Leon
REMOTE · WITH A CODE

Reach another computer with a code.

Run agents on a workstation, a server or a second laptop and drive them from the one in front of you. No SSH setup, no ports to open.

The app shipped in 0.1.0. The relay is the part still coming online.

RELAY · COMING ONLINE

The code for sharing a machine shipped in 0.1.0. The relay service at relay.getleon.dev is still being deployed, so "With a code" will tell you the relay is unreachable until it is. SSH works today. The feature has had no independent security review yet.

Plain version: the code is written and released; the service it needs is not online yet. Roadmap

HOW IT WORKS

Four steps.

Both computers need Leon (or leon host on a server).

  1. 01

    On the computer you want to reach

    Install Leon and choose Share this machine (File menu, the palette, Settings, or the foot of the sidebar). Leon shows a pairing code: ten symbols, valid for ten minutes, usable once.

  2. 02

    On your computer

    Choose Connect a machine, then With a code, and type it. The screen checks four things in turn: it reaches the relay, finds the computer, verifies the code and opens the secure channel.

  3. 03

    Approve it

    By default the shared computer asks you to approve the new device, showing its name and fingerprint. Headless hosts treat the code as the approval.

  4. 04

    Work

    The shared computer appears in your tree next to your own. Its projects, worktrees and agent sessions are there, and you open terminals on it.

[ YOUR COMPUTER ]

Leon

client

[ RELAY · ZAVU ]

Pairs and forwards

sees only ciphertext

[ SHARED COMPUTER ]

Leon

host

[ NETWORK ]

No ports, no SSH

Both computers dial out. Nothing to open, no keys to copy, and it works behind NAT.

[ PRIVACY ]

End-to-end encrypted

The relay passes ciphertext. It cannot read your terminals or commands.

[ DEVICES ]

One key per device, revocable

List your paired devices and revoke any of them. A revoked device gets no answer.

[ SESSIONS ]

Sessions keep running

Agents and terminals stay alive on the shared computer. Reconnect and get the output you missed.

SECURITY

What the relay can and cannot see.

The short version: it sees that a connection exists, not what is in it.

[ IT CAN SEE ]

  • That a host is online, and when clients connect and leave.
  • How many bytes flow and when.
  • The public room part of a pairing code, which only routes.

It can also refuse service, drop or delay a connection.

[ IT CANNOT ]

  • Your commands, terminal output, file names, keys or device names. It carries ciphertext.
  • Alter or forge messages without being noticed. Every message is authenticated.
  • Pretend to be your computer or a paired device. It does not have their keys.
  • Guess a pairing code offline.
A PAIRED DEVICE

It gets a terminal as you.

A paired device can run any command and open any terminal on the shared computer, as the user who runs Leon there, with that user's full rights. That is the feature. There is no sandbox. Pair only your own devices. The host refuses to run as root unless told otherwise.

Each paired device has its own key. To see them and revoke one, open Share this machine on the shared computer, or run leon host devices and leon host revoke <device>. An unknown or revoked device gets no answer.

Not protected: metadata, availability (the relay can refuse service, and the shared computer must be online), traffic analysis, and someone reading the code over your shoulder during its ten minutes. The code works once, is burned after five wrong tries, and the approval prompt shows the new device.

No independent security review yet. The code is open so that one can happen.

FOR THE CURIOUS

The primitives.

The full protocol and threat model are in docs/REMOTE.md. No home-made cryptography: Leon composes audited crates.

[ PAIRING ]
SPAKE2 turns the short code into a strong shared key that matches only if the codes match. Someone watching learns nothing that lets them test guesses offline. The code has 30 secret bits, lives ten minutes, works once and is burned after five failed attempts.
[ SESSIONS ]
Noise (IK, ChaCha20-Poly1305, BLAKE2s, X25519) with pinned device keys. The host checks its device list before answering and says nothing to an unknown or revoked key. Sessions rekey after an hour, a gibibyte or about a million messages.
[ DEVICE KEYS ]
Each installation has an X25519 key for Noise and an Ed25519 key that proves to a relay which host it is. The host id is a hash of that public key, so a relay cannot take over a host's id.
[ WHAT RUNS ]
The host offers two primitives over the encrypted channel: run a command, and a terminal that keeps running when every client disconnects. It keeps the last 2 MiB of output so a reconnecting client receives each later byte exactly once.
HEADLESS

On a server: leon host.

leon host runs the sharing service without a window. It refuses to run as root. Pairing and device management are subcommands; the relay address can be set with --relay or LEON_RELAY_URL.

SSH is still there.

Leon also connects over your system's SSH and installs nothing on the other computer. It is the advanced method, and it works today. See the connect screen.

# on the server (not as root)
leon host --pair          # run in the foreground
leon host pair            # print a fresh code from the running host
leon host devices         # list paired devices
leon host revoke <device>  # cut one off
leon host status         # is it running?

# a different relay
LEON_RELAY_URL=wss://relay.getleon.dev leon host --pair
FAQ

Questions.

Do I need to open ports?

No. Both computers connect out to the relay over a normal secure web connection. There is nothing to forward, no SSH server to set up and no keys to copy.

Can Zavu read my terminal?

No. Zavu operates the relay, and the relay only forwards ciphertext. It does see metadata: that a host is online, when clients connect, and how much data flows. It can cut or delay a connection, but it cannot read or change what you send.

What if I lose a device?

Revoke it from Share this machine on the shared computer, or run leon host revoke <device>. Open sessions from that device are dropped within about a second, and a revoked device gets no answer at all. Keys are stored owner-only but not encrypted at rest, so use full-disk encryption on your computers.

Does it work across networks?

That is the point of the relay: both ends dial out, so it works across networks and behind NAT, once the relay is online.

Is it open source?

The protocol, the cryptography and the host and client code are open source in the Leon repository, so they can be reviewed without trusting any server. The relay service itself is operated by Zavu and its server code is not in that repository.

Does it work today?

Not with a code, yet. The relay service is still being deployed; until it is, Leon says the relay is unreachable and names the address it tried. SSH works today.

Does the shared computer have to be on?

Yes, and Leon (or leon host) has to be running on it. Sharing stops when Leon closes there; a background service is planned. While it runs, terminals and agents on it keep going when you disconnect or close your laptop, and you get the output you missed when you reconnect.

RELAY · COMING ONLINE

The code for sharing a machine shipped in 0.1.0. The relay service at relay.getleon.dev is still being deployed, so "With a code" will tell you the relay is unreachable until it is. SSH works today. The feature has had no independent security review yet. Roadmap