$_sudoterm
Operations

Security model

Phase 1 assumes a single trusted user controls the VPS. We've made the defaults safe for that scenario; some of them get more sophisticated in Phase 2 (multi-user, SSO).

Auth

on use

At-rest encryption

Per-provider AI API keys are encrypted before being written to SQLite:

first run)

Network

an outbound HTTPS connection — no inbound ports required

by Cloudflare for *.sudoterm.com

WebSocket auth

Cookies don't cross ports in the browser. The daemon mints a one-time WS token (POST /api/auth/ws-token, 60s TTL) on demand — that's what the browser attaches as ?token=… to its terminal WS URL.

What we don't do (Phase 1)

for the use case

← Block-based outputSubdomains →