Guides
Worked examples for agents, short-lived runs, deploy machines, media servers and Rift Cloud.
Add an agent
On your laptop, run rift invite with a name for the agent. It prints a token. Give the token to the agent, which installs Rift and joins with it. Then share the folders the agent needs.
# your laptop$ rift invite coder✓ invite for coder rift_4f1c…9a2e# where the agent runs$ rift init --invite rift_4f1c…9a2e✓ created a key for this machine ed25519:a1b2c3d4…f0a1b2✓ joined as coder✓ folder at ~/rift# your laptop$ rift share project-a coder✓ shared project-a with coder · write
The agent works in ~/rift/project-a, and everything in it is an ordinary file. Its machine now has project-a and nothing else from your machine. Your SSH keys and the rest of your home directory were never sent, so no prompt or tool call can reach them.
A coder and a reviewer
The coder edits the project. The reviewer reads all of it and can write only to reviews, so a review can never change the code it is reviewing.
Two agents on the same project with different roles. The reviewer's edits outside reviews are rejected by every machine.
$ rift share project-a reviewer --read✓ shared project-a with reviewer · read$ rift share project-a/reviews reviewer✓ shared project-a/reviews with reviewer · write
Short-lived runs
Give each run its own invite and remove its access when the run ends. If the run's key leaks later, it has no access to any folder.
# your machine$ rift invite run-481✓ invite for run-481 rift_8c2e…41d7$ rift share project-a run-481✓ shared project-a with run-481 · write# the run finishes$ rift unshare project-a run-481✓ removed run-481 from project-a · new key
Deploy from a folder
$ rift share website/dist deploy --read✓ shared website/dist with deploy · read
The deploy machine receives website/dist each time you build and publishes from it. It has no source code and no secrets, and it cannot change the folder. Remove its access to stop deploys.
Media servers
Alice's server gets the whole library, as write. Her friend's server gets movies, as read.
$ rift share media mediaserver✓ shared media with mediaserver · write$ rift share media/movies friend --read✓ shared media/movies with friend · read
The friend's server downloads a movie the first time the friend plays it.
Rift Cloud
Rift Cloud is storage on the Sia network. Connect a Sia account and Rift uploads every file this machine can read, in the background.
$ rift sia initapprove this machine in your browser✓ storage connected$ rift sia statusstored 1,204 files 38.2 GBuploading 3 files 212.0 MBretrying 0 files
Each file is encrypted before it leaves the machine. The storage hosts see ciphertext and file sizes. They cannot see file names, folders or members.
The account that connects pays for what it stores. When Bob connects his own account, the files you shared with him are stored a second time under his account. His copy stays if you delete yours.
Rift Cloud is optional, and it is the one feature that needs an account, held with a provider on the Sia network. Without it, a file can be fetched only while a machine that has it is online.