-sync — discover and onboard assets from AWS, GCP, and Azure
Password auto-rotation — scheduled credential rotation; no reused or shared passwords
Virtual Applications (VirtualApp) — browser-based access to desktop apps, with recording
Active-Standby HA / Full HA cluster — zero-downtime deployments
Custom UI & branding — white-label the portal for your organisation or clients
SMS notifications — access alerts and OTP codes via SMS
Email + ticket support with SLA — dedicated account manager and guaranteed response
Community vs Enterprise
Community Edition is free forever (GPL-3.0) and supports up to 5,000 assets. Enterprise Edition is a scale-based commercial subscription — all four tiers share identical features, differing only in asset capacity and HA topology.
| Feature | CommunityFree forever | EnterpriseEE subscription |
|---|---|---|
| Max IT assets | Up to 5,000 | 50 to Unlimited |
| SSH / RDP / VNC / Database / K8s | ||
| Oracle & SQL Server | — | |
| Session recording & playback | ||
| LDAP / AD / MFA (TOTP) | ||
| SSO (OIDC / SAML2 / OAuth2) | — | |
| RADIUS / LDAP HA | — | |
| RBAC with custom roles | — | |
| Just-In-Time (JIT) access | — | |
| Ticket approval workflow | — | |
| Multi-tenant organisation | — | |
| Cloud asset sync (AWS / GCP / Azure) | — | |
| Password auto-rotation | — | |
| Active-Standby / Full HA cluster | — | |
| SLA support + account manager | — |
Enterprise tiers
EE Basic
Up to 50 assets
Standalone deployment
EE Standard
Up to 500 assets
Active-Standby HA
EE Pro
Up to 5,000 assets
Active-Standby HA
EE Ultimate
Unlimited assets
Full HA cluster · AWS Marketplace
Industry use cases
DevOps & Cloud
Secure SSH, Kubernetes, and cloud console access. Auto-sync assets from AWS, GCP, Azure.
Finance & Banking
Privileged access governance for SOX and PCI-DSS compliance with a full audit trail.
Manufacturing & OT
Control access to production servers and SCADA/OT management systems.
Healthcare
HIPAA-compliant privileged access to EMR/EHR systems and clinical servers.
MSSP / Multi-Tenant
Multi-tenant isolation — manage privileged access for multiple clients from one instance.
Government & Public
Self-hosted, air-gapped deployment for classified or sensitive government infrastructure.
Why JumpServer Enterprise?
500k+ deployments
10+ years of production use across enterprises, telecoms, banks, and governments.
Cost-effective
Enterprise-grade PAM at a fraction of CyberArk / BeyondTrust cost — no per-agent fees.
100% self-hosted
All data stays on your infrastructure — no cloud dependency, nothing leaves your perimeter.
All protocols
SSH, RDP, VNC, Kubernetes, MySQL, Oracle, SQL Server, and RemoteApp — one platform.
Cloud-native
Auto-sync cloud assets; deploy on Docker, Kubernetes, or VM; available on AWS Marketplace.
Compliance-ready
SOC 2, SOX, PCI-DSS, and HIPAA audit logs and session recordings out of the box.
Technical specifications
- Deployment
- Docker, Linux VM, Kubernetes; on-premise, private cloud, or AWS Marketplace
- Protocols
- SSH · RDP · VNC · SFTP · Telnet · SQL · Kubernetes (kubectl) · RemoteApp/VirtualApp
- Databases
- MySQL, MariaDB, PostgreSQL, Redis, MongoDB; Oracle & SQL Server (EE)
- Authentication
- LDAP/AD · OIDC · SAML2 · OAuth2 · RADIUS · CAS · Passkey/WebAuthn · TOTP MFA
- Authorization
- RBAC custom roles (EE) · JIT + ticket approval (EE) · IP/time/protocol/command ACL
- Account mgmt
- Auto-discovery · password rotation (EE) · encrypted backup · cloud sync AWS/GCP/Azure (EE)
- Audit / SIEM
- Video session recording · keystroke log · Syslog · Splunk · Elasticsearch integration
- HA / scale
- Standalone / Active-Standby / Full HA cluster (EE); unlimited assets on Ultimate tier
- Compliance
- SOC 2, SOX, PCI-DSS, HIPAA, ISO 27001 — full audit trail and session playback
- Stack
- Python (Django) back-end · Vue.js front-end · GPL-3.0 open-source core
Start your 14-day Enterprise trial
No credit card required — full Enterprise features for 14 days. Contact iconnet, a JumpServer authorised partner, to get started.