v0.1.0 prototype Free during the prototype · macOS and Linux
A real-time workspace for your team and Claude Code, hosted on your own computer.
Share a project folder with smurg host: teammates join from a browser, edit files with you in real time, and watch and steer the Claude Code sessions on your machine, while the relay in between only forwards end-to-end encrypted data.
Install on the computer that shares the folder
curl -fsSL https://smurg.ai/install.sh | sh
For macOS (Apple silicon, Intel) and Linux (x64, arm64, glibc). The script downloads one executable from downloads.smurg.ai and installs it to ~/.local/bin/smurg only if its SHA-256 matches the release’s SHA256SUMS. No Node.js needed.
Got an invite link? Open it in Chrome; there is nothing to install. The app’s interface is currently in Traditional Chinese; English is coming.
- src
- app.ts
- login.tsAmy、Ben 編輯中
- session.ts
- tests
- login.test.tsClaude(Amy)修改中
- data
- package.json
- README.md
1import { createSession } from './session.ts';2import { verify, redirect } from './auth.ts';34export async function login(req: Request): Promise<Response> {5 const user = await verify(req);6 if (!user) {7 return redirect('/login?expired=1'Amy);8 }9 const session = await createSession(userBen);10 return redirect('/', session.cookie);11}
> add a test for the expired-session redirect ● Read(src/login.ts) └ Read 11 lines● Update(tests/login.test.ts) └ Added “redirects an expired session”● Bash(pnpm test tests/login.test.ts) └ Tests passed● The new test covers the expired-session redirect.>
- Claude(Amy)修改了 tests/login.test.ts(Edit)剛剛
- BEBen 上傳 data/fixtures.json1 分鐘前
- Claude(Ian)透過 shell 指令修改了 package.json透過指令3 分鐘前
01
How it works
One person hosts. Everyone else joins with a link. The folder, the agents and their output stay on the host’s computer.
-
Step 1
The host shares a folder
Sign in with Google, then share a folder. smurg runs in the foreground and prints two links: your own, which opens the workspace as the host, and an invite link for teammates (editor role by default, valid for 7 days). Ctrl-C stops sharing.
smurg login smurg host ~/projects/my-app -
Step 2
Teammates join
Send the invite link in a private message: the part after
#is the key. Teammates open it in Chrome, sign in with Google and join, with nothing to install. To follow sessions in a terminal,smurg attach --invite -joins too.https://app.smurg.ai/join/<id>#… -
Step 3
Work with agents together
Editors edit the same files at once; everyone sees every Claude Code session live and editors send suggestions to steer an agent. Teammates the host fully trusts can get the “can use agents” role: they open agent sessions and type into any session, and those sessions run as the host, with the host’s Claude account, on the host’s computer.
02
What you can do
-
Edit together
A file tree and an editor in the browser. Several people type in the same file at once, each cursor labelled with a name, and changes save to the host’s disk automatically. Agents show up the same way, as “Claude (owner)”.
-
Upload and download
Drag files or whole folders onto the file tree. Large uploads resume after a dropped connection and are refused before they start if the host’s disk would run low. Download any file, or a folder as a zip.
-
Claude Code sessions
Real Claude Code runs on the host’s computer. Everyone sees every session live, including what happened before they opened it, and can follow one in their own terminal with
smurg attach. Suggestions wait until the host or a teammate with the “can use agents” role accepts them, edits them first or rejects them; nothing reaches an agent before that. -
Worktrees and merge requests
If the folder is a git repository, an agent can work in its own worktree on its own branch, away from the main workspace. When it is done, a teammate with the “can use agents” role (or the host) requests a merge; the host reads the full diff and merges or rejects it. A conflict stops the merge and leaves the main workspace as it was.
-
Locks and attribution
Once you type in a file, agents can’t change it until you pause (30 seconds by default) or close it. While an agent edits a file, it is read-only in everyone’s editor. If an agent changes such a file some other way, with a shell command for example, its changes are merged in; where they overlap what someone is typing, the person’s text is kept and the agent’s version goes to a conflicts panel. The activity feed shows who, or which agent, changed each file, shell commands included.
-
Roles and a host console
Invite people as viewer, editor or “can use agents” (who may open agent sessions and type into them, as the host). The host console lists members, roles, invite links, sessions and the audit log; one click removes a member or ends a session. If the host’s computer sleeps or goes offline, everyone sees it within seconds.
03
Security, in plain words
Your code passes through smurg’s relay only in encrypted form. This is what that means, and where it stops.
End-to-end encrypted
Every browser and terminal opens its own encrypted channel to the host’s computer, using the Noise protocol. The invite link carries the fingerprint of the host’s key and a secret after the #, the part of a link that browsers never send to a server. A relay that tries to pose as the host is refused.
The host keeps the files
Files, Claude Code sessions and the audit log live on the host’s computer; the relay stores none of them. While that computer sleeps or smurg is stopped, nobody can use the workspace; it reconnects when the host is back.
Agents run as the host
Every agent and terminal session runs on the host’s computer as the host: the host’s account, files and Claude Code login, with no sandbox. Besides the host, only teammates with the “can use agents” role open sessions or type into them; editors send suggestions and viewers watch. That role lets someone make an agent run any command on your computer, read your home folder and use your Claude account, so give it only to people you fully trust.
What the relay sees
Which Google account each connection belongs to (its ID, name and picture; at sign-in Google also gives the relay the account’s email, used as the display name only when the account has no name), its IP address, the workspace code, and the size and time of each message, so it can tell who worked with whom, and when. Not file contents, file names, terminal output, commands, the invite secret or any key. It keeps only each workspace’s code and its owner’s account. smurg’s maintainer, who runs the relay, and Cloudflare can see the same.
What smurg can’t protect you from
- Everyone in a workspace can read every file in the shared folder,
.envfiles included; only.git,.envrc, smurg’s own.smurgfolder and the host’s personal Claude Code settings are hidden. Don’t share a folder that holds passwords, keys or personal data. - Agent sessions are not sandboxed and read what teammates write. A file could hide instructions meant for them (prompt injection), so keep Claude Code’s permission prompts on.
- A teammate with the “can use agents” role can do on your computer whatever you can: run any command, read your home folder, spend your Claude usage. smurg can’t limit that.
- The web app is served by the relay. As with any end-to-end encryption in a browser, a tampered app could leak keys; the CLI doesn’t have this problem.
Read the host guide before you share (in Traditional Chinese)
04
Platforms and requirements
- Host computer
- macOS 11 or later on Apple silicon or Intel. Linux with glibc 2.28 or later (Ubuntu 20.04 and later) on x64 or arm64. Windows hosts and musl-based Linux such as Alpine are not supported.
- Claude Code
- To run agent sessions, the host’s computer needs Claude Code (the
claudecommand) 2.1.220 or later, signed in: every session uses the host’s login. Worktrees need the shared folder to be a git repository. - Teammates
- Any operating system with a browser. Chrome on a computer is the tested one; Safari and Firefox have not been tested yet. Optionally the smurg CLI on macOS or Linux.
- Sign-in
- A Google account, for the host and for teammates.
- Relay
- The shared relay runs on Cloudflare’s free plan and is for fair use: everyone shares one daily quota, and when it runs out nobody can connect until 00:00 UTC (08:00 in Taiwan). It is the only relay for now: its source isn’t public, so you can’t run your own.
v0.1.0 is the first public release, a prototype. It was developed and tested on macOS on Apple silicon; the Intel Mac and Linux builds are built and smoke-tested on GitHub Actions. Known limits are listed in the changelog.
05
Documentation
The host guide covers installing, sharing a folder, what to check before you share and what to do when something goes wrong; the guide for teammates covers joining, roles, editing together and working with agents.
The guides are in Traditional Chinese for now.
06
Questions
Do I need Node.js?
No. The installer downloads a single executable built for your computer; installing it needs no sudo. Teammates who join in a browser install nothing.
The macOS executable has only an ad-hoc signature, not an Apple Developer ID. Install it with the line above: after checking the SHA-256, the installer removes the quarantine flag. A copy downloaded with a browser is blocked by Gatekeeper.
How do I update or remove it?
smurg update replaces the executable with the newest version, after the same SHA-256 check (stop sharing first). smurg uninstall lists what it will remove, then removes the executable, its cache and ~/.smurg; the .smurg/ folders inside your projects are left to you. Version 0.2.0 has neither command: run the install line again to update it.
What does the relay see?
The Google account of each connection (ID, name and picture; at sign-in also the email), its IP address, the workspace code, and the size and time of each message, so it can tell who worked with whom, and when. Files, file names, terminal output, commands and keys are end-to-end encrypted between the host’s computer and each teammate. There is no other relay to choose for now: the relay’s source isn’t public, so hosts can’t run their own. If what the relay sees is too much for a project, don’t share it with smurg.
Do teammates need their own Claude account?
No. Every agent runs on the host’s computer with the host’s Claude Code login, so its usage counts against the host’s account. Viewers watch every session, editors also send suggestions, and teammates with the “can use agents” role open sessions and type into them, all as the host. The host needs Claude Code installed and signed in.
Can I see the source code?
No, the source code is not public. The executables are free to download and use during the prototype, under the terms of the license. The components smurg is built from keep their own licenses, listed in the third-party notices of the executables and in those of the web app.
Which browsers work?
Chrome on a computer is the one tested. Safari and Firefox have not been tested yet.
What happens when the host’s computer sleeps?
Everyone sees “host offline” within seconds. Edits wait in the browser and are sent when the host is back; agents can’t be used in the meantime. smurg keeps an idle computer awake while sharing, but closing a laptop’s lid still puts it to sleep.