Tactic Remote

Security

API key management, path restrictions, and security best practices.

Tactic Remote gives your iPhone control over a terminal on your Mac. This page covers what's protected, how, and what you should configure.

API key authentication

The server supports API key authentication. When set, every connection must provide the correct key.

export CLAUDE_REMOTE_API_KEY="your-secret-key"

The Mac app can generate a random key for you.

When it's required:

  • Always required for public/tunnel access (strongly recommended).
  • Optional for local-only access, but still a good practice.

Rules:

  • Don't share your API key in screenshots or chat.
  • Rotate the key if you suspect it was exposed.
  • The Mac app stores the key in the macOS Keychain.

Path restrictions

You can restrict which directories Claude Code can access:

export CLAUDE_REMOTE_ALLOWED_PATH="/Users/you/projects"

By default this is set to your home directory (~). Narrowing it to your projects folder prevents Claude from accessing unrelated files.

Blocked by default: The server blocks access to sensitive directories like .ssh, .aws, .gnupg, and similar paths regardless of the allowed path setting.

Session security

  • Session names are validated: alphanumeric characters, underscores, and hyphens only (max 50 characters). This prevents command injection via session names.
  • Commands passed to tmux are validated. Only the claude command with approved flags can be launched.
  • Path traversal attacks (e.g. ../../etc/passwd) are blocked.

Rate limiting

The server enforces a rate limit of 30 requests per minute per connection. This prevents abuse and accidental request storms.

Network security

Local network

On a trusted home or office network, local mode is reasonably secure. The main risk is other devices on the same network. Treat the IP and API key as credentials.

Cloudflare Tunnel

Tunnel connections are encrypted (WSS/TLS) by default. Cloudflare also provides DDoS protection. The tunnel makes no inbound ports necessary on your router.

For public access, always:

  1. Set an API key.
  2. Use a named tunnel with a stable URL when possible.
  3. Remove stale tunnel configurations when no longer needed.

Checklist

ItemStatus
API key set for serverRequired for tunnel, recommended for local
Allowed path configuredDefault ~, narrow to project folder
Mac firewall allows appRequired for local connections
Sensitive dirs blockedAutomatic (.ssh, .aws, etc.)
Rate limiting activeAutomatic (30 req/min)
Key rotated after exposureManual action when needed

On this page