Porthole
Peer-to-peer · nothing touches the server

Share your terminal, peer to peer

Run one command, share a link. Your terminal streams straight to a browser — or to someone else's terminal — over an encrypted WebRTC connection. No terminal data ever passes through a server.

your machine
$porthole host --mask
Codep3rx-9kma
Linkporthole.sh/s/p3rx9kma
● Streaming… (Ctrl+] ? for commands)
$echo $GITHUB_TOKEN
ghp_16C7e42F292c6912E7710c8383
their browserread-only
Connected — watching p3rx-9kma
$porthole host --mask
$echo $GITHUB_TOKEN
[redacted:github_token]
The signaling server introduced these two, then stepped aside. It cannot read either — and with --mask, neither can the person watching.

Join a session

Have a code?

Paste the code or link your host shared, and jump straight into their terminal — nothing to install.

How it works

A handshake, then the server steps aside

The signaling server only introduces the two peers. After that, terminal data travels directly — it never sees your session.

1

Run porthole host

The agent spins up a PTY on your machine and registers a short-lived session with the signaling server.

2

Share the link

You get a link, code, and QR. The viewer opens it in any browser — desktop or mobile — and the two peers negotiate a connection.

3

Stream peer to peer

Once the WebRTC DataChannel opens, the server drops out. Keystrokes and output flow directly between host and browser.

Two ways to watch

A browser tab, or a terminal

Both ends speak the same protocol. The host does not choose for you, and the server cannot tell the difference.

For anyone

In a browser

Send a link. There is nothing to install on the watching end — the viewer is a web page that speaks WebRTC straight to your machine.

https://porthole.sh/s/p3rx-9kma
  • Works on any modern browser, desktop or phone
  • Accessory key bar supplies Esc, Ctrl, Tab and arrows on touch
  • Session context, connection quality, and fullscreen built in
Browser viewer

For developers

In a terminal

The same peer-to-peer channel, rendered by your own terminal emulator instead of a canvas. Architecturally this is SSH's arrangement, so it behaves like it.

$ porthole join p3rx-9kma
  • vim, htop, less and tmux at full fidelity
  • Your own scrollback, font, colours, and selection
  • Record what you are shown with --record
Terminal viewer

Security & privacy

Terminal data never touches the server

Porthole was built privacy-first. The architecture makes eavesdropping not a policy you trust, but a thing that can't happen.

The server never sees your terminal

Signaling brokers the connection and then gets out of the way. Terminal bytes travel peer to peer — there is nothing to log, store, or leak.

Encrypted end to end

WebRTC DataChannels are encrypted with DTLS by default. The stream between your machine and the browser is private in transit.

Enforced at the source

Read-only and password rules are applied by the agent on your machine — not trusted to the viewer — so a tampered client can't bypass them.

Install

Up and running in one command

One binary does both jobs: porthole host to share, porthole join to watch. Whoever is watching in a browser installs nothing at all.

$ curl -fsSL https://assets.porthole.professorhusnain.com/install.sh | sh

Prefer to build from source, or want every flag? Read the docs

Share your next session in seconds

Install the agent, run one command, send the link. That's the whole thing.