Skip to main content
You can share individual hosts with people on your team. The recipient gets access to connect to the host using their own master password. Your credential is re-encrypted for them at the point of acceptance.
Sharing requires a Pro subscription. Free accounts cannot send or manage share invites.

Share a host

  1. Right-click a host in the sidebar and select Share.
  2. Pick a recipient from your team roster.
  3. Click Send invite.
If the person you want to share with isn’t on your team yet, add them from the Teams page first, then come back to share. The invite is sent through the API backend. The host payload is encrypted before it is stored.

Accept or decline an invite

Pending invites don’t sit in your host list waiting for you. Click the bell icon in the sidebar: it shows a count of pending invites and opens a dialog to accept or decline each one. Accepting an invite:
  1. Downloads the encrypted host payload.
  2. Decrypts it using the sharing key.
  3. Re-encrypts the credential with your DEK.
  4. Saves the host to your local list, tagged as shared.
Declining rejects the invite. The host is not added. If the host owner has command logging enabled, the accept dialog asks you to confirm before you continue. Accepting means your session activity on that host is recorded and visible to the owner.

Keeping a share up to date

If the owner changes a shared host’s credential, address, or username, every existing share of that host is updated automatically. You never need to be re-invited just because the owner rotated a password.

Revoke access

If you shared a host, open the host’s Sharing tab and find the recipient. Click the trash icon to revoke. The recipient’s local copy of the host is not automatically removed from their device, only their access to it. A revoked invite cannot be turned back on by the recipient. If you want to share with them again, send a new invite.

Limitations

  • You can share a host you own. You cannot re-share a host that was shared with you.
  • There is no permission level. A shared host gives the recipient full connect access.