Usage¶
Opening a terminal on your computer¶
- Log in at dev.roamd.co.uk with your email and master password.
- My devices lists your computers. A green dot means it's online.
- Click Connect. You're now typing on that computer.
My devices
+--------------------------------------------------+
| (o) home-pc online [Connect] [Remove] |
| ( ) old-laptop offline [Connect] [Remove] |
+--------------------------------------------------+
green dot = roamd is running there
The first time you connect from a new browser, it already knows your computers: that information travels with your account, encrypted.
Voice and the command box¶
Under an open terminal there are two extras:
+--------------------------------------------------------+
| [Voice] [ type or dictate a command, then Enter ][Send]|
| Error: permission denied <- what Voice said |
+--------------------------------------------------------+
- Voice (off until you press it, remembered for each computer): roamd tells you about errors, questions waiting for your answer, and long commands finishing, out loud and on screen. On the Account page you can add your own words to listen for and choose how long a command must run before its finish is announced.
- The command box: type or dictate a command, check it, press Enter. Handy on a phone. A Speak button appears where your browser can understand speech on the device.
All of this happens inside your browser: nothing is sent to us. More in Voice.
Using another browser or computer¶
Just log in there with the same email and master password. Your computers and keys come with you. Nothing to set up again.
Locking and logging out¶
- Closing the tab locks roamd. Next time, enter your master password again.
- After 15 minutes without use, the page locks itself.
- Log out (top right) signs this browser out completely.
Changing your master password¶
Go to Account → Change master password. You need your current password. Your other browsers are logged out, and your recovery key keeps working.
Forgot your master password?¶
On the login page choose Forgot password, and enter your email, your recovery key and a new master password. Everything you had is still there.
Keep your recovery key safe
If you lose both your master password and your recovery key, your account can't be recovered, not even by us. That's the price of us never being able to read your data.
Managing a computer (on the computer itself)¶
| Command | What it does |
|---|---|
roamd keys |
Shows which browsers may log in to this computer |
roamd keys revoke <fingerprint> |
Stops one of them, immediately |
roamd logout |
Removes this computer from your account |
roamd service install |
Starts roamd automatically when you log in |
roamd service uninstall |
Stops starting it automatically |
roamd service status |
Shows whether it's running |
roamd help |
Lists all commands |
Every login attempt on the computer, allowed or refused, is written to a file called
access.log in roamd's settings folder, so you can always check who got in.
Removing a computer¶
Either click Remove next to it in My devices (then Yes, remove), or run
roamd logout on the computer. Either way, roamd on that computer stops and can't
reconnect. To add it back, run roamd login again.
Web app¶
| Area | Behaviour |
|---|---|
| Sessions | Hub session cookie (HttpOnly; Secure; SameSite=Lax, 30 days). The unlocked vault key is kept in sessionStorage for the tab only. |
| Idle lock | 15 minutes without keyboard, pointer or terminal input: the vault key is dropped from the tab, open terminals close. The hub session remains; unlocking re-derives from the password. |
| Other browsers | Log in with email + password; the vault syncs the browser SSH key and pinned host fingerprints. Open browsers pick up vault changes within seconds. |
| Change password | Needs the current password's proof; re-locks the same vault key with a new salt; ends all other sessions. |
| Recovery | Recovery key proves itself to the hub, unlocks the vault key, and a new password re-locks it; all sessions end. |
| Remove machine | The device record and its token are deleted and its tunnel dropped; the pinned identity is removed from the vault. |
| Voice | Per-machine toggle under the terminal; keywords and the "long command" threshold on the Account page. Stored as an encrypted vault item. Narration and speech run in the browser only (see Voice). |
| Command box | Sends its text plus Enter to the open terminal on submit, never before. Optional on-device speech input fills it. |
roamd commands¶
roamd login [--hub URL] [--name NAME] [--config DIR] [--allow-root]
roamd run [--config DIR] [--allow-root]
roamd keys [list] [--config DIR]
roamd keys revoke FINGERPRINT [--config DIR]
roamd logout [--config DIR]
roamd service install|uninstall|status [--config DIR]
roamd help
keys revokerewritesauthorized_keys. The running daemon re-reads that file on every login attempt, so the change is immediate. Terminals already open with that key stay open until closed (known gap).logoutasks the hub to delete this machine, then deletesdevice.jsonandauthorized_keys(the host key is kept). If the hub is unreachable, nothing is changed locally.- A running
roamd runwhose token the hub refuses exits with "this machine was removed from its account", instead of retrying forever.
Access log¶
access.log in the settings folder, owner-only, rotated to access.log.1 automatically:
2026-09-30T08:12:44Z login accepted SHA256:5Jx…
2026-09-30T08:13:02Z login refused SHA256:Qm2…
2026-09-30T08:20:10Z connection closed no login within the time limit
2026-09-30T08:21:00Z connection refused too many connections