Share your terminal, peer to peer
Run one command, share a link. Your terminal streams straight to a browser — or to someone else's terminal — over an encrypted WebRTC connection. No terminal data ever passes through a server.
--mask, neither can the person watching.Join a session
Have a code?
Paste the code or link your host shared, and jump straight into their terminal — nothing to install.
How it works
A handshake, then the server steps aside
The signaling server only introduces the two peers. After that, terminal data travels directly — it never sees your session.
Run porthole host
The agent spins up a PTY on your machine and registers a short-lived session with the signaling server.
Share the link
You get a link, code, and QR. The viewer opens it in any browser — desktop or mobile — and the two peers negotiate a connection.
Stream peer to peer
Once the WebRTC DataChannel opens, the server drops out. Keystrokes and output flow directly between host and browser.
Two ways to watch
A browser tab, or a terminal
Both ends speak the same protocol. The host does not choose for you, and the server cannot tell the difference.
For anyone
In a browser
Send a link. There is nothing to install on the watching end — the viewer is a web page that speaks WebRTC straight to your machine.
https://porthole.sh/s/p3rx-9kma- Works on any modern browser, desktop or phone
- Accessory key bar supplies Esc, Ctrl, Tab and arrows on touch
- Session context, connection quality, and fullscreen built in
For developers
In a terminal
The same peer-to-peer channel, rendered by your own terminal emulator instead of a canvas. Architecturally this is SSH's arrangement, so it behaves like it.
$ porthole join p3rx-9kma- vim, htop, less and tmux at full fidelity
- Your own scrollback, font, colours, and selection
- Record what you are shown with --record
Features
Built for how sharing a shell actually goes
Someone joins mid-incident, needs context, needs to type for two minutes, and should not see your AWS keys on the way past.
Security & privacy
Terminal data never touches the server
Porthole was built privacy-first. The architecture makes eavesdropping not a policy you trust, but a thing that can't happen.
The server never sees your terminal
Signaling brokers the connection and then gets out of the way. Terminal bytes travel peer to peer — there is nothing to log, store, or leak.
Encrypted end to end
WebRTC DataChannels are encrypted with DTLS by default. The stream between your machine and the browser is private in transit.
Enforced at the source
Read-only and password rules are applied by the agent on your machine — not trusted to the viewer — so a tampered client can't bypass them.
Install
Up and running in one command
One binary does both jobs: porthole host to share, porthole join to watch. Whoever is watching in a browser installs nothing at all.
$ curl -fsSL https://assets.porthole.professorhusnain.com/install.sh | shPrefer to build from source, or want every flag? Read the docs
Share your next session in seconds
Install the agent, run one command, send the link. That's the whole thing.