Share a folder with a key, choose a role and remove access when you need to.
Share a folder
Sharing takes a path, a key and a role. The other machine starts syncing that folder immediately, and nothing else on your machine is visible to it.
Alice
ed25519:7f3a91c0…3a4b5c
team
spec.md
private
Bob
ed25519:c4d5e6f7…b3c4d5
teamwrite
spec.mdwrite
Agent
ed25519:a1b2c3d4…f0a1b2
teamread
spec.mdread
Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.
Bob can edit team. The agent can read it. Neither sees Alice's private folder.
on this machinedownloads when openednot shared
$ riftshareteambob✓ shared team with bob · write$ riftshareteamagent--read✓ shared team with agent · read$ riftmembersteamalice admin youbob writeagent read
bob and agent are aliases Alice saved with rift peer add. Aliases exist only on her machine. A full public key works in place of an alias.
Roles
Role
List and read
Add, edit, move, delete
Share and remove access
read
yes
no
no
write
yes
yes
no
admin
yes
yes
yes
write is the default. Every machine rejects an edit signed by a read key.
Share a subfolder
Share team/docs with Carol, a contractor, and her machine syncs that subfolder only. Nothing else in team reaches her machine, including file names.
Alice
ed25519:7f3a91c0…3a4b5c
team
src
docs
guide.md
Bob
ed25519:c4d5e6f7…b3c4d5
teamwrite
docswrite
Carol · contractor
ed25519:9c1e04b8…c2d3e4
docswrite
guide.mdwrite
Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.
Bob has the whole folder. Carol has one subfolder of it.
$ riftshareteam/docscarol✓ shared team/docs with carol · write$ riftmembersteam/docsalice admin youbob write from teamcarol write
Everyone with access to team keeps access to team/docs. A subfolder share only adds members.
Restrict a path
--exclusive limits a path to the keys you name. Members of the parent folder lose access to it. Here Alice shares .env with her agent, and Bob can no longer read it. Bob keeps any copy his machine already downloaded, so replace the secrets in it.
Alice
ed25519:7f3a91c0…3a4b5c
project-a
src
.env
Bob
ed25519:c4d5e6f7…b3c4d5
project-awrite
.env
Agent
ed25519:a1b2c3d4…f0a1b2
project-awrite
.envread
Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.
Bob sees that .env exists. New versions are encrypted with a key he was never sent.
$ riftshareproject-a/.envagent--read--exclusive✓ shared project-a/.env with agent · read! bob no longer has access to project-a/.env# bob$ riftcatproject-a/.env✗ permission deniedproject-a/.env is restricted to 2 keys
Remove access
Alice
ed25519:7f3a91c0…3a4b5c
team
Bob
ed25519:c4d5e6f7…b3c4d5
team
Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.
Bob stops receiving changes. Files he already downloaded stay on his disk.
$ riftunshareteambob✓ removed bob from team · new key$ riftmembersteamalice admin youagent read
After rift unshare, Bob cannot read anything new in team, and the other machines reject any change he sends. The folder gets a new key, and the remaining members receive it.
Removing access does not delete files Bob already downloaded. If one held a secret, replace that secret.
Moving a file to a folder with different members changes who can read it. See Move.