Rem0te
A self-hosted, multi-tenant remote support portal built around a self-hosted RustDesk server — enrollment, permissions, credential release without passing passwords around, and a full audit trail.
The problem
Open-source RustDesk is a solid remote-access engine, but supporting many customer businesses needs more: who may connect to which machine, how credentials are released without being shared, and a record of every session.
Why existing tools fell short
Self-hosted RustDesk lacks multi-customer enrollment, role-based access, and credential release in its free edition; the commercial alternatives are per-technician subscriptions.
The solution
Rem0te wraps a self-hosted RustDesk server in a multi-customer portal. Devices are enrolled per business, access is granted by role, and technicians connect without anyone passing passwords around. Business owners can see and manage their own computers and users.
- Three-level roles: platform admin, business owner, and business user
- Managed-device enrollment for Windows, Linux, and macOS
- Connect without sharing passwords, using single-use grants
- Device inventory, Windows event logs, and Tactical RMM launch integration
- Audit timeline and a public API
Engineering involved
Verified from the public repository: README, dependency manifests, and source files.
- Architecture
- A pnpm monorepo: a NestJS API, a Next.js web portal, a Tauri desktop launcher, and a Windows installer written in Go.
- Database design
- PostgreSQL through Prisma with tenant, membership, role, permission, customer, site, and endpoint models; Redis.
- Tenant isolation
- The business boundary is enforced on the server and covered by an end-to-end access test.
- Authentication & authorization
- Argon2 password hashing, TOTP MFA, and role-permission mappings across three access levels.
- Security
- AES-GCM encryption for stored device credentials; a GPG-signed in-app updater that is off by default.
- Deployment
- Install script with Caddy for automatic HTTPS, systemd services, and fail2ban.
What makes it interesting
Credential release uses single-use, hashed, expiring connection grants: the portal authorizes one connection, hands off to the local RustDesk client through a deep link, and the grant can’t be replayed.
Outcome
Measured Public GitHub figures as of 10 October 2026: 8 stars, 0 forks, and 43 published releases since the repository was created in March 2026. Stars and forks show public interest, not active installations — the project doesn’t collect usage data.
Current status
Open Source Free, MIT-licensed, self-hosted. The source code is public on GitHub.
Open source under the MIT license, pre-1.0 and actively released. It is deliberately not an RMM and does not offer in-browser remote control.
See it working
Screenshots and a walkthrough video recorded with demo data: github.com/agit8or1/rem0te. Overview: mspzero.com/tools/rem0te.
Want something similar?
Need a system like this, built around your own business? MyAppDone can design, build, deploy, and maintain an application tailored to your workflow.


