Download Lens
Version 4.9.139, published 14 September 2026. One app for macOS, signed and notarized, and a signed installer for Windows. Free to download; every account comes with free server licenses.
macOS
Universal — Intel and Apple Silicon. macOS 12 or later. Signed with LockFlare Corp's Developer ID and notarized by Apple.
Download for macOSLockFlareLens-4.9.139-mac.dmg · 35.6 MB · SHA-256 checksum016f2cb63353fe6d27f07e596773fe83f82fc0e2cc167dfc46a99349452170d5
On first launch macOS asks whether Lens may access files on removable volumes. That is the pen drive: allow it once.
Windows
64-bit Windows 10 or 11. Signed with Azure Trusted Signing, so SmartScreen knows the publisher from the first download.
Download the installerLockFlareLens-4.9.139-win-amd64-installer.exe · 17.6 MB · SHA-256 checksum · Portable exe (45.1 MB)01008cd0b30c01f532c66232c4577794b5a3b19e3fba1c45bf179ef42bc8d542
The Windows build has no biometric step; the pen drive alone is the key.
The first ten minutes
Every screen of it, in order, is on getting started — the account, the key drive and the first server.
Create an account
One form, no card. You get an activation key: paste it into Lens when the door asks. It is written onto your pen drive and carries your free server licenses.
Plug in a pen drive
Any stick under 128 GB. Lens writes your key onto it, bound to this computer, and asks Touch ID once. From now on the stick is how you get in.
Put a server on the map
Add a server, paste a server license, and the address comes with it. Or add a console — any box you can SSH into — for the terminal, files and tunnels with no license at all.
Turn on the backup
Setup → Encrypted backup on my key. Saved logins, certificates, buckets and snippets live only on your computer; the backup is what brings them back on the next one.
What Lens needs from a server
An SSH login. Debian, Ubuntu, Rocky and Alma are the distributions it is proved on — apt and dnf, ufw and firewalld. Root through sudo for anything that changes the box.
What it never needs
An agent, an open port, an account with LockFlare in the path, a network connection to anything but your servers and, if you use Themis, the model provider you chose.
Verifying a download
shasum -a 256 "LockFlareLens-4.9.139-mac.dmg" on a Mac, certutil -hashfile … SHA256 on Windows, against the checksum beside each file.