Security and permissions
Authentication, short-lived Local sharing credentials, runtime isolation, and command approvals.
Local sharing
Local sharing is disabled by default. Inviting a member does not start a relay or expose the folder. The owner must separately enable joining while Worktree is open.
Guests sign in to Worktree and receive short-lived connection credentials. Active clients renew them automatically. Disabling sharing, removing membership, expiration, or losing the host connection closes access.
The relay forwards authenticated traffic and holds no repository checkout. A relay credential is scoped to one connection and one Workspace.
Command execution
Commands execute in the Workspace’s placement: on the owner’s host for Shared Local, or in the isolated sandbox for Cloud. Worktree retains OpenCode’s permission and approval flow for sensitive tools and commands; sharing a Workspace is not blanket permission to run every host operation without approval.
Cloud isolation
Cloud Workspaces run in managed isolated sandboxes. Credentials are synchronized only into their intended Workspace scope. Worktree enforces Team access and builder-seat requirements on its servers and at the runtime gateway, not only in the Desktop interface.
Presence
Presence is ephemeral collaboration metadata. It reports active or background Thread clients and is not used as durable message history or a security grant.
