Remote support for your devices, from a server you run.

MeshRMM is remote monitoring and management in one Linux program: the website, sign-in, device connections, NAT traversal and Agent updates. Install it on your own machine. It doesn't depend on any hosted service.

$ docker run -d --name meshrmm \
    -p 443:443 -p 3478:3478/udp \
    -p 49160-49200:49160-49200/udp \
    -v meshrmm:/var/lib/meshrmm \
    -e MESHRMM_PUBLIC_URL=https://rmm.example.com \
    -e MESHRMM_TLS__CONTACT_EMAIL=you@example.com \
    ghcr.io/gccody/meshrmm-server
$ docker logs meshrmm
INFO starting the MeshRMM server
INFO database ready backend=Sqlite
WARN no accounts exist yet; open this link to
     create the first administrator
     link=https://rmm.example.com/setup#token=…
The first start. Open the link to create your administrator account.

One server. Every part of it is yours.

Technicians and endpoints connect only to your server. Remote sessions then run directly between the viewer and the Agent, and fall back to your server's own relay when a network won't let them meet.

Technician

  • Browser for devices, the toolbox, users and settings
  • Viewer for Windows or macOS

meshrmm-server on your Linux machine

  • Website
  • API
  • Sign-in and roles
  • Session signaling
  • STUN/TURN relay
  • Installers and updates

SQLite or PostgreSQL, plus a data directory for files and keys

Endpoint

  • Agent on Windows or macOS, running as a service

Screen, input, audio and files travel peer to peer, encrypted end to end by WebRTC. Your relay carries them only when a direct path fails.

Install
A Docker image, or a tarball with a systemd unit. Linux on x86_64 or arm64.
Database
SQLite for a single machine, or PostgreSQL if you already run one.
Certificates
Automatic from Let's Encrypt, your own certificate files, or a reverse proxy in front.
Updates
Each server release carries its Agents and viewers. Upgrade the server and they follow.

The server contacts only what you set up: your identity provider and mail server if you use them, and Let's Encrypt if you choose automatic certificates.

What technicians get

Remote desktop that keeps up

The endpoint encodes its screen as H.265 or H.264, on its GPU when it has one, and sends it straight to the viewer. Pick a quality preset, from a 1 Mbps data saver to 12 Mbps, and switch Windows viewers to 4:4:4 color for crisp text when both GPUs support it. Clipboard (text, rich text, images and files), file transfer, chat and system audio come with every session.

Work without taking over the screen

Background mode opens a private desktop on a Windows endpoint, with its own taskbar, Command Prompt, PowerShell, Services and File Explorer, while the user keeps working. It's experimental.

Scripts and files on hand

The toolbox keeps PowerShell, Command Prompt and zsh scripts and a library of files. Run a script from the website or during a session, as the signed-in user or as SYSTEM (root on a Mac), and send files to the device.

Every device at a glance

See which devices are online, with a recent picture of each screen. Add a Windows device with a downloaded installer, or a Mac with one Terminal command.

Maintenance controls

Block the user's keyboard and mouse, black out the screens with your own message while you work, and lock the computer or sign the user out when you leave.

The user stays informed

Optionally ask the user to approve each connection, notify them when a session starts, and show a banner and border while it's live.

Restarts don't end the session

Restart a computer from the viewer, into Safe Mode with Networking if you need to. The viewer waits, and the session picks up again when the Agent is back.

Computers without a monitor

When a Windows computer has no monitor connected, the Agent adds a virtual one for the session, at the size you choose.

Sign-in and permissions, built in

Accounts live in your database. Connect your identity provider if you have one; you don't need one.

  • Strong sign-in. Passwords with authenticator-app codes, recovery codes and passkeys. Require two-factor sign-in for everyone.
  • Single sign-on. Any OpenID Connect provider, with SCIM to create, update and disable users from your directory.
  • Custom roles. Build roles from permissions such as connecting to devices, running scripts or managing users.
  • Audit log. Sign-ins, settings changes, enrollments, sessions, script runs and file deliveries.
  • Email optional. Send invitations and password resets through your SMTP server, or copy the links and send them yourself.
  • Signed updates. Agents and viewers install only updates signed with the MeshRMM release key, whichever server offers them.

Install

You need a Linux machine with a DNS name, TCP port 443, and UDP ports 3478 and 49160–49200 open to the internet.

  1. Start the server

    Run the Docker image as shown above, or unpack a release tarball and run sudo ./install.sh. Then edit /etc/meshrmm/server.toml and start it with systemctl enable --now meshrmm-server.

  2. Open the setup link

    On its first start the server writes a one-time link to its log. Open it to name your instance and create the first administrator.

  3. Add your devices

    Choose Add device on the Devices page. Download the Windows installer, or copy the Terminal command for a Mac.

Server
Linux, x86_64 or arm64
Agent
Windows 10 version 1903 or newer; macOS 12.3 or newer (still being ported)
Viewer
Windows 10 version 1903 or newer; macOS 12 or newer