Security
How noxed protects your servers and credentials
noxed holds the keys to your infrastructure, so it's built to keep secrets out of files, keep data on your machine, and treat its own UI as untrusted.
Where your data is stored
| Data | Where it lives |
|---|---|
| Passwords and other secrets | Your OS keychain: macOS Keychain, Windows Credential Manager, or libsecret on Linux. Never written to a config file. |
| Connection details (host, port, username, key path) | A local settings file in noxed's app-data folder on your computer. |
| SSH private keys | Stay where they already are. noxed stores the path and reads the key only when connecting. |
No accounts, no cloud, no telemetry
noxed has no sign-in, no sync service and no analytics in the app. It connects only to the servers, databases and clusters you configure. The one other request is the update check: installed builds ask GitHub Releases whether a new version exists when they start, and nothing is downloaded until you agree.
SSH host key verification
noxed checks every SSH server's host key before sending credentials. Keys you already trust in ~/.ssh/known_hosts (hashed entries included) are accepted automatically. A host noxed hasn't seen before shows its SHA256 fingerprint for you to confirm. If a trusted host presents a different key, noxed warns you and won't connect unless you choose to replace the key. You can review and remove trusted keys under Settings → Security → Known Hosts.
Claude Code access (MCP)
Off unless you turn it on. When it's on, noxed runs an MCP server that listens only on 127.0.0.1 and requires a random token kept in your OS keychain. It also rejects requests that come through a web page. Claude Code never sees your passwords or keys: commands run over the connections noxed already holds. Every command and file read waits for your approval in noxed, and a short list of destructive commands (such as rm -rf /, mkfs and shutdown) is always refused. While noxed is locked, every request is refused. Issuing a new token in Settings cuts off clients that used the old one.
Lock screen
An optional lock screen protects saved credentials with Touch ID, a PIN or a password. It can lock automatically after a period of inactivity. While noxed is locked, secrets aren't released to the interface.
Restricted file access
SSH keys are only read from ~/.ssh, ~/.config/ssh and ~/.pem. Kubeconfigs are only read from ~/.kube and standard config folders, plus files you explicitly import. A compromised UI can't ask the app to read arbitrary files.
Sandboxed, untrusted UI
noxed is an Electron app with a sandboxed, context-isolated renderer. All system access (SSH, SFTP, databases, Kubernetes, keychain) lives in the main process, behind handlers that validate every input. They also check that a window only uses connections it opened.
Guard rails
- The Redis command line blocks destructive commands.
- Docker, metrics and Kubernetes features use your existing SSH connection or kubeconfig, so nothing has to be installed on your servers.
Signed releases and open source
macOS builds are signed with an Apple Developer ID and notarized, and Windows installers are code-signed. All the source code is on GitHub under the MIT license, so you can audit it or build it yourself.
Reporting a security issue
If you find a vulnerability, please open an issue on GitHub without exploit details, and the maintainer will follow up.