What is it?
Apache Guacamole is a remote desktop gateway you use from a web browser. You log in to a web page, pick a machine from your list, and the Guacamole server opens the RDP, VNC, SSH, telnet or Kubernetes session on your behalf. The project calls itself "clientless": the user's computer needs no plugin and no client software.
The difference from RustDesk and MeshCentral is on the target side. RustDesk runs its own application on the machine you control, and MeshCentral installs an agent there. Guacamole installs nothing on the target: it talks to the RDP, VNC or SSH server the machine exposes. The open source remote desktop comparison details what each approach asks of the network and the server.
Why is it interesting?
- A browser is enough: the client is an HTML5 application the server sends to the browser, mobile browsers included, with an on-screen keyboard that sends Ctrl-Alt-Del to the remote machine without triggering it on your own.
- Desktops and terminals in one list: guacd loads each protocol as a plugin, so moving from an RDP desktop to an SSH shell happens in the same tab.
- Pick your authentication: a database, Active Directory and LDAP, TOTP or Duo as a second factor, single sign-on through CAS, OpenID Connect, SAML or smart cards, RADIUS.
- Recorded sessions: every protocol can be recorded graphically, played back in the browser or turned into a video with
guacenc. Since 1.6.0, an audit permission grants read-only access to the history. - Sharing and file transfer: the Share menu generates a link to the running session. Files move by drag and drop, over SFTP, or through the virtual drive Guacamole emulates for RDP.
- Reusable libraries: guacamole-common (Java) and guacamole-common-js embed a remote desktop in another web application.
Good to know
Three components in production. First comes guacd, the C daemon that speaks the remote desktop protocols. Built from source, it only enables a protocol if the matching library is installed: FreeRDP 2.0.0 or later for RDP, libssh2 for SSH, libVNCServer for VNC. Second is the Java web application from the guacamole-client repository, a .war deployed into Tomcat or another servlet container. Third is the account database. The default authentication, a single user-mapping.xml file, is "not intended for production use", and the documentation highly recommends MariaDB/MySQL, PostgreSQL or SQL Server instead. The database is what adds the web admin interface, sharing links and load-balancing groups. The official Docker images split guacd and the web application, and the latter will not start until at least one authentication mechanism is configured.
Targets must be reachable from the gateway. The guacd daemon opens the connection to each RDP, VNC or SSH server itself, "on behalf of the user" in the words of the architecture documentation. Every machine has to run that server and be reachable from guacd's network. MeshCentral works the other way round: its agent dials out to the server, so a machine behind NAT stays reachable without opening a port on its side.
An Apache Software Foundation project with no commercial tier of its own. Support goes through the project's mailing lists and JIRA. The Guacamole support page lists third-party companies that sell support, and states that the foundation has neither endorsed nor vetted them.
A 1.6.1 in the works, fifteen months after 1.6.0. The latest release is 1.6.0, published on 22 June 2025. From 1.0.0 (January 2019) to 1.5.0 (February 2023), at least one minor version shipped every year; the next one took twenty-eight months and five 1.5.x patch releases. In September 2026 both repositories received fixes on a staging/1.6.1 branch, with no release published as of 7 October 2026.
