Linkdocs

Security

What Link Host opens on your computer, what each party can see, and the promises Link keeps.

Link's job is to make your computer reachable without making it exposed. This page lists everything that listens, every key, and who sees what.

Keys and trust

  • The phone makes its own key (Ed25519) when you pair. The private half never leaves the phone, where it's encrypted with an Android Keystore key.
  • The pairing code is a one-time key that can only add the phone's public key, once, within 10 minutes. It can't open a shell, a terminal or a tunnel.
  • The computer's SSH key is pinned. The phone checks it against the code before sending anything, then on every connection. A computer that presents a different key is refused, and an error screen never offers to accept it; only editing the computer in the app can replace it, side by side with the old key, after you choose to.
  • Fingerprints in codes come from the computer's own loopback, never from the address in the code, so a DNS name or NAT address can't swap in another key.
  • Your agents' credentials stay on the computer. Link starts the agents you already logged in to; it never reads or stores their API keys.

What listens on your computer

WhatWhereWho can use it
Link's SSH server (Linux)port 2222Only keys of phones you paired; passwords refused; runs as you, so it can only sign in your account; forwards only local ports, which the desktop uses
Link Host's health check127.0.0.1:45999Loopback only, read-only
Desktop stream (when the phone opens it)127.0.0.1, a free portLoopback only, plus a token made for that session
Claude channel sockets$XDG_RUNTIME_DIR/link/channels/Your account only (file permissions)
Punch socket (while a phone connects)a UDP portOnly packets signed with that connection's key

Link Host refuses to bind its own listeners to anything but loopback. Link's SSH server does listen on your network, for phones on it; with rendezvous or a relay, phones elsewhere don't need that port at all, because the computer reaches out to them, so your firewall can stay closed.

Who sees what

PartySees
Your relay (yours, on your Cloudflare account)Encrypted SSH bytes; which phones connect and when; addresses, to introduce the two sides
ntfy (rendezvous)Two sealed messages per connection, and which IP addresses used the topic
STUN serverYour public address, as it does for any video call
Cloudflare TURN (when used)Encrypted SSH bytes
FalaqNothing: there is no Falaq server in the path today

Promises

  • Link never approves an agent's request by itself. Requests it can't show are refused. Modes that let an agent act without asking are your choice, confirmed each time you turn one on.
  • No root. On Linux, installing Link Host and pairing phones need no administrator rights; link-host ssh setup refuses to run under sudo. (Only the optional --system mode, which sets up the system's OpenSSH instead, asks for your password.)
  • No changes to your SSH setup. Link's server has its own configuration and keys in ~/.config/link/sshd; your system sshd_config and ~/.ssh are untouched.
  • Unpairing is immediate. link-host devices remove deletes the phone's key and ends its open sessions.

On this page