A private remote workstation for two machines. You sit at the viewer and work on a virtual display the host creates for you. With permission granted at the host, you can also see and control one of its real screens.
Two apps, nothing else:
- Sensorium runs on the machine you sit at.
- Sensorium Host runs on the machine you work on.
No account, no relay, no telemetry, no command line.
- One viewer machine and one host machine.
- The host runs macOS 13 or later. Built and tested only on macOS 26.
- The viewer runs macOS 13 or later, or Fedora 44 with Wayland.
- Both on the same Tailscale tailnet. Nothing else can reach the host.
- Build both apps with
SENSORIUM_ALLOW_ADHOC=1 ./Scripts/package-apps.sh. See Install to keep permissions across rebuilds. - Open Sensorium Host on the host machine. Grant what its window asks for.
- Open Sensorium on the viewer machine. Pick the host. Type the six-digit code.
Docs:
- Install
- Install on Linux
- Permissions
- Privacy
- Threat model
- Wire protocol
- Host screen mode
- User interface spec
- Design system
- Testing
- Uninstall
Nothing runs in the background, so removal is manual. On each machine:
- Quit the app. On the host, end any session first so its canvas is released.
- Delete
Sensorium.apporSensorium Host.app. - Delete its data, which forgets the pairing:
rm -rf ~/Library/Application\ Support/Sensorium - Remove its permission rows in System Settings, Privacy & Security.
If you added the optional PF firewall rule, see Uninstall.
Works between the two machines it was built for. Pairing, virtual display, pinned-identity QUIC transport, H.264 video, input, clipboard and reconnect all run. Host screen mode runs too, and a locked host screen unlocks by typing at it from the viewer. Not signed, not notarized, not yet tested on other hardware.
Swift 6. No dependencies. No Xcode needed. Run the tests with
./Scripts/run-unit-tests.sh. See testing and
CONTEXT.md for the words the code uses.
- Changing physical displays. One exception: a host screen's resolution, on request, restored afterwards.
- Backend, accounts, browser viewer, relay, telemetry.
- Audio, file transfer, multiple users, pre-boot (FileVault) unlock.
GPL-3.0. Copyright (c) 2026 blutarche.