Security

Security model

Understand RepoTunnel's layered local security boundaries.

Guides follow the current project source. Check the release notes for your installed version.

Default position

Access is denied unless a project or capability has been explicitly enabled through RepoTunnel's user-controlled surfaces.

Core boundaries

  • Approved workspace roots
  • Protected credential paths
  • Fail-closed command sandbox
  • Review/Auto policy separation
  • Validated Git surface
  • Explicit push instruction
  • Loopback raw MCP gateway
  • OAuth for public MCP paths
  • Sensitive browser/desktop semantic fields
  • User-controlled Phone access

Do not bypass host policies

RepoTunnel is designed to work with operating-system, browser, Android, application and external-service security policies rather than bypass them.

Where the trust boundary lives

The Rust backend mediates registered workspace IDs, protected filesystem paths, safe editing and command execution. The raw MCP gateway stays bound to loopback and public HTTPS paths are subject to authenticated transport and OAuth rules.

AI Auto removes repeated approval prompts only for compatible authorized operations. It is not unrestricted host access or permanent permission to publish Git history.

Separate capability grants

Desktop, Phone, browser, Git, AI Workspace and terminal operations have different guards. Permission for one does not silently enable another. User-controlled Phone escalation and desktop self-control restrictions cannot be bypassed through a different MCP action.

Know the limitations

This model applies to RepoTunnel-controlled paths. Applications a person runs manually outside RepoTunnel are not sandboxed by RepoTunnel. macOS uses its current Seatbelt compatibility backend, with a long-term stronger native replacement still a platform consideration.

Start typing to search.