roamd¶
Dev preview
roamd is in early development. This site describes the preview running at dev.roamd.co.uk, which is behind a shared access password while we test it.
Every page has a Simple and a Technical version. Pick one with the tabs below; your choice carries over as you move between pages.
roamd lets you use your own computers from any web browser: your home PC, your work laptop, a Raspberry Pi. You open a website, click your computer, and get its command line, as if you were sitting in front of it.
Everything between your browser and your computer is locked with encryption that only you hold the keys to. We run the website that connects the two, but we can't see what you type, what comes back, or your saved keys.
Your browser roamd website Your computer
(anywhere) (just passes on (running roamd)
locked messages)
+-----------+ locked +------------------+ locked +-------------+
| you type | ==========> | can't read it | ========> | it runs |
| you see | <========== | | <======== | your |
+-----------+ +------------------+ | command |
+-------------+
Where to start
- New here? Read the User manual: installing, using roamd, and fixing problems.
- Wondering whether it's safe? Read How it works: what we store, what's encrypted, and what we can and can't see.
roamd is remote shell access to your own machines from a browser, with end-to-end encryption between the browser and the machine.
- A small agent,
roamd, runs on each machine (Linux, macOS, Windows). It keeps an outbound WebSocket to the hub, so no inbound ports, port forwarding or VPN are needed. - The browser speaks SSH itself (a Rust SSH client compiled to WebAssembly). The hub only relays ciphertext between the browser's WebSocket and the machine's tunnel.
- Accounts are zero-knowledge. The browser derives keys from the master password (Argon2id), and the hub stores only a proof hash and data sealed with XChaCha20-Poly1305. The browser's SSH key lives in that vault.
- Machines are paired by a device-code flow plus a pairing code both screens show. The machine trusts only browser keys the user confirmed on the machine; the browser pins the machine's host key.
browser (wasm SSH client) hub machine (roamd)
------------------------ ---------------------- -----------------------
vault: SSH key, pins ---> accounts, sealed vault
device routing
SSH (end to end) =====wss====> splice <====wss (outbound)==== SSH server
Manuals
- User manual: installation, usage, troubleshooting (including exact error messages).
- How it works: architecture, cryptography, threat model and known limits.