CryptoMesh
Machines Access Sharing DNS Organizations API access Identity Logs & webhooks Settings All machines
Account & billing

Machines

Every phone, computer and gateway on your private network.

No machines yet

Connect in the CryptoMesh app on your phone, or add a PiKVM or Linux computer with a join key.

MachineAddressesHome networkLast seenActions

Access

Who can reach what on your network.

Your devices reach each other

Machines signed in to your account can reach each other. With a subscription they can also send internet traffic through CryptoMesh exit servers, and any account can use exit nodes it runs itself. The network policy CryptoMesh generates does not grant other customers' accounts access to your machines, even when two homes use the same 192.168.1.x addresses. CryptoMesh operator accounts are not exempt: they can reach only CryptoMesh's own servers, not your machines or your home network.

Gateways share a home network

A gateway (for example a PiKVM) that shares its home network gets a private IPv6 range for that network. The network policy grants that range to your account, not to other customers. TouchKVM uses it to reach a KVM at home while you are away.

Exit servers

CryptoMesh Cloud servers appear as exit nodes you can choose in the app. Internet traffic then leaves from that server. Available with a Cloud subscription.

Sharing

Devices you share with other CryptoMesh accounts, and devices they share with you.

What a share grants

The person you invite reaches only that one machine, at its own addresses. Your other machines, home network routes and exit nodes stay private. The shared machine cannot start connections to their devices unless they allow it, and either of you can end the share at any time.

Invitation links stay private

An invitation works once and expires. The code travels only in the part of the link after #, which browsers never send to a website, and CryptoMesh stores only a hash of it.

DNS

Names for your machines on the network.

Machine names

Each machine is reachable by its name under mesh.cryptomeshvpn.com, for example pikvm.mesh.cryptomeshvpn.com. Rename a machine from the Machines page.

Your own DNS stays yours

CryptoMesh does not change the DNS servers on your devices. Name lookups for the network are answered locally by the app.

Organizations

People and roles for a shared CryptoMesh directory. Roles are decided by the server; this page shows the latest state it knows.

What an organization is

A directory of accounts with fixed roles: owner, admin, network admin, member and auditor. Owners manage everything, admins manage members, auditors and network admins, network admins edit the network policy and devices, auditors read policy and audit logs, members see the organization, their own role and their own devices.

What it does not do yet

The organization network policy and device approvals are kept and checked here, but the CryptoMesh apps do not enroll into organization networks yet, so they do not change which of your personal machines can reach each other. Organizations do not grant Cloud access or move subscriptions or personal nodes.

Invitations are handed over by you

An invitation is issued to a principal ID and comes with a secret that is shown once. CryptoMesh never emails it. Share it with the recipient yourself; only their signed-in account can redeem it, and only once.

API access

Credentials for automation, CI and infrastructure as code. They call the administrative API for one organization and can never do more than your role allows.

Tokens and OAuth clients

An API access token is a bearer secret that expires after at most 90 days. An OAuth client exchanges its secret for access tokens that last one hour, so long-lived automation never sends its secret with every request.

API tokens belong to the person who created them and stop when that person's role or account ends. OAuth clients belong to the organization: each keeps the role its creator had when it was made, survives that person leaving, and works until an owner or admin revokes it.

Secrets are shown once

CryptoMesh stores only a hash. Copy a new secret into your secret manager before closing the panel. Revoking a credential, or rotating an OAuth client, stops the old secret at once.

Identity

Single sign-on through your identity provider, verified domains, and user and group provisioning with SCIM.

How single sign-on works

CryptoMesh is an OpenID Connect client of your identity provider. People who sign in through it get a CryptoMesh account that belongs to your organization only, so disabling them never touches a personal account. Two-factor authentication and session rules stay with your provider.

Deactivation removes access

When your provider deactivates or deletes someone through SCIM, CryptoMesh suspends their membership, refuses their sign-in at once and disables their organization account, which removes their devices from the network. Reactivating them restores only what provisioning suspended.

Logs & webhooks

Audit retention and export, signed webhooks, log streaming to your SIEM, and opt-in network flow logs for an organization.

What flow logs contain

Only when an owner or admin turns them on: the reporting device, the peer device, protocol, ports, packet and byte counts per minute. No packet contents, no public addresses and no home-network addresses. Records are kept for the retention you choose (at most 90 days) and can be deleted when you turn collection off.

Verifying webhooks

Each request carries CryptoMesh-Webhook-Signature: t=<unix time>,v1=<hex>. Compute HMAC-SHA256 with your signing secret over the timestamp, a period and the raw body, compare in constant time, and reject timestamps more than five minutes old. During a secret rotation there may be two v1 values; accept either.

Settings

Account

Manage account, plan and billing

Device allowance

Up to 100 machines per account are included free. Cloud exit servers and relay require a subscription.

All machines

Administrator view across every account.

MachineAccountAddressesHome networkLast seen

Add device

Run this on the device within 10 minutes, then paste the one-time key when it asks. The key works once.


                

One-time key


                  

Install CryptoMesh, sign in with this account, then tap Connect under CryptoMesh network.

Google Play App Store Mac, Windows and Linux

Redirecting to sign-in…