File Sharing

File Sharing

Share a local file or directory through one HTTPS tunnel.


rstream files combines a local file server and its HTTPS tunnel. Recipients browse folders and download files through an interface included in the CLI. Your device must stay connected; files are read directly from disk. WebDAV uses normal project traffic quota; optional WebRTC can transfer directly between peers.

rstream files and the WebTTY filesystem are unavailable in the restricted FIPS profile for both WebDAV and WebRTC. See the FIPS compatibility matrix.

Start a share

After installing the CLI and selecting a project:

rstream files ./exports
rstream files ./backup.tar.zst --password

Open the forwarding URL printed by the command. With no path, the CLI shares the current directory. A file path shares only that file, including a hidden file explicitly selected this way. Stop the command to close access. Automatic reconnection is enabled; add --no-retry to stop after disconnection.

The browser offers folder navigation, sorting by name, size or modified date, filtering within the current folder, individual downloads and a ZIP of the current directory. Downloads are read-only: recipients cannot upload, rename or delete files. Shared HTML and SVG download as attachments.

Choose access

ModeCommand optionPlans and behavior
Project defaultNo auth optionInherits project policy. If public access is permitted, anyone with the URL can download; CLI and browser display this clearly.
Local password--passwordAll plans. Prompts without echo; recipients enter username rstream and this password in the browser's login prompt.
rstream account--rstream-authPro and Enterprise. Uses the usual account login and project access checks.
rstream token--token-authIncludes Basic. For HTTP/WebDAV clients that send an authorized token on every request.

Account authentication is optional. Local passwords cannot be combined with project authentication. If your project requires authentication, remove the local password option and use the project policy; the CLI rejects conflicting settings. The browser does not collect tokens.

For automation, use --password-file /path/outside/share/password or pipe a password to --password-file -. Keep that file outside the shared directory. --username changes the default username. Password values are not accepted as command-line arguments or printed in status output.

Select the files to expose

Directory shares omit dotfiles and dot-directories by default. Add --include-hidden deliberately when they are needed. Exclusions apply equally to listings, direct URLs and ZIP. Selecting a single file that matches an explicit exclusion is an error:

rstream files ./exports --exclude '*.log' --exclude private

--exclude is repeatable and case-insensitive. A glob without / matches names at any depth; a root-relative glob such as reports/*.csv targets that path. Matching a directory excludes its descendants. *, ? and character classes follow Go glob rules; ** is not a recursive glob. Files outside the root, including through symlinks, cannot be downloaded. In-root symlinks are supported.

Choose the transfer backend

WebDAV is the default. Add --backend webrtc for read-only peer transfers using your rstream project's STUN/TURN servers:

rstream files ./exports --backend webrtc

The browser keeps the same folder navigation and download controls. Browsers with a disk-save API choose a destination before transferring and stream without buffering the entire file in memory; progress and Cancel appear during the download. Other browsers and native link actions use HTTP attachment downloads. That compatibility path uses normal tunnel traffic.

WebRTC transfers directly between your device and the recipient when the network permits it; otherwise, rstream TURN relays the transfer. Direct file transfers bypass the tunnel. Relayed traffic uses the project's separate TURN quota.

With WebSocket terminal transport and terminal E2E disabled, enable the same transfer mode using rstream webtty server --fs-root ./exports --fs-backend webrtc. CLI clients, local MCP tools and SDKs detect the selected backend automatically. WebRTC supports listing and downloads; uploads and other write operations return a read-only error.

Download with the CLI or local MCP

Give a share a name with rstream files ./exports --name exports, then download a file from another configured device:

rstream webtty fs --url rstrm://exports download /report.csv ./report.csv

The filesystem client detects WebDAV or WebRTC automatically. rstrm:// uses a private Engine connection even when the share also has a public URL. If your token can open streams but cannot read inventory, add --no-discovery and use an exact tunnel id or name. Use --fs-path for an endpoint other than /fs.

Local MCP filesystem tools accept the same target and dial privately without inventory discovery. Pass fs_path when needed. Server authentication and the share's read-only policy remain enforced.

Large downloads and WebDAV

Individual downloads support HTTP Range, HEAD, ETag and Last-Modified. A client can resume an interrupted file:

curl -C - -o backup.tar.zst 'https://<share-host>/fs/backup.tar.zst'

For password access, add --user rstream to let curl prompt. When files may have changed, use an If-Range validator to avoid combining different versions. Files are live, not a snapshot: leave them stable during transfer.

The WebDAV endpoint is /fs/. Clients can use OPTIONS, PROPFIND with Depth 0 or 1, GET and HEAD. Other methods are forbidden. URL-encode each path segment, including spaces, #, ? and % in filenames. The browser handles this automatically.

ZIP streams while it downloads, without staging the full archive. An interrupted ZIP must restart. Two ZIP streams can run simultaneously; further requests receive HTTP 429 and can retry. A directory may contain at most 10,000 raw entries for listing; share a smaller directory if HTTP 507 is returned. Archives are limited to 100,000 entries and 64 directory levels, and reject symlink cycles. They support ZIP64 for large files and use store mode rather than compression. The browser displays 100 entries per page.

Tunnel options and automation

Use --name, --host and repeatable --label for naming, a stable domain and metadata. Global context, region, transport and logging options apply normally. --retry-interval sets the reconnection interval in milliseconds.

-o json emits the tunnel status and forwarding URL plus files metadata: contract version, shared name, kind, backend, access and capabilities. The same metadata is available at /_rstream/files/v1/info. Backend is webdav or webrtc; read, list and resume are supported, write and e2ee are false, and archive is available only for directory shares.

A file share runs independently of WebTTY and does not require registering a WebTTY server. The WebTTY filesystem sidecar also works on lightweight and registered persistent servers when the terminal uses WebSocket and E2E is disabled. WebDAV and WebRTC backends use the advertised filesystem endpoint; WebTransport terminals currently have no filesystem sidecar.

Encryption and the hosted file-sharing tool

With WebDAV, HTTPS encrypts traffic between the recipient and rstream, and the agent tunnel encrypts traffic between rstream and your device. WebRTC encrypts the peer connection, including when TURN relays the transfer. HTTP compatibility downloads use the WebDAV transport path.

rstream files does not encrypt files with a separate, recipient-held key. The hosted file-sharing tool encrypts files before upload and includes the decryption key in the download link. Use rstream files to keep files on your connected machine and let recipients browse or resume downloads; use the hosted tool for a temporary encrypted upload.