> For the complete documentation index, see [llms.txt](https://docs.gotempest.app/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.gotempest.app/collaboration-and-handoff/collab-live-terminal-sharing.md).

# Collab — Share a Live Terminal with Your Team

Share a live Tempest terminal with your team, invite viewers or editors, manage co-hosts, and chat with end-to-end encryption.

**Collab** lets other people join the terminal you already have open in Tempest. Everyone sees the same terminal output, and people with editing permission can type into the same shell. Use it to investigate an incident together, pair on a deployment, or give a live walkthrough.

The shell stays on the device that opened it. Your colleagues do not need your SSH keys, an account on the remote machine, or access to its VPN. Their input reaches the shared session through Tempest; commands run with the access and environment of that session.

[Handoff](/collaboration-and-handoff/handoff-live-collaboration.md) uses the same collaboration system to continue a session on your own devices. This guide covers sharing with other people.

## What you need

* A Tempest account signed in on the server you use for collaboration. Invitees must sign in to the same Tempest server; hosted and self-hosted accounts are separate.
* **Tempest Pro or higher to host a shared session.** Joining an invited session does not require Pro.
* A running terminal on the hosting device and internet access for the participants. The hosting device must stay running and connected for others to use its terminal.

## Start sharing a terminal

1. Open the terminal you want to share on the desktop.
2. Click **Collaborate**, the people icon in the terminal toolbar.
3. In the sharing dialog, choose a **General access** mode:

| Mode                              | Who can join                                     | How to use it                                                  |
| --------------------------------- | ------------------------------------------------ | -------------------------------------------------------------- |
| **Restricted — only me**          | Sharing is off for this terminal.                | Return to a private session.                                   |
| **Invited only**                  | The accounts you invite.                         | Work with specific colleagues.                                 |
| **Anyone with the link can view** | People holding the complete share link can view. | Give a live walkthrough; grant editing separately when needed. |

Choosing a sharing mode starts the collaboration room for the current terminal. Changing between sharing modes restarts sharing, so participants may need to rejoin.

## Invite a colleague by email

1. Choose **Invited only**.
2. Enter the email address your colleague uses for their Tempest account and click **Invite**.
3. Your colleague opens **Handoff** in Tempest and joins the listed session. On the desktop, double-click the session row or use its context menu to join.
4. Use the participant controls in the sharing dialog to make them view-only or allow editing.

An invited session belongs to the account you invited. Forwarding its room ID to someone else does not grant that person access.

## Share a viewing link

1. Choose **Anyone with the link can view**.
2. Click **Copy Link** and send the complete copied URL to the people you want to join.
3. They open the link in Tempest. On mobile, they can also paste it using **+** in the Handoff tab.

Keep the part after `#` intact: it contains the information needed to decrypt the room. A link stripped of that fragment cannot open the terminal. Treat the complete URL as access to the shared screen; anyone holding it can view while link sharing is active.

Link viewers start with view-only access. Signed-in viewers appear in the host's access list, where you can allow editing. Email invitation is available in **Invited only** mode.

## Control who can type and manage the room

The sharing dialog separates live connections from people with access. One account connected from two windows can appear as two live connections.

* **Make view-only** prevents a participant from sending terminal input while keeping the screen visible.
* **Allow editing** lets a participant type into the shared shell. Editors share one prompt, so coordinate before entering commands.
* **Promote to co-host** gives a participant member-management controls. Co-hosts can manage editing access and remove other participants; in invited rooms they can also invite people.
* **Demote to participant** removes the co-host role. Only the host can promote or demote co-hosts.
* **Remove from session** revokes that account's access and disconnects it from the room.

Only the host controls the room's general-access mode and copies the share link. A co-host does not take over the underlying terminal or keep it running if the hosting device exits.

## Chat beside the terminal

Open **Chat** to discuss what you are doing without putting messages into the shell. Terminal output, keyboard input and chat are encrypted between participants.

The terminal uses a coordinated grid size that fits the connected participants. A colleague joining from a smaller window can change the shared terminal size; everyone continues to see the same terminal layout.

## Stop sharing

Choose **Restricted — only me** in the host's sharing dialog. Collaboration ends, while the original terminal keeps running on the hosting device. Leaving as a participant closes your view without ending the host's shell.

Closing the original terminal or stopping its hosting process ends the shared session. Collab relays a live terminal; it does not move the shell to the relay server.

## End-to-end encryption

Tempest encrypts the shared terminal traffic and chat before sending them through the relay. The relay carries ciphertext and does not receive the room's decryption key.

For invited accounts, Tempest delivers the room key encrypted for the recipient. For viewing links, the key travels in the URL's `#` fragment, which is not sent in HTTP requests to the server. Participants who can view the session can read its output, including any secrets displayed in the terminal.

## Use Collab from the CLI

The CLI can host a local shell or join an existing room:

```bash
tempest login
tempest unlock
tempest collab host --title "Incident investigation"
```

On another signed-in client with access to the room:

```bash
tempest collab list
tempest collab join ROOM_ID --read-only
```

Omit `--read-only` to send input when your permissions allow it. The hosting CLI process must remain running. CLI hosting does not create email invitations or viewing links; use the app for those sharing controls. See [Tempest CLI — Collaboration](/cli/tempest-cli.md#collaborate-from-the-terminal) for commands and current limits.

## See also

* [Handoff — Pick Up a Session Anywhere](/collaboration-and-handoff/handoff-live-collaboration.md)
* [End-to-End Encryption (E2EE)](/accounts-vaults-and-privacy/end-to-end-encryption.md)
* [Self-Hosted Tempest Server](/self-hosting-and-web-mode/self-hosted-tempest-server.md)
