Team server
Team mode is available under a commercial agreement with Coderica, which includes support. Solo mode, including one person driving their own remote server, is free for individuals and organizations with up to 10 engineers. See pricing.
hashd is a client (hashd, hashd watch) talking to a server (hashd-server). By default both run on your machine as one user with no login. This page covers the other shape: one server that clients connect to over the network, whether that is your laptop driving a box in the closet or a server shared by a team.
How trust works
When the server listens on anything other than loopback, two things switch on automatically:
- TLS. The server serves HTTPS with a self-signed certificate it generates once and keeps. There is no CA to configure.
- Authentication. Every request needs a bearer token. No token, no answer.
The certificate's fingerprint is carried inside the token the server mints. When a client pairs, it pins that fingerprint, so a single relayed token establishes both identity and a trusted connection.
Make the server reachable
Run these on the server host. A fresh install already runs on http://127.0.0.1:1337.
# 1. mint an owner token (no token is needed on loopback yet)
hashd auth create --description "server host"
# 2. bind the server to its LAN address and restart
hashd server set https://<lan-ip>:1337 --token <owner-token>
hashd restart server
hashd status
# 3. optional: require identity on every request, including loopback
hashd config set deployment_mode team
hashd restart server
Add people
User provisioning runs on the server host:
hashd admin user add [email protected] --name "Alice"
This prints a one-time access token to hand to Alice over a trusted channel. Add --admin for admin rights. Manage users with hashd admin user list, remove and reset-key.
Prefer passwords? Issue a setup key with hashd admin user reset-key [email protected]; Alice redeems it with hashd set-password --key <key> and then signs in with hashd login [email protected].
Pair a client
On each teammate's machine:
hashd server set https://<lan-ip>:1337 --token <token>
hashd status
hashd agents login claude
status shows the server, its health and your identity. Registering your agent credential means runs on your workstreams use your own account. hashd server unset returns a client to local mode.
Team mode rules
- Identity on every request. Tokens are stored only as SHA-256 hashes; the plaintext is shown once.
- Owners. Stories, suggestions and workstreams belong to the user who created them. In team mode only the owner may change them. Unassigned items are open to anyone, and reassignment is logged.
- Shared settings. Server-wide configuration can only be changed by an owner or admin. Project settings are unaffected.
- Your view.
hashd list --mineand the dashboard's owner filter show only your own work.
Solo mode enforces none of this, so the single-user experience is unchanged.
Other ways to connect
In solo mode you can keep the server bound to loopback and reach it over an SSH or WireGuard tunnel without tokens. You can also supply your own CA-signed certificate with hashd-server --tls-cert-file ... --tls-key-file ....
Do not terminate TLS at a reverse proxy that connects to hashd-server over loopback in solo mode: from the server's point of view that connection is local, so it would not require a token.