macOS · Identity-Aware Proxy

IAP Desktop for Mac

Google's IAP Desktop only runs on Windows. Ostgate is a native macOS app that does the same job over the same Identity-Aware Proxy TCP forwarding: SSH terminals, Remote Desktop, SFTP and tunnels to Compute Engine VMs that have no public IP, from one window on your Mac.

Updated

Version 0.0.1 · Apple Silicon · macOS 26.3+ · 7-day free trial · no gcloud needed

What IAP Desktop is, and why Mac users go without it.

IAP Desktop is Google's free, open-source desktop client for Identity-Aware Proxy TCP forwarding. You sign in with your Google account, browse your projects and VM instances, and double-click one: IAP carries the connection to a VM with no external IP, so there is no bastion host and no VPN. It opens Remote Desktop and SSH sessions as tabs, manages tunnels to other ports, generates Windows credentials, and shows a VM's serial output and event log.

It is a Windows application, built on Windows' own Remote Desktop control, and there is no macOS version. Teams with a mix of Windows and Mac laptops end up with one good workflow and one improvised one.

What reaching a private VM from a Mac looks like today.

Without IAP Desktop, a Mac user installs the Google Cloud SDK and stitches three tools together: gcloud to open the tunnel, a terminal to hold it open, and Microsoft's Windows App (formerly Microsoft Remote Desktop) or an SSH client pointed at a port on localhost. Every tunnel costs a terminal window, every local port is picked by hand, and when a connection fails you get a closed socket rather than the missing IAM role or firewall rule.

Today, with gcloud

$ gcloud compute start-iap-tunnel win-01 3389 \
    --local-host-port=localhost:13389 \
    --zone=europe-west1-b --project=acme-prod
# keep that running, then point Windows App at localhost:13389

Generate a Windows password in the Cloud Console, copy it into a second app, and repeat for every VM and every port.

With Ostgate

$ ssh web-01.europe-west1-b.acme-prod.gcp

Or double-click the instance: SSH for Linux, RDP for Windows, in a tab. Ports are allocated for you, credentials can be saved in the Keychain, and a failure names what to fix.

The IAP Desktop workflow, rebuilt for macOS.

Ostgate runs entirely on your Mac and calls Google's APIs as you. There is no Ostgate server in the path of your connections, and it never reads or runs gcloud.

Ostgate's Resources view: a sidebar with two Google accounts, and a table of Compute Engine VMs grouped by project, each with status, zone, internal IP and OS, one marked as a favorite and three with a live session.
Resources: projects and instances

SSH terminals

A terminal tab per instance. Your key is generated on your Mac, in the Secure Enclave where available, and published through OS Login or instance metadata. Password or private-key-file sign-in covers appliances without OS Login.

Remote Desktop

Windows desktops as tabs, with text clipboard sync, shared folders, resize that follows the window and Type Clipboard Text for login screens. Generate password in the credential form, or Set Windows Password… on the instance, creates or resets an account, and saved credentials sign you in automatically.

Ostgate's RDP tab for win-example before connecting: a credential form with Username acme-admin, Domain None (local account), an empty Password field, a Save password for this VM checkbox, Shared folder None with a folder button, and Generate password and Connect buttons.
RDP credential form

Tunnels to any port

Forward any VM port to 127.0.0.1, or start from a preset such as PostgreSQL, MySQL, SQL Server or HTTP. Each keeps its local port between runs, and Copy Command gives you the client line.

Ostgate's Connections view listing IAP tunnels to PostgreSQL on port 5432, RDP on 3389 and HTTP, each with its local 127.0.0.1 port, who may connect, and whether it is listening or in use, above two running forward profiles.
Connections: tunnels and forwards

Files over SFTP

Browse Files opens a VM's file system in a tab. Drag files in to upload and out to Finder to download, or drop one on a terminal.

Serial output, event log, SSH keys

Read COM1, COM3 and COM4 for a VM that never reaches SSH, list its last 7 days of audit events, and see and delete the SSH keys that can sign in to it.

Settings that inherit

SSH and RDP options set once for an account, project, zone or VM, the narrowest winning field by field. Passwords stay in the Keychain or come from Secret Manager.

Ostgate and IAP Desktop, compared honestly.

Where IAP Desktop does something Ostgate does not, the table says so. It compares Ostgate 0.0.1 with IAP Desktop 2.50.

FeatureIAP DesktopOstgate
Runs onWindowsmacOS 26.3+, Apple Silicon
Price and sourceFree, open source7-day trial, then a licence key (pricing coming soon); closed source
Several Google accounts at onceYesYes
SSH terminal tabsYesYes
SSH password sign-inYes, plus keyboard-interactivePassword only
SFTP file browserYesYes, files only; no folder transfers yet
Authorized SSH keys listYesYes
Embedded Remote DesktopYesYes
Windows password generationYesYes
RDP clipboard, shared drives, resizeYesYes
RDP type clipboard textYesYes
RDP colour depth, resolution, NLA, admin session, Restricted Admin, audioYesYes
RDP microphone, printers, smart cards, COM and LPT ports, plug-and-play devicesYesNo
RDP system-shortcut settingYesNo
Tunnels to any port, with presets and sticky local portsYesYes
Launch a client app with the tunnel (.iapc files)YesNo; Copy Command gives the client line
Inherited connection settingsYesYes
Connect over VPN or Interconnect instead of IAPYesNo, IAP only
Serial port outputYesYes
Event logYesYes, per instance, last 7 days
Start and stop VMsYesYes
Cloud SQLThrough a Cloud SQL proxy VMThrough any running VM in the VPC, no proxy VM
Loopback access control per tunnelYesYes: Ostgate only, my processes, or any local process
Open by iap-rdp:/// URLYesNo
Join a VM to Active DirectoryYesNo
Certificate-based access (mTLS)YesNo
Private Service Connect endpointYesNo
Central policy managementYes, group policiesNo

What Ostgate adds on a Mac. One click writes an ~/.ssh/config block, so ssh, scp and your IDE reach any instance by name through IAP. Forward profiles carry several ports to anything a chosen VM can route to over one SSH session, such as an internal load balancer or a private database. Internal-only Cloud Run services open in your browser through a local proxy, and Connection Doctor names the missing role or firewall rule when a connection fails.

IAP Desktop alternatives on a Mac.

Without a Mac version of IAP Desktop, people reach private Compute Engine VMs from macOS in one of four ways. All but the third keep Google's Identity-Aware Proxy, which costs nothing for Compute Engine, and the IAM roles you already have.

ApproachWhat you installSSH and RDPTunnels
gcloud and a terminalThe Google Cloud CLI, plus a separate RDP client such as Windows Appgcloud compute ssh --tunnel-through-iap in Terminal; for RDP, a start-iap-tunnel left running and the RDP client pointed at localhostOne terminal window per tunnel, each local port picked by hand
Open-source GUI wrappers around gcloudThe Google Cloud CLI signed in with Application Default Credentials, plus the wrapperHanded off to Terminal and to a separate RDP clientStart and stop gcloud tunnels from a window
Access products that replace IAPAn agent or connector in your VPC and a client on each Mac, usually per-user pricingThrough the product's own gateway instead of IAPThrough the product's own gateway
OstgateOne app; no gcloud, nothing on your VMsBuilt in: SSH tabs, an embedded Remote Desktop with Windows password generation, SFTPBuilt in, with presets, sticky local ports and forwards to internal addresses

From a Google Cloud project to a first connection.

If your project already works with IAP Desktop, skip the first step: the IAP setup is exactly the same.

  1. Prepare the project. Allow ingress from 35.235.240.0/20 to ports 22, 3389 and any others, and grant roles/iap.tunnelResourceAccessor. See Prepare your project.
  2. Install and sign in. Drag Ostgate to Applications and sign in with Google in your own browser. See Install and sign in.
  3. Pin projects and connect. Pin your projects in Resources, then double-click an instance. See Find your instances, SSH and Remote Desktop.
  4. Add tunnels and ssh. Forward other ports, or use ssh from Terminal. See Tunnels and forwards and Use ssh from Terminal.

Ostgate for macOS.

A disk image for Apple Silicon Macs running macOS 26.3 or later. Drag the app to Applications, launch it, and sign in with the Google account that already has access to your projects.

Version 0.0.1 · 30 September 2026 · signed and notarized by Apple

Apple Silicon · macOS 26.3+ · 7-day free trial

What people ask when they switch from IAP Desktop.

Is there a Mac version of IAP Desktop?

No. Google's IAP Desktop is a Windows application. On a Mac, the route Google documents is the gcloud command line. Ostgate is a separate, native macOS app that connects to the same VMs through the same Identity-Aware Proxy TCP forwarding.

What are the alternatives to IAP Desktop on a Mac?

The gcloud command line with Terminal and a separate RDP client; open-source GUI wrappers that still need gcloud; access products that replace IAP with their own agents and gateway; or a native client such as Ostgate, which opens IAP tunnels itself and has SSH, Remote Desktop, SFTP and port tunnels built in.

Is Ostgate made by Google?

No. Ostgate is independent and is not affiliated with, endorsed by or sponsored by Google. It talks to Google's public APIs and to the IAP tunnel endpoint as the Google account you sign in with.

Do I need gcloud installed?

No. Ostgate signs in with your Google account in your own browser and opens IAP tunnels itself. It never reads or runs gcloud, so you do not need the Google Cloud SDK on your Mac.

Does my project need different setup than for IAP Desktop?

No. The setup is the same: a firewall rule that allows ingress from 35.235.240.0/20 to the ports you use, and roles/iap.tunnelResourceAccessor for each person who connects. Nothing is installed on your VMs.

Can I keep using ssh, scp and my IDE?

Yes. One click in Settings adds a block to ~/.ssh/config, after which ssh, scp and an IDE's remote session reach INSTANCE.ZONE.PROJECT.gcp through IAP, with Ostgate's window closed.

Which Macs does Ostgate run on?

Apple Silicon Macs running macOS 26.3 or later. Intel Macs are not supported. Every Mac starts with a 7-day free trial, then needs a licence key.