3270 · 5250 · SSH
Point WebTerm/3270 at a host and you get a real green screen: TN3270 and TN3270E for z/OS and VM, TN5250 for IBM i, SSH for everything around them. No emulator to install, no Java, no HOD profile to hand around. The full tier adds passive ESM fingerprinting and a stack of mainframe recon and probe tools, built into the same client.
what it is
Most shops still run a fat desktop emulator per person, each with its own keyboard map and its own copy of the host list. WebTerm/3270 is that emulator, moved to the server and reached over the web.
The client is a web page. No install, no Java runtime, no per-machine config. Works the same on a locked-down laptop as on your own.
Field attributes, extended colour and highlighting, structured fields, GDDM graphics, the OIA. It renders what the host actually sends, not an approximation.
Session profiles, macros and SSH host lists live with the account. New teammate, one login, same connections.
how a session works
Sign in and open the client.
The terminal loads in the tab. Your saved session profiles are already
in the list.
Choose 3270, 5250 or SSH and connect.
The bridge dials the host, negotiates the protocol, and streams the
screen back over one WebSocket. Every connect is written to an audit row.
Work the screen.
Full keyboard map with PF and PA keys, record and replay, macros,
file transfer. Close the tab when you're done.
security tooling
The full tier turns the client into an assessment tool. It reads what the host already puts on the wire, runs recon from an ordinary login, and probes where you have permission to, on z/OS, z/VM, CICS, DB2, z/TPF and IBM i.
IND$FILE transfers
are flagged one by one.LISTAPF + LISTDSD),
SYS1.PARMLIB read-access test, DFSMS at-rest encryption audit.WRKSYSVAL), user and Q* profiles, object
authority, network attributes (DSPNETA: JOBACN(*FILE),
DDMACC(*ALL)), job descriptions, authorization lists, active jobs.DFHAC2001 "not authorized" confirms a
transaction is defined, even when you can't run it.LINK password typed at the CP READ
prompt renders in cleartext, CP has no masked input for command arguments.Drive it from an AI assistant. The same tooling is exposed as an MCP server, sixteen tools over the bridge's WebSocket, so an assistant can connect, read screens and field maps, send keys, run macros headless, and pull the ESM fingerprint. v1 is loopback-trust.
tiers
Every tier is the full terminal. What changes is what you can point it at and which tooling comes with it. Current pricing shows when you create an account.
Authorized use only. Gated behind an acceptance and manual review.
who runs it
WebTerm/3270 is built and operated by Two Women and an Acre LLC.
It does one job and is kept deliberately small. Support is a person answering email, not a ticket queue, and the people who answer are the people who wrote it.
questions
Nothing. WebTerm/3270 runs in the browser. There is no desktop emulator, no Java runtime, and no HOD or PCOMM-style local configuration. You sign in and the session opens in a tab.
TN3270 and TN3270E for z/OS and VM, TN5250 for IBM i, and SSH for the surrounding Linux and USS work. One client, one keyboard map, all three.
The hosted service can reach any internet-facing host. A private, on-premise system needs a connector running inside your own network, which is on the roadmap. Systems with a public endpoint work today.
Passive ESM fingerprinting and session-crypto analysis; RACF policy, user, group and
dataset recon from a TSO READY prompt; APF library and SYS1.PARMLIB
exposure checks; a full IBM i assessment across system values, profiles, object
authority, network attributes and authorization lists; a credential probe and a CICS
transaction scanner; a 3270 protocol fuzzer; datastream checks for field-length
disclosure, cross-session buffer bleed and VM minidisk password exposure; and an MCP
surface so an AI assistant can drive it.
It is for testing systems you own or are explicitly authorized to test. The full tier is gated behind an authorized-use acceptance and a manual account review, every connection the service makes is written to an append-only audit row with the account, client IP and target, and using it against a system without authorization is a misuse of the service.
WebTerm/3270 is operated by Two Women and an Acre LLC, a small US company. Support is a real person answering email.