self-hosted · open-source backend

Muxr

Attach to your remote herdr and zellij sessions from your phone or tablet.

A Frust-native client that drives your herdr or zellij multiplexer over TLS-secured, bearer-authenticated gRPC — full session, tab, and pane control with touch-native gestures.

┌──────────────────────────────┐ │ muxr · remote attach │ │ TLS + bearer · QR pairing │ └──────────────────────────────┘
Muxr on an iPhone showing a zellij session with a file tree, a shell and a floating log pane
your zellij layout, as you left it
what you get
// features

Built for remote terminal control

Everything you need to drive a herdr or zellij server from a touch device — secured, self-hosted, and open at the boundary.

TLS + bearer auth

Every connection is encrypted and authenticated. The gRPC boundary speaks the muxr.v1 protobuf contract over fingerprint-pinned TLS with bearer-token auth.

QR-code device pairing

Pair from the setup TUI by scanning a QR. The code pins the server's TLS certificate fingerprint — cert-pinned trust, no manual cert wrangling.

Full session, tab & pane control

Create, rename, and close sessions, tabs, and panes — or switch spaces on herdr. Drive the whole multiplexer, not just a single attached pane.

Touch-native gestures

Tap to focus, tap again for the keyboard, long-press to fullscreen a pane, swipe back to peel immersive layers. A modifier key bar covers Ctrl, Alt, Esc, arrows.

Tablet split-pane rail

On tablets a persistent 220 px pane rail lists tabs and panes alongside the terminal — collapsing to a 56 px icon mini-rail in immersive mode.

Read-only tokens & biometrics

Mint per-device tokens, read-only or read-write — mutating RPCs fail closed on read-only. Saved credentials are gated behind a biometric unlock for one-tap reconnect.

how it works
// three steps

From bare server to pocket terminal

Self-host the open-source backend, pair once, and you are driving herdr or zellij from anywhere on your network.

01
Run the server
Build or Docker-run muxrd next to your herdr or zellij install — it auto-detects whichever is present. It binds 127.0.0.1:50051 by default — put the machine on your tailnet and bind its Tailscale address in the setup wizard.
02
Pair with a QR code
Open the muxrctl setup wizard, mint a token, and scan the QR it shows. The code encodes the host, port and token; for a self-signed server it also pins the certificate fingerprint, and for a CA-signed server it uses system trust — no further prompts.
03
Control from your phone
Attach to any session and drive tabs, panes, and the keyboard. A biometric prompt offers to save the credential for one-tap reconnect later.
in the terminal
// session log

It speaks herdr and zellij

The server relays over your multiplexer's native IPC — zellij's Unix-domain sockets or herdr's wire protocol — so what you see on the phone is the real session state.

muxrctl · server
$ muxrd start --daemonize --bind 0.0.0.0:50051 → zellij 0.45.1 detected (version match ok) → TLS cert loaded ~/.local/share/zellij/muxrd/ → listening on 0.0.0.0:50051 (SAN: 192.168.0.42)   $ muxrd create-token --name mobile ✓ token created  3f9a2c1b-7e44-4d02-9c6a-1b8e5f0d2a77  read-write   $ muxrctl # dashboard → w wizard → scan the QR ● client attached  phone · iPhone  3 sessions, 7 panes