CluTerm
formerly CludCode
Your machines, as one encrypted computer
All your machines act as one end-to-end encrypted computer you open in a browser. Terminals, files, containers, screen share with remote input, and your own AI across all of it. The relay carries the traffic and holds no key. A Rust agent on every machine, a web client, a desktop app.
The problem
You're on your phone or a tablet. You need to run something on your dev machine — deploy a fix, check logs, run Claude Code. SSH is painful on mobile. VS Code Remote requires a full IDE. CluTerm gives you every machine you own in your browser, with end-to-end encryption and zero configuration.
How it works
-
Install a lightweight agent on your machine (curl | sh, auto-updates)
-
The agent dials out to the relay over WebSocket — no port forwarding, no open ports
-
AES-256-GCM end to end, with keys agreed per session over X25519 — the relay sees ciphertext and routing metadata only
-
Open cluterm.com in any browser, on any device
-
Sessions start on the relay, then upgrade to a direct WebRTC path — LAN or peer-to-peer, with TURN in between
-
The Rig: every machine, terminal, container, and file view in one workspace
-
Screen share with remote input — H.264 frames and keystrokes travel peer-to-peer over WebRTC, never through the relay
In action
Screens from the CludCode era, before the rename.
Architecture
Components that never have to trust each other. The relay is a zero-knowledge proxy: it forwards encrypted bytes without ever holding a key. Each device key is generated on the machine and never leaves it.
your screens: Browser (cluterm.com, on any device), Desktop app (Electron). Relay (Node.js · forwards ciphertext, holds no key). Rust agent, on every machine: Terminals (native PTY multiplexer), Files (tree + editor, stays on disk), Containers (Apple container · Podman · Docker), Screen (H.264 over WebRTC), MCP server (40+ tools for Claude). WebRTC direct path: LAN or peer-to-peer, TURN in between. Terminals upgrade to it; screen share lives on it.
- Device keys live in the OS keystore: Keychain, Secret Service, DPAPI.
Key decisions
-
Agent initiates outbound
no port forwarding, no firewall config, works behind any NAT
-
Per-session forward secrecy
a fresh X25519 key for every session, so compromising one reveals nothing about the others
-
Agent rewritten from Bun to Rust
one static binary across macOS, Linux, and Windows, lower memory, no runtime to ship
-
Relay first, direct second
every session connects instantly through the relay, then moves to the fastest direct path it can find
-
A native Rust PTY multiplexer replaced tmux as the default
one less dependency on every machine
-
MCP server on every agent
40+ tools across terminals, files, and containers, registered in Claude Code automatically
-
Security audits close classes, not instances
host-input and credential-state holes made impossible by construction