> Documentation index: https://rift.sh/llms.txt

# Guides

Worked examples for agents, short-lived runs, deploy machines, media servers and Rift Cloud.

## Add an agent

On your laptop, run `rift invite` with a name for the agent. It prints a token. Give the token to the agent, which installs Rift and joins with it. Then share the folders the agent needs.

```
# your laptop
$ rift invite coder
✓ invite for coder rift_4f1c…9a2e

# where the agent runs
$ rift init --invite rift_4f1c…9a2e
✓ created a key for this machine
  ed25519:a1b2c3d4…f0a1b2
✓ joined as coder
✓ folder at ~/rift

# your laptop
$ rift share project-a coder
✓ shared project-a with coder · write
```

The agent works in `~/rift/project-a`, and everything in it is an ordinary file. Its machine now has `project-a` and nothing else from your machine. Your SSH keys and the rest of your home directory were never sent, so no prompt or tool call can reach them.

## A coder and a reviewer

The coder edits the project. The reviewer reads all of it and can write only to `reviews`, so a review can never change the code it is reviewing.

Two agents on the same project with different roles. The reviewer's edits outside reviews are rejected by every machine.

```
$ rift share project-a reviewer --read
✓ shared project-a with reviewer · read
$ rift share project-a/reviews reviewer
✓ shared project-a/reviews with reviewer · write
```

## Short-lived runs

Give each run its own invite and remove its access when the run ends. If the run's key leaks later, it has no access to any folder.

```
# your machine
$ rift invite run-481
✓ invite for run-481 rift_8c2e…41d7
$ rift share project-a run-481
✓ shared project-a with run-481 · write
# the run finishes
$ rift unshare project-a run-481
✓ removed run-481 from project-a · new key
```

## Deploy from a folder

```
$ rift share website/dist deploy --read
✓ shared website/dist with deploy · read
```

The deploy machine receives `website/dist` each time you build and publishes from it. It has no source code and no secrets, and it cannot change the folder. Remove its access to stop deploys.

## Media servers

Alice's server gets the whole library, as write. Her friend's server gets movies, as read.

```
$ rift share media mediaserver
✓ shared media with mediaserver · write
$ rift share media/movies friend --read
✓ shared media/movies with friend · read
```

The friend's server downloads a movie the first time the friend plays it.

## Rift Cloud

Rift Cloud is storage on the Sia network. Connect a Sia account and Rift uploads every file this machine can read, in the background.

```
$ rift sia init
approve this machine in your browser
✓ storage connected
$ rift sia status
stored     1,204 files   38.2 GB
uploading  3 files       212.0 MB
retrying   0 files
```

Each file is encrypted before it leaves the machine. The storage hosts see ciphertext and file sizes. They cannot see file names, folders or members.

The account that connects pays for what it stores. When Bob connects his own account, the files you shared with him are stored a second time under his account. His copy stays if you delete yours.

Rift Cloud is optional, and it is the one feature that needs an account, held with a provider on the Sia network. Without it, a file can be fetched only while a machine that has it is online.
