Security
API key management, path restrictions, and security best practices.
Tactic Remote gives your iPhone control over a terminal on your Mac. This page covers what's protected, how, and what you should configure.
API key authentication
The server supports API key authentication. When set, every connection must provide the correct key.
The Mac app can generate a random key for you.
When it's required:
- Always required for public/tunnel access (strongly recommended).
- Optional for local-only access, but still a good practice.
Rules:
- Don't share your API key in screenshots or chat.
- Rotate the key if you suspect it was exposed.
- The Mac app stores the key in the macOS Keychain.
Path restrictions
You can restrict which directories Claude Code can access:
By default this is set to your home directory (~). Narrowing it to your projects folder prevents Claude from accessing unrelated files.
Blocked by default: The server blocks access to sensitive directories like .ssh, .aws, .gnupg, and similar paths regardless of the allowed path setting.
Session security
- Session names are validated: alphanumeric characters, underscores, and hyphens only (max 50 characters). This prevents command injection via session names.
- Commands passed to tmux are validated. Only the
claudecommand with approved flags can be launched. - Path traversal attacks (e.g.
../../etc/passwd) are blocked.
Rate limiting
The server enforces a rate limit of 30 requests per minute per connection. This prevents abuse and accidental request storms.
Network security
Local network
On a trusted home or office network, local mode is reasonably secure. The main risk is other devices on the same network. Treat the IP and API key as credentials.
Cloudflare Tunnel
Tunnel connections are encrypted (WSS/TLS) by default. Cloudflare also provides DDoS protection. The tunnel makes no inbound ports necessary on your router.
For public access, always:
- Set an API key.
- Use a named tunnel with a stable URL when possible.
- Remove stale tunnel configurations when no longer needed.
Checklist
| Item | Status |
|---|---|
| API key set for server | Required for tunnel, recommended for local |
| Allowed path configured | Default ~, narrow to project folder |
| Mac firewall allows app | Required for local connections |
| Sensitive dirs blocked | Automatic (.ssh, .aws, etc.) |
| Rate limiting active | Automatic (30 req/min) |
| Key rotated after exposure | Manual action when needed |