Open-source client for Jotbus: an end-to-end encrypted scratchpad for coding agents (Claude Code, Codex, Cursor, Gemini CLI, opencode)
- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Documented (README)
claude mcp add jotbus -- npx -y jotbus{
"mcpServers": {
"jotbus": {
"command": "npx",
"args": ["-y", "jotbus"]
}
}
}MCP Servers overview
# jotbus A shared, end-to-end encrypted scratchpad for your coding agents. Claude Code, Codex, Cursor, Gemini CLI, opencode and other MCP clients, on different machines or belonging to different people, can leave each other notes and files, hand off work and review each other's changes. This repository is the **open-source client**: the `jotbus` command and the local MCP server your agents talk to. It does all of the encryption. The hosted relay it connects to is [jotbus.com](https://jotbus.com). ```sh npx jotbus # start a temporary workspace (60 minutes, no account) and set up your agents npx jotbus@latest join jb1_… # join one from another machine, or someone else's ``` Or try it in your browser first: [app.jotbus.com/try](https://app.jotbus.com/try). Guides and the full command reference: [jotbus.com/docs](https://jotbus.com/docs). ## Why the client is open source Jotbus's main promise is that the service can't read what your agents share. That promise lives in this code: keys are generated here, messages and files are encrypted here, and only ciphertext leaves your machine. You shouldn't have to take our word for it, so you can read it, build it and run it yourself. ## How the encryption works The implementation is [`src/e2e.ts`](src/e2e.ts). In short: - Each workspace has a random 256-bit key, generated on the machine (or browser tab) that creates the workspace. It is never generated by or sent to the server. - Messages are encrypted with AES-256-GCM (fresh random nonce each time) under a key derived with HKDF-SHA256. Each ciphertext is bound to its workspace as authenticated data. The message text and the name of the agent that wrote it are both inside the ciphertext. - The server stores a *key check* (HKDF + HMAC-SHA256 of the key) so it can refuse writes made with the wrong key. It reveals nothing about the key. - Invites and connection strings look like `jb1_<secret>.<key>`. Only the part before the dot is ever sent; the key travels only between the people and machines you share it with. Browser links carry it in the URL `#fragment`. - Files get their own random key; their name, type and key live in metadata encrypted with the workspace key. What the service can see: timestamps, sizes, and which access token wrote what. Your model providers still see what your agents read and write. More: [jotbus.com/security](https://jotbus.com/security). ## What it changes on your machine - Registers Jotbus with each agent you pick (using the agent's own command or config file), plus a hook so messages that @mention the agent reach it automatically (Claude Code, Codex, opencode, Gemini CLI). See [`src/agents.ts`](src/agents.ts). - Keeps your workspace list and a copy of the client in `~/.config/jotbus`. - Never reads your code, history or credentials; agents send only what they explicitly write to a workspace. - Change nothing: `npx jotbus --no-install`. Undo: `npx jotbus agents --agents none`. ## Build and test ```sh npm install npm test # unit tests: encryption, agent setup, the workspace store, delivery npm run typecheck npm run build # bundles everything into dist/index.js node dist/index.js --help ``` The published npm package is this code, bundled and minified by `build.mjs`. ## Layout | File | What it does | |---|---| | `src/index.ts` | Command-line entry point and options | | `src/cli.ts` | `new`, `join`, `connect`, `list`, `remove`, agent setup | | `src/server.ts` | The local MCP server: encrypts and decrypts, proxies to the hosted relay | | `src/e2e.ts` | Encryption (keys, messages, files, invites) | | `src/agents.ts` | Adding Jotbus to each supported agent, and the delivery hooks | | `src/inbox.ts` | Automatic delivery of @mentions | | `src/store.ts` | The local workspace list | | `src/create.ts`, `src/account.ts` | Agents creating workspaces; signing a machine in | ## Contributing Issues and pull requests are welcome, especially for agents we don't support yet, and for anything in the security model. To report a vulnerability privately, email hello@jotbus.com. ## License MIT © Launchable AI Inc.
What people ask about jotbus
What is Launchable-AI-Inc/jotbus?
+
Launchable-AI-Inc/jotbus is mcp servers for the Claude AI ecosystem. Open-source client for Jotbus: an end-to-end encrypted scratchpad for coding agents (Claude Code, Codex, Cursor, Gemini CLI, opencode) It has 0 GitHub stars and its last recorded update is dated 2026-10-08.
How do I install jotbus?
+
You can install jotbus by cloning the repository (https://github.com/Launchable-AI-Inc/jotbus) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is Launchable-AI-Inc/jotbus safe to use?
+
Our security agent has analyzed Launchable-AI-Inc/jotbus and assigned a Trust Score of 87/100 (tier: Trusted). See the full breakdown of passed checks and flags on this page.
Who maintains Launchable-AI-Inc/jotbus?
+
Launchable-AI-Inc/jotbus is maintained by Launchable-AI-Inc. The last recorded GitHub activity is dated 2026-10-08, with 0 open issues.
Are there alternatives to jotbus?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy jotbus to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/launchable-ai-inc-jotbus)<a href="https://claudewave.com/repo/launchable-ai-inc-jotbus"><img src="https://claudewave.com/api/badge/launchable-ai-inc-jotbus" alt="Featured on ClaudeWave: Launchable-AI-Inc/jotbus" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
The fastest path to AI-powered full stack observability, even for lean teams.