Documentation

Documentation

Install the relay, enroll Windows machines, and license the deployment.

Secure Desk has two halves. A Node.js server on a Linux host serves the technician portal, the public join page, the browser console and the WebSocket relay. A native Windows client runs on each supported machine. You install the first once; the second gets distributed to the machines you support.

Read this first: who is who

The naming is consistent across the product, the protocol and these docs, and getting it backwards will make everything else confusing.

  • Client — the computer receiving support. It shares its screen and receives input.
  • Agent — the support technician giving support. They view the screen and send mouse and keyboard.
  • Relay — your server. It pairs an Agent and a Client and forwards bytes between them.

So: the Agent connects to the Client.

The short version

  1. Provision a Linux VM with a public DNS name, download the release, extract it and run sudo bash install.sh.
  2. Read the one-time setup token out of the service log, open /setup and create the admin account and TLS settings.
  3. Get a free license, read the Node ID from Settings → License, activate, and paste the key back in. Skip this and you run as free Starter.
  4. Create a support session in the portal and send the join link — or install the client as a service on the machines you want unattended access to.

Nothing is configured from a file. On first start the relay prints a one-time setup token and funnels all traffic to /setup. Secrets are generated and stored in the data directory, not committed to a config you might paste into a ticket.

The Secure Desk portal dashboard, v0.3.94, showing seven devices online, seven installed devices, two customers, no pending requests or active sessions, seven portal users, six updates available, and an Enterprise LICENSE - OK tile. The signed-in identity chip is redacted.
Portal dashboard. Identity redacted.

Requirements

  • Server: a Linux host with Node.js 18 or newer. Developed and tested on Debian with Node 22.
  • Database: PostgreSQL in production — the Debian installer provisions it for you. Without DATABASE_URL the relay falls back to an in-memory store that is wiped on restart; that is for local development only.
  • DNS + TLS: a public name pointing at the host, with ports 80 and 443 reachable so Let's Encrypt can issue. Browsers will not open a WebSocket to an untrusted certificate.
  • Endpoints: Windows on the supported machines. The technician console is the browser page — a web page cannot be the supported-machine client, and there is no supported native technician application.

Where to go next