> Documentation index: https://rift.sh/llms.txt

# Rift vs Mesa

Mesa is a versioned filesystem where every agent write is a commit. Rift syncs folders that only your keys can read.

### What Mesa is

Mesa is a hosted filesystem for agents with version control built in. An agent mounts a repository as ordinary files, and every write becomes a commit that can be reviewed or rolled back. Each commit records both the agent and the person it worked for. It is in early access.

### How they differ

Mesa grants access by the repository and serves the files itself. Rift grants access by the folder, and each machine that receives a folder checks the grant.

- Identity
  - Mesa: A short-lived token that your backend signs.
  - Rift: A key that each machine and agent makes for itself. No account.

- Smallest share
  - Mesa: One repository, read-only or read-write, for up to four hours. A read-only repository can be mounted inside a writable one. Mesa's home page lists access controls per branch and path. Its documentation describes grants per repository.
  - Rift: A folder, a subfolder or one file, as read or write.

- Who checks access
  - Mesa: Mesa.
  - Rift: Each machine that receives a file checks the grant itself.

- Who can read your files
  - Mesa: Mesa serves the files itself. Its home page states AES-256 encryption at rest. We found no documented option for customer-held keys. Mesa also offers a version that runs in your own cloud account, with Mesa operating the control plane.
  - Rift: Only the machines you shared with. Rift Cloud holds ciphertext.

- When your machines are off
  - Mesa: Files stay available from Mesa.
  - Rift: Files stored in Rift Cloud stay available.

### Which to choose

Choose Mesa when

- Every agent write should be versioned and reviewable.
- Two agents edit the same files at once and you want both edits kept.

Choose Rift when

- An agent should receive one folder out of a larger project, with no separate repository made for it.
- Whoever stores the files must be unable to read them.
- The other side's agent should hold its own key and need no token from you.

Based on Mesa's documentation, read in October 2026. Sources: [authentication](https://docs.mesa.dev/content/concepts/authentication.md) , [token reference](https://docs.mesa.dev/content/reference/authentication.md) , [layouts](https://docs.mesa.dev/content/mesafs/layouts.md) , [live edits](https://docs.mesa.dev/content/mesafs/advanced/realtime.md) , [home page](https://www.mesa.dev/).
