Secure self-hosted remote access for businesses. Users sign in and connect to the business computers they've been granted access to. That's it. Managed by Luna β a very good German Shepherd Dog.
β If Rem0te is useful to you, a star helps others find it!
Rem0te is: a business remote-access product. One Rem0te operator hosts the platform and creates customer businesses; each business has its own owners, users and computers, and nothing is shared between them.
Rem0te is not: an RMM, and not a reseller hierarchy. No patch management, no software inventory, no ticketing, no monitoring dashboards. RustDesk is the underlying remote-desktop transport β an implementation detail hidden from the customer experience.
REM0TE PLATFORM
|
+--------------+---------------+
| |
ACME Manufacturing Smith Accounting
(a Business) (a Business)
| |
Users Users
β β
Computers Computers
PLATFORM ADMIN
Full platform access
|
v
BUSINESS OWNER / ADMIN
Full business control
|
v
BUSINESS USER
Permissions assigned by owner
Three levels. That's all of it.
| Level | Scope |
|---|---|
| Platform Admin | The Rem0te operator. Creates and manages every business, sees every computer, owns all platform settings and infrastructure. |
| Business Owner | Full administrative control of one business β its computers, its people, its sessions, its audit history. Cannot see any other business. |
| Business User | Exactly the capabilities the Business Owner granted. Nothing else. |
A Business is the security boundary, and it is enforced server-side on every request. Hiding a button in the UI is a courtesy; changing a URL or calling the API directly still gets refused.
| Group | Permissions |
|---|---|
| Computers | View computers Β· Remote connect Β· Add computers Β· Remove/revoke computers Β· Rename/edit computers |
| Support | Use Quick Connect Β· View active sessions Β· View session history |
| Users | View business users Β· Manage business users |
| Audit | View business audit log |
New Business Users start with View computers and Remote connect on; everything more administrative is off until granted. A Business Owner implicitly holds all of them; a Platform Admin holds everything.
Quick Connect is a permission, not a role.
- Log in.
- Land on My Computers β the PCs they've been authorized for.
- Click Connect. Rem0te fetches the credentials and launches RustDesk with the password pre-filled.
No RustDesk ID typing, no password copy-paste, no server configuration.
- Users β add, disable, remove business users, and set exactly what each one can do.
- Computers β every computer in the business, its assigned users, its status.
- Downloads β Managed Device Installer bound to this business; Quick Connect client for one-off support.
- Sessions / Audit β what happened in this business, and when.
- Business Settings β the business profile.
- Businesses β create, edit, disable and (when empty) delete every customer business.
- Computers β search and manage computers across every business, including unassigned ones.
- Access Control β the three-level model, business users, and platform admins.
- Settings β RustDesk infrastructure, branding, MFA policy, and the Quick Connect master switch.
- Security / System Status / Updates β the platform itself.
Temporary support access to a machine that is not an enrolled managed computer.
Person needing help β https://your-rem0te/quick β downloads the Quick Connect client
β
Runs it. No install, no account, no service.
β
Client shows: Remote ID 123 456 789
Password A7k9X2
Status Waiting for connection
β
They read both out to the person helping them
β
Authorized Rem0te user β Quick Connect β enters ID + password β Connect
β
RustDesk session. Closing the client ends it.
- No permanent enrollment. No
Endpointrow is created; nothing becomes a managed device. - The client is preconfigured for your RustDesk server, so nobody types a relay host, ID server or key.
- The password is never stored, never logged, never put in a URL. The remote person choosing to read it out is what authorises the session.
- Three switches must all be on: platform master switch β per-business switch β the user's
Use Quick Connectpermission.
Every session start and end is audited with the user, their business, the remote RustDesk ID and the source IP. Passwords, clipboard contents, keystrokes and screen contents never are.
Admin β Add Computer β pick company + users β Generate Installer
β
one-time PowerShell / bash command
β
Run once on target PC
β
Downloads + installs RustDesk (config baked in via MSP renamed-installer)
β
Registers with Rem0te using a customer-bound token
β
Server stamps company + user access from the token β endpoint has no say
β
Computer appears in the correct company; assigned users see it
β
Employee clicks CONNECT
The endpoint that redeems the enrollment token cannot influence which company it lands in or who gets access β those are stamped from the token at mint time and validated server-side.
POST /api/v1/endpoints/:id/connect authorizes the caller via ComputerAccess (or COMPANY_WIDE + membership) and returns {rustdeskId, password}. The browser copies the password to the clipboard and launches rustdesk://connection/new/<id>?password=<url-encoded>. Modern RustDesk builds honor the URI password (truly one click); older builds fall back to the clipboard paste. Every reveal is audited.
| Threat | Control |
|---|---|
| Cross-business data access | Every business-scoped read and write resolves through AccessControlService; object lookups by id go through assertEndpointInScope / assertBusinessInScope / assertUserInScope before anything is read. Proven by apps/api/scripts/e2e-business-access.mjs (82 checks). |
| Privilege escalation | Nobody can edit their own permissions or level. Only a Platform Admin can create a Business Owner. Capability strings are allowlisted before they reach the database. |
| Quick Connect abuse | Platform master switch β per-business switch β per-user capability, all re-checked server-side on every call. Denials are audited. |
| API key over-reach | Every key is bound to exactly one business and acts as a Business Owner within it only β never a Platform Admin. Keys predating business scoping were revoked by migration 0009. |
| Endpoint password exposure | Ciphertext never leaves the server. Plaintext only via authorized getPassword / connect β throttled, MFA-gated, audited (ENDPOINT_PASSWORD_REVEALED) |
| Enrollment token abuse | 256-bit random, SHA-256 hashed at rest, one-time, TTL-bound, atomic redemption |
| Stale JWT after role change | JWT re-checks user.isPlatformAdmin, tenant.isActive, membership.isActive on every request |
| Recovery-code brute force | 5/min throttle + per-user 5-fail β 15-min lockout, audited |
| Auth cookies | HttpOnly, SameSite=strict, Secure=true whenever NODE_ENV=production |
| Trusted-proxy spoofing | TRUSTED_PROXIES env drives Express trust proxy (default loopback) |
| Installer supply chain | Windows installer uses RustDesk MSP renamed-installer + --config β verifies effective config against public rustdesk.com and hard-fails (exit 20) if a public rendezvous survives |
| In-app updater | Off by default. Requires ALLOW_IN_APP_UPDATE=true and signed GPG tag (git tag --verify) |
| Sudoers | No wildcards. Only the exact commands the API executes are allowed, visudo -c validated |
Full audit trail: docs/SECURITY-AUDIT.md.
| Layer | Tech |
|---|---|
| API | NestJS + Prisma + PostgreSQL + Redis |
| Web | Next.js 14 App Router + shadcn/ui + TanStack Query |
| Desktop launcher | Tauri 2.0 (optional) |
| Remote transport | RustDesk hbbs / hbbr, self-hosted |
| Deploy | systemd on Ubuntu (no Docker required) |
Regenerated automatically from the running v0.8.x UI via Playwright (node apps/web/scripts/screenshots.mjs). Both light and dark themes captured.
| Page | Light | Dark |
|---|---|---|
| My Computers | ![]() |
![]() |
| Dashboard | ![]() |
![]() |
| Businesses | ![]() |
![]() |
| Access Control | ![]() |
![]() |
| Users | ![]() |
![]() |
| Computers | ![]() |
![]() |
| Add Computer | ![]() |
![]() |
| Sessions | ![]() |
![]() |
| Quick Connect | ![]() |
![]() |
Quick Connect (public /quick) |
![]() |
![]() |
| Audit Log | ![]() |
![]() |
| My Account | ![]() |
![]() |
See docs/setup.md for full installation instructions.
git clone https://github.com/agit8or1/rem0te
cd rem0te
pnpm install
cp apps/api/.env.example apps/api/.env
# Edit .env β DATABASE_URL, JWT_SECRET, ENCRYPTION_KEY (openssl rand -hex 32), etc.
pnpm build
sudo systemctl start reboot-remote-api reboot-remote-webPrerequisites: PostgreSQL 14+, Redis, RustDesk hbbs + hbbr on the same host, Caddy for TLS.
Issues, ideas, and pull requests are welcome.
- π Report a bug
- π‘ Request a feature
- π¬ Join the discussion
This project is overseen by Luna, a German Shepherd Dog of exceptional intelligence and discerning taste in remote support software. All major decisions are reviewed by Luna before merging.
πΎ
- β Star on GitHub
- π GitHub Sponsors
MIT β see LICENSE























