Teleport

Gravitational, Inc.·Gravitational.Teleport

Teleport provides connectivity, authentication, access controls and audit for infrastructure.

Teleport includes an identity-aware access proxy, a CA that issues short-lived certificates, a unified access control system and a tunneling system to access resources behind the firewall. We have implemented Teleport as a single Go binary that integrates with multiple protocols and cloud services: - SSH nodes. - Kubernetes clusters - PostgreSQL, MongoDB, CockroachDB and MySQL databases. - Internal Web apps. - Windows Hosts. - Networked servers. You can set up Teleport as a Linux daemon or a Kubernetes deployment. Teleport focuses on best practices for infrastructure security: - No need to manage shared secrets such as SSH keys or Kubernetes tokens: it uses certificate-based auth with certificate expiration for all protocols. - Two-factor authentication (2FA) for everything. - Collaboratively troubleshoot issues through session sharing. - Single sign-on (SSO) for everything via GitHub Auth, OpenID Connect, or SAML with endpoints like Okta or Microsoft Entra ID. - Infrastructure introspection: Use Teleport via the CLI or Web UI to view the status of every SSH node, database instance, Kubernetes cluster, or internal web app. Teleport uses Go crypto. It is fully compatible with OpenSSH, sshd servers, and ssh clients, Kubernetes clusters and more.

winget install --id Gravitational.Teleport --exact --source winget

Latest 18.11.1·September 16, 2026

Release Notes
  • Added support for LSA protection, the Teleport Windows authentication package can now be used on hosts with LSA protection (RunAsPPL) enabled.
  • Fixed an issue where Windows authentication would fail with Teleport-managed non-AD users.
  • Fixed an issue causing the bot web UI page to crash when the cluster has 1000 bots with many traits. Performance of the page will be improved in a later release.
  • Added a new command, tsh mcp login, to provide OAuth authentication support for MCP servers in tsh.
  • Fixed an issue that caused Teleport Connect to leak connections to the local SSH agent.
  • Updated Go to 1.26.8.
  • Running tsh proxy kube with per-session MFA now performs a single MFA ceremony covering all requested Kubernetes clusters instead of one per cluster, and issues per-cluster certificates concurrently.
  • The tsh proxy kube command now issues a single shared certificate for Kubernetes clusters that do not require per-session MFA, reducing certificate issuances across large fan-outs.
  • Improved OpenTelemetry tracing configuration mechanism in tbot.
  • Fixed Bot kind not being reported accurately in heartbeats.
  • Improved SCIM group member addition performance.
  • Fixed tsh kubectl exec masking exit codes.
  • Fixed an issue in tbot's workload-identity-api service where slow connections to the Teleport Proxy could result in timeouts.
  • Added ldap_host and ldap_tls_server_name options to the database service's AD config, letting the LDAP endpoint and its TLS server name be configured separately from kdc_host_name.
  • Added a pki_domain option to the database service's AD config, letting the CRL-publishing domain be configured separately from domain.
  • Added tctl plugin support for Github and SCIM plugins.
  • Fixed loss of Bound Keypair token status on update by always preserving the existing token's status, ensuring bots and agents can not have their credentials deleted accidentally.
  • Added support for RDS Proxy discovery configuration in teleport/discovery/aws Terraform module.
  • Added CA override support to SQL Server PKINIT databases. The complete trust chain must be present in the CA override definition, otherwise kinit won't be able to validate its own certificate.
  • Added support for ambient credentials in teleport/discovery/aws Terraform module.
  • Fixed Error parsing application context error when trying to use bash auto completes generated by tbot or teleport-update.
  • Support --iac=terraform for tctl acl create and tctl acl update commands that print the Terraform config for the resulting resources instead of applying the change (dry-run).
  • Improved search in the user pickers to match username only.
  • Fixed tsh scp failing to spawn a SFTP server if the user home directory was not found. Non-existent files will still fail but absolute paths will be handled gracefully.
  • Fixed regression where joining when the token name contains : followed by base64 would result in a not found error.
  • Fixed access request reason requirement (request.reason.mode: required) being ignored when requestable roles were specified with a wildcard, regexp, or claims_to_roles instead of literal role names.
  • Improved output of tctl plugins command.
  • Changed tctl auth crl to export CA override CRLs, in addition to the self-signed CA CRLs.
  • Fixed an issue that prevented the correct version from being displayed for tctl builds on macOS.
  • Added draft, enforce, and 30-minute test run controls to the IP Allowlist panel for Teleport Cloud, backed by new mode and expires fields on the client_ip_restriction resource.
  • Reduced memory allocations on the VNet network stack data path.
  • Improved VNet throughput by increasing the TUN MTU to 16 KiB.
  • Added teleport reconfigure to generate a new agent configuration file from an existing one.
  • Added support for using the tpm join method with scoped tokens.
  • Added scope namespacing to ssh servers.
  • Scoped bots can now issue application-routed certificates through tbot's.
  • Added support for the GitLab CI join method with scoped join tokens, including scoped Bot.
  • Updated Entra ID edit plugin UI to support sync interval configuration.
  • VNet no longer rewrites /etc/resolver files on macOS when the DNS configuration is unchanged.
  • Reduced VNet memory allocations when handling DNS queries.
  • Fixed Redshift automatic user cleanup after a PostgreSQL client disconnects during connection setup.
  • EC2 auto-discovery now fetches instances across AWS accounts and regions concurrently with bounded concurrency.
  • Fixed potential deadlock/segfault when using libnss-extrausers on Linux agents with user creation enabled.

Installer type: zip

x64—47068168A5C587B4A0A506742090F6BDB5931D772A6CE7BF9FCC88EEC7B9303E

Details

License
AGPL-3.0
Copyright
© 2026 Gravitational Inc.; all rights reserved.

Older versions (59)

18.11.0
x64—9E7B4CC7BE7A7806EF91C3CE5F45EE2C0808184B3F4E5CC45C8C673E808DDC95
18.10.7
x64—CB0F0237599F6370FDEC0B1137E10935F967DC84E0871BB0F252ABDD71714EEE
18.10.6
x64—5EE6AA0C22E7D3EE09EAE343535F823292879239910E688485F19C03E91729AB
18.10.3
x64—BB19CDC67310C051FBF850B16CF63F64217E769AD62BF604F827D332118F2945
18.10.1
x64—94FC4F899AF247E97FFD37F9E137ECCE708352B1B86EB140BBE0314EFCE890E8
18.10.0
x64—4F47E100FAB27ACBE440F5413559893BA46BD2A7A5055D19E7906159D7A33341
18.9.2
x64—07A30ACE569476B98C45E064B5CA5CB0665CE6214E545C1F7A826D0130686A16
18.9.1
x64—08174285CE9C4BD1A9C9BD940676B813AB7A8F0F2CFB837844BD89E174B59515
18.9.0
x64—FE4D467BCDAFB915CDC808ED3E821DDA4491F855CC6AC5B72DF2A75799271F07
18.8.3
x64—AB7DAE9F724B83FB8FF553710B408863DCC7ADDF6A5A66E5A865BA5DE6AF8902
18.8.2
x64—25FE9C2DE02CE225F7A090CAA484EA02DE55C4A4192FDD8F7D9862ED058E5908
18.8.1
x64—0182D57C0E7200D14BD8EB7E129FDBFC9B3FF2B0D2F8B990588B199AAEE00FBB
18.8.0
x64—7A56BE438BAE5D7583A60A72B16EC42EB6E43F91B895D499E270519F2E983140
18.7.6
x64—BB29904F88A0764339A7D480D03F4EEFE6E2FC8DFB0A64BAFC44799A45D4C535
18.7.5
x64—E32C0DCF79C7E2BAF24B01F6F594B8EBCC230FDAA774844EE99B8A94C337B418
18.7.4
x64—D44E0B96100414ECD29876C3BC6C4AE982B4A303B2C8B95AC24F3032888A973A
18.7.3
x64—754F67CAC6DBF7B669576A43F495C15DDF61C685AA8F0F606EEE9139CE140F46
18.7.2
x64—3FBF2C1B00E25D6D38DD82C689AFE8DB2B3FB3EB9DDED47DA3BFE1B4E656ECE6
18.7.1
x64—E3EB9BB30CC3DF041133B735A1AD53B9DC0EE8E2CC9F08DF6BCF1461263E1083
18.7.0
x64—DA66C7691182983107C4D6D099D1E05629E4BA342CF941AEFE6E2F398A9A0592
18.6.8
x64—EB1ACA80B41CB2BDD50A49CADFD7A96A196C1F3B10F88E21D1BFFD6B5099F93B
18.6.7
x64—8A1F5FA9F1CF3DE066A74CC9961C127559170E6F812504F94EBCA3204243D652
18.6.6
x64—33C8D177CDF4D104A116248C3C1042C32E6E2E9761E5BF0F021A7F8DCDF6602F
18.6.5
x64—F1B897B7AE1C0A9CFF7652294B0357ACD7D5AB6D2476033D111443690D23FC6B
18.6.4
x64—9776A11BE22D8B92C7B419B447C5C88B9B0229B0A79985AD17AB4DDAE73CB7C8
18.6.3
x64—56F8E2C9852C3DD066262872A90FB3BF80E3001FF1A4C6ED4C6B763355F51A49
18.6.2
x64—F391BB1A49753FAAC46482EF17017638932B8707E6C4E03E5394919A153A2BDE
18.6.1
x64—BB352E1E59EAAA08E57A8D5CED11632C4CEED6C342BFC68F50C4A02949B75BCD
18.6.0
x64—6E9300A4FB8D03AF155D005ED3425628364D0BAEB5E756702A6EF98C316647B2
18.5.1
x64—45E59A21EDC990F1179F879E6425EE9832A00F0F4F90E944071E948A80C950E4
18.5.0
x64—03CFF2913D59FDAD50E6D97113A9B98306EBBD480FB389B3B4D72BDD43B84998
18.4.2
x64—B61830DD1EE3280F62CC059F41268361B73219DC0661D03D00B417E241449007
18.4.1
x64—7C8084071A5C3B1F6EF3BE2280997F8B1C3257E5FB18F53D66459CF653E79186
18.4.0
x64—025F2C736DE3C239CADD24A4C8740E002F059291BBCA96E742D9E1CD5D07F5DC
18.3.2
x64—A789F6AC56EA5A47F44CB5945FA1F87964DDEDBEA4F59DEB17AF614DEFE39D9B
18.3.1
x64—E5361630690EF747CFD6C65A7BBF308D2D079C840870F6D78FF98BE903320D56
18.3.0
x64—EC6146ADC7F7068FC4F12D3DB6017E8C0B0AF04E8E53A2823D9D0133A9F925AC
18.2.10
x64—9AA8B5C9903AE4D130D60C9719604CDCE28D4C01B7E40A7E79474B67904C21BB
18.2.9
x64—7F39D67D59343CE730BB20BFCDBCC27DD2E149240DF0CDFF3F8AE0AC5A92172A
18.2.8
x64—DDE0F1C7E6EE16087017073F27DF5B3A56C24EF82882BC4EF301BCF4B20A7AF2
18.2.7
x64—F6F06A66EE0A32FC1FB4C4D9A5DE850A23E1AE1DA9A7E2253F9BFFC6B3704B5A
18.2.6
x64—B3C0F61AF5626D1E87AAE2850CF675F850C34A9324A230D3671D4D14873C10F3
18.2.5
x64—413C2C43C9CB0FE7C8AB952124FAB6A3FEF6582CA6C655775AB32FD5364FE4E5
18.2.4
x64—DC919C36DA0BDDB385C1A838A85E60638E4EB3D18EAA8A9E0837AEA6F0768643
18.2.3
x64—EAFD7C9038E0FB96A245438852D79A7200CB92FC42C9D2A715940F8527AB9558
18.2.2
x64—B42FF4CBE3A0D3787686750AD9372717B50F0C4FF084FA1319CFBE9A22E9EF76
18.2.1
x64—704D8FDC9C7E805B60F51B434364FE0613A2338A92C3D29A099ED12F63D44314
18.2.0
x64—4D1E9F6D679B90C2703BE3F3BE0850D92200017B8C68569407B68F91E314E87E
18.1.8
x64—04515E8F91ED40667D7AD757D395214A8FD73C4E519CC38685A0E7A5A0591497
18.1.7
x64—E31154E855ACFC7923E56F37705B22922D8B8A13BAFEA73BFB9AB50C60D6662E
18.1.6
x64—D25331140DD3DE3DDC8A1CBA55AA3D9EB527E52691186BCF854380AF5D39E969
18.1.5
x64—290AD0880B2380FAC9C82BD5747A0DAC2D81FCD3899C98456FB71338A09ED2CB
18.1.4
x64—B69ADD42804A88DF2D497807890B32CD3D7AE9FFA515F4A544C193C4BC560A97
18.1.3
x64—18D98C5F0B23A831094BE3BB2F7FBE2BBA0D525BD58B36BB31E64F13EA538A4A
18.1.2
x64—BC256A711C3B47EB897278488228A68C987F57E8957BE1FA0FA3C254D6B51232
18.1.1
x64—CDB69F250F83CFB99EE780CF21F830F4FCE1525747ED60B707BB1A46FB4CC9C7
18.1.0
x64—72EED8A0D2AE5E4463A54B57997DB6A6C36EA3EE1BD07EE3BED96519CFAA7DC4
18.0.2
x64—28CFE1BA3B72567E31B3E2D56E1C4953CB7B54FB948DB6161874A71FC56936BB
18.0.1
x64—0D096B8075F275D80A6CBAE1AB06A0C67DE010FFF8DBD8424195A9B24499D518