Security model
Understand RepoTunnel's layered local security boundaries.
Guides follow the current project source. Check the release notes for your installed version.
Default position
Access is denied unless a project or capability has been explicitly enabled through RepoTunnel's user-controlled surfaces.
Core boundaries
- Approved workspace roots
- Protected credential paths
- Fail-closed command sandbox
- Review/Auto policy separation
- Validated Git surface
- Explicit push instruction
- Loopback raw MCP gateway
- OAuth for public MCP paths
- Sensitive browser/desktop semantic fields
- User-controlled Phone access
Do not bypass host policies
RepoTunnel is designed to work with operating-system, browser, Android, application and external-service security policies rather than bypass them.
Where the trust boundary lives
The Rust backend mediates registered workspace IDs, protected filesystem paths, safe editing and command execution. The raw MCP gateway stays bound to loopback and public HTTPS paths are subject to authenticated transport and OAuth rules.
AI Auto removes repeated approval prompts only for compatible authorized operations. It is not unrestricted host access or permanent permission to publish Git history.
Separate capability grants
Desktop, Phone, browser, Git, AI Workspace and terminal operations have different guards. Permission for one does not silently enable another. User-controlled Phone escalation and desktop self-control restrictions cannot be bypassed through a different MCP action.
Know the limitations
This model applies to RepoTunnel-controlled paths. Applications a person runs manually outside RepoTunnel are not sandboxed by RepoTunnel. macOS uses its current Seatbelt compatibility backend, with a long-term stronger native replacement still a platform consideration.