Skip to content

Usage

Opening a terminal on your computer

  1. Log in at dev.roamd.co.uk with your email and master password.
  2. My devices lists your computers. A green dot means it's online.
  3. Click Connect. You're now typing on that computer.
 My devices
 +--------------------------------------------------+
 | (o) home-pc      online    [Connect]  [Remove]   |
 | ( ) old-laptop   offline   [Connect]  [Remove]   |
 +--------------------------------------------------+
        green dot = roamd is running there

The first time you connect from a new browser, it already knows your computers: that information travels with your account, encrypted.

Voice and the command box

Under an open terminal there are two extras:

 +--------------------------------------------------------+
 | [Voice]  [ type or dictate a command, then Enter ][Send]|
 | Error: permission denied            <- what Voice said |
 +--------------------------------------------------------+
  • Voice (off until you press it, remembered for each computer): roamd tells you about errors, questions waiting for your answer, and long commands finishing, out loud and on screen. On the Account page you can add your own words to listen for and choose how long a command must run before its finish is announced.
  • The command box: type or dictate a command, check it, press Enter. Handy on a phone. A Speak button appears where your browser can understand speech on the device.

All of this happens inside your browser: nothing is sent to us. More in Voice.

Using another browser or computer

Just log in there with the same email and master password. Your computers and keys come with you. Nothing to set up again.

Locking and logging out

  • Closing the tab locks roamd. Next time, enter your master password again.
  • After 15 minutes without use, the page locks itself.
  • Log out (top right) signs this browser out completely.

Changing your master password

Go to Account → Change master password. You need your current password. Your other browsers are logged out, and your recovery key keeps working.

Forgot your master password?

On the login page choose Forgot password, and enter your email, your recovery key and a new master password. Everything you had is still there.

Keep your recovery key safe

If you lose both your master password and your recovery key, your account can't be recovered, not even by us. That's the price of us never being able to read your data.

Managing a computer (on the computer itself)

Command What it does
roamd keys Shows which browsers may log in to this computer
roamd keys revoke <fingerprint> Stops one of them, immediately
roamd logout Removes this computer from your account
roamd service install Starts roamd automatically when you log in
roamd service uninstall Stops starting it automatically
roamd service status Shows whether it's running
roamd help Lists all commands

Every login attempt on the computer, allowed or refused, is written to a file called access.log in roamd's settings folder, so you can always check who got in.

Removing a computer

Either click Remove next to it in My devices (then Yes, remove), or run roamd logout on the computer. Either way, roamd on that computer stops and can't reconnect. To add it back, run roamd login again.

Web app

Area Behaviour
Sessions Hub session cookie (HttpOnly; Secure; SameSite=Lax, 30 days). The unlocked vault key is kept in sessionStorage for the tab only.
Idle lock 15 minutes without keyboard, pointer or terminal input: the vault key is dropped from the tab, open terminals close. The hub session remains; unlocking re-derives from the password.
Other browsers Log in with email + password; the vault syncs the browser SSH key and pinned host fingerprints. Open browsers pick up vault changes within seconds.
Change password Needs the current password's proof; re-locks the same vault key with a new salt; ends all other sessions.
Recovery Recovery key proves itself to the hub, unlocks the vault key, and a new password re-locks it; all sessions end.
Remove machine The device record and its token are deleted and its tunnel dropped; the pinned identity is removed from the vault.
Voice Per-machine toggle under the terminal; keywords and the "long command" threshold on the Account page. Stored as an encrypted vault item. Narration and speech run in the browser only (see Voice).
Command box Sends its text plus Enter to the open terminal on submit, never before. Optional on-device speech input fills it.

roamd commands

roamd login [--hub URL] [--name NAME] [--config DIR] [--allow-root]
roamd run [--config DIR] [--allow-root]
roamd keys [list] [--config DIR]
roamd keys revoke FINGERPRINT [--config DIR]
roamd logout [--config DIR]
roamd service install|uninstall|status [--config DIR]
roamd help
  • keys revoke rewrites authorized_keys. The running daemon re-reads that file on every login attempt, so the change is immediate. Terminals already open with that key stay open until closed (known gap).
  • logout asks the hub to delete this machine, then deletes device.json and authorized_keys (the host key is kept). If the hub is unreachable, nothing is changed locally.
  • A running roamd run whose token the hub refuses exits with "this machine was removed from its account", instead of retrying forever.

Access log

access.log in the settings folder, owner-only, rotated to access.log.1 automatically:

2026-09-30T08:12:44Z login accepted SHA256:5Jx…
2026-09-30T08:13:02Z login refused SHA256:Qm2…
2026-09-30T08:20:10Z connection closed no login within the time limit
2026-09-30T08:21:00Z connection refused too many connections