Browser-native 5250 terminal

Your IBM i application. In the browser.

Start with the green-screen application you already use. PristineScreen400 adds managed sign-on, exact profile grants, scoped permissions, and secure browser access without requiring a rewrite or screen template.

  • Existing 5250 applications work now
  • IBM i credentials stay server-side
  • White-labeling and templates are optional

Works today. The existing 5250 application runs without a screen template.

Managed access before the host sign-on

Give each person the right IBM i doorway.

The person entering the browser and the IBM i identity doing the work are managed separately. Users see only their assigned grants. PristineScreen400 resolves the protected host credential and opens the live terminal.

  1. 01
    Sign in

    Authenticate with an application account from an approved browser.

  2. 02
    Choose a grant

    Select only from assigned IBM i profiles and approved access.

  3. 03
    Start working

    Open the existing 5250 application without entering its password.

A managed browser identity starts the session.
The user selects an assigned grant, never an arbitrary host identity.

The daily workspace

The live terminal stays at the center.

Operators work in the existing application while approved IBM i tools and observable activity sit beside it. The browser never receives raw hosts, credentials, connector objects, or an unrestricted system API.

One live 5250 session, the tools assigned to this grant, and no screen template required.
Full host interactionFields, keyboard state, function keys, code page, and screen updates
Assigned IBM i toolsJobs, Messages, Spool, IFS, Db2, Objects, and other bounded operations
Responsive accessThe same workspace remains usable on desktop, tablet, and narrow browsers
Observable executionSequenced activity and sanitized outcomes tied to the current workspace

Administration that understands IBM i

Control access around the application, not inside it.

Manage application users, protected IBM i profiles, exact grants, and the capabilities surrounding each terminal. Changes to access revoke affected workspaces without requiring changes to the host application.

Application identities and IBM i profiles remain separate.
Every capability assignment remains visible, scoped, and approval-aware.

Optional presentation

Brand the entry. Modernize only the screens that benefit.

White-labeling and screen templates are independent, opt-in layers. Keep the entire application Classic, apply your brand without changing host screens, or template exact workflows while the RPG program and Db2 state remain authoritative.

Brand the browser entry while the IBM i application remains entirely Classic.

Brand Kit

Make the doorway yours.

Apply your product identity without changing the host application or requiring a screen template.

  • Product name, logo, and favicon
  • Login heading and instructions
  • Approved color palette
  • Support and legal content
  • Assignment to exact user and IBM i grants

Supported public ingress, private host boundary

Open the right terminal without exposing the system behind it.

The browser reaches PristineScreen400 over HTTPS. IBM i targets, credentials, the live 5250 session, and capability execution remain server-controlled inside the isolated deployment boundary.

Explore the security and public access model
PUBLICAuthenticated browserBranded or default HTTPS entry
CONTROLLEDPristineScreen400Identity · grants · terminal · redaction · activity
PRIVATEIBM i applicationAllow-listed TLS services

Bring the IBM i application you already run

Start with managed Classic access. Add optional layers where they help.

We will connect PristineScreen400 to a reviewed environment, demonstrate the live browser terminal, and evaluate branding or selected screen templates only if they fit your users.

Request a demo