Skip to content
User Guide

Sharing a session & external guests

From any interactive session — SSH/console, cloud, database, a graphical (RDP / VNC) desktop, or a web application session — you can invite others to watch and take part. That includes both fellow MisterShell users and external guests who have no account, reached by email.

How sharing works

Internal participants join over their own connection to the core, which fans your session out to everyone. External guests reach a one-time link on the public edge instead, scoped to just this session — so the core is never exposed to them:

flowchart TB
  host["Host's live session"]
  subgraph core["Core"]
    relay["Session relay<br/>fans output to each participant"]
  end
  host --> relay
  internal["Internal user<br/>has an account"]
  relay <--> internal
  subgraph edge["Public edge"]
    proxy["Proxy · one-time link<br/>scoped to this session only"]
  end
  guest["External guest<br/>no account"]
  guest <--> proxy
  proxy <--> relay

What you can do

  • Share a live session with internal users.
  • Invite an external guest by email.
  • Chat in-session with all participants.
  • See who is connected.
  • Remove (kick) a participant.
  • Hand off mouse/keyboard control in a graphical session (RDP, VNC, or Web).

Common tasks

Share with internal users

  1. Open the Invite dropdown in the session toolbar. It lists your users by presence — active, idle, or offline.
  2. Toggle a user on to invite them. Users currently offline cannot be invited — their toggle is disabled until they come online.

In a text shell (SSH/console, cloud, database), invited users can both view and type — everyone types into the same terminal at once. A graphical session (RDP, VNC, or Web) is different: only the controller drives, and you hand control off explicitly — see Control in a graphical session below.

Invite an external guest

  1. Open the same Invite dropdown and choose Invite by email….
  2. Enter one or more email addresses.
  3. Click Create invites.

MisterShell generates a one-time join link for each address. The link is shown only once — copy it and send it yourself. A link stays redeemable for 24 hours by default (administrators can change this, up to 30 days); an expired link simply stops working — create a new invite. A Sent invitations table tracks each invite as pending (not yet joined) or redeemed (the guest has joined). Click the Revoke invitation button on a pending invite to cancel it before it is used.

External guests must be enabled by an administrator (an app setting, off by default). If it is off, the modal tells you so and you cannot create guest invites.

See and remove participants

The participants list (the Invite dropdown) shows internal users with a toggle, and a separate External guests section listing each guest by name and email. Click the ✕ next to a guest to remove them immediately.

Control in a graphical session

Text shells let every participant type at once. A graphical session (RDP, VNC, or Web) is different: it has a single controller — one person driving the mouse and keyboard at a time, the owner (you) by default. Everyone else watches the same live screen read-only.

  1. Invite participants as above.
  2. From the Invite menu, hand control to any accepted participant (give-control).
  3. Reclaim control whenever you like — the same button now reads Reclaim control.

A ”… has control” indicator shows who is currently driving. Handing control off releases any keys the previous controller was holding, so nothing sticks. Handing off control uses the same app.session.execute permission as inviting — no extra permission is needed.

The guest experience

A guest opens the join link, enters their name and email, and joins a dedicated page showing the shared session and the chat — the shared terminal for a shell session, or the live screen for a graphical (RDP, VNC, or Web) session.

  • In a shell session, they see recent scrollback on join, not a blank screen, and can type commands like any other participant.
  • In a graphical session, they watch the live screen; like everyone else they only drive the mouse and keyboard while you have handed them control, and where clipboard exchange is enabled they may paste text in but can never copy remote text out.
  • They see the chat history and can chat.
  • A Leave Session button disconnects them — you are notified and they drop off the participants list.
  • Guests share the session’s lifetime: when the session ends (including via the workspace inactivity timeout), the shared view closes for everyone.

In-session chat

A collapsible chat pane is shared by everyone in the session. System messages note when someone joins. Guests receive the prior chat history when they join, so they arrive with context.

Licensing

Sharing with internal users has no license requirement. Inviting external guests requires the Session Proxy add-on in your license and the administrator setting described above — either one alone can block guest invites. Reaching a guest also relies on a deployed Proxy — see Fabric → Proxies.

Permissions

  • Share a session, invite or remove participants, and manage invitations: both app.session.execute and app.resources.execute for the session’s resource location. You must also own the live session.
  • Existing participants and pending invitations remain valid while the live session is active if your permissions later change.
  • Session Policy rules still apply to the session itself.