Peer-to-peer · No account · No server

Your work has
a next chapter.
Same momentum.

Your projects, tools, and unfinished ideas — picked up exactly where you left them, on the other laptop. Not copied. Rebuilt.

StackHandoff.dmg Apple silicon Free & open source

SCROLL TO CONNECT
THE HANDOFF / 01

01 / CAPTURE

Everything you need.
Right where you left it.

Capture the projects, tools, and git changes you choose.

01 — SOURCEYour work machine
Captured workspace READY
The StackHandoff Capture Workspace screen, with two project rows selected — openshorts, flagged as having uncommitted changes, and docs — plus the VS Code and Terminal applications.
main 2 projects · 2 applications
02 — DESTINATIONYour next machine
Restore workspace PAIRED
The StackHandoff Restore Plan screen on the destination machine: four steps in dependency order, three required and one optional, with the patch step and the destination path spelled out.
Paired. Waiting. Your paired device is ready when you are.
awaiting handoff Review before restoring
Paired. Private. Direct. LOCAL NETWORK
Skip animation

The problem

Your setup is not in your files.
It is everywhere at once.

A project is a folder, a branch, a runtime version, three extensions, an API key in your shell, a signed-in account, and a half-finished refactor. Copying the folder gets you none of the rest — so you spend the first hour of a new machine rebuilding the hour you just lost.

Not copied

It does not copy your files

StackHandoff captures a description of your working environment — a manifest — and rebuilds the environment from it. Your source of truth stays where it is.

Never automatic

Nothing happens without you

Every step is shown first, in plain English, before it runs. You review what was captured, skip what you don't want, and apply the rest.

Nothing leaves

No server, no account, no cloud

Your machines find each other on the local network over mDNS and talk directly. There is nothing in the middle to trust with a copy of your setup.

No credentials

You never carry a secret

Variable names travel, never values. Accounts are checked for and asked about. Keys, tokens and cookies are on an explicit never-captured list.

How it works

Four steps, in order, both sides watching.

The source captures, the destination decides. Every frame below is a real screenshot of the app, captured from this repository — click any of them to see it full size.

1

Pair the two machines

Same network, same Wi-Fi. Each side advertises itself over mDNS and you confirm the other one's fingerprint by hand — read it aloud, out loud, if you want to be sure. Trust is per-device and revocable, and you choose what each one may do.

  • Scoped trust: receive, send, files, clipboard
  • Fingerprints compared out of band, not trusted blindly
  • Revoke a device and its keys stop being accepted
2

Capture what you actually use

Pick your project folders, the apps you keep open in them, the runtimes and tools they need, and the URLs you want to reopen. Nothing outside that list is read from the machine — the screen tells you the count as you go.

  • Per-project git branch, remote and dirty state
  • Uncommitted work travels as a patch, applied on the far side
  • Env var names only — presence is checked, values never read
3

Send it, sealed

You see exactly what is in the manifest before it leaves, sealed and encrypted. It goes straight to the other machine over the connection you already set up. No upload, no queue, no size limit that isn't your own disk.

  • Manifest is shown in full before sending
  • AEAD-sealed archive, authenticated with your paired key
  • Preflight runs on the destination, never on the source
4

Review, then restore

The destination builds a plan: every step in dependency order, with the exact final path it will write to. Required steps can't be skipped — a restore that silently drops one produces a workspace that looks right and isn't. Optional ones are your call.

  • Destination folder per bucket, never invented
  • Required steps are locked; optional ones toggle
  • Commands are printed for you to run, never run for you

Your git status survives the trip

Cloned repositories are rebuilt on the destination with the working-tree delta re-applied as a patch. The other machine shows exactly your changes — not a rewritten tree, not a fresh clone with your work missing.

$ git status
On branch main
Your branch is ahead of origin/main by 1 commit.

Changes not staged for commit:
  modified:   src/screens/TransferScreen.tsx
  modified:   src-tauri/crypto/src/keys.rs

What travels

The manifest, in full.

This is the whole of it. Everything below crosses the wire, and nothing that isn't on this list is ever read off the source machine.

{
  "workspace": {
    "name": "Workspace Clone - Win to Mac Transfer",
    "portability": "cross_platform"
  },
  "projects": [
    {
      "name": "openshorts",
      "destination_location_id": "code",
      "git": {
        "branch": "main",
        "commit": "a1b2c3d",
        "dirty_worktree": true,
        "dirty_state_captured": true
      }
    }
  ],
  "requirements": {
    "runtimes":   [{ "name": "node", "version": "22.13.1" }],
    "cli_tools":  [{ "name": "git" }],
    "identities":  [{ "service": "github", "needs_consent": true }],
    "environment": { "presence_only": ["SUPABASE_URL", "API_BASE_URL"], "values_included": false }
  },
  "policy": {
    "automatic_command_execution": false,
    "secret_values_included": false
  }
}

Never captured, in any build

  • Environment variable values, tokens, cookies, private keys
  • Absolute paths — replaced with a redacted hint
  • Credentials in repository remotes
  • Shell history — not read at all
  • Browser history and profile — not read at all
  • Anything you didn't tick on the capture screen

Why it's different

Built to be checked, not trusted.

Direct and authenticated

Noise_IK with X25519 and AEAD. Both ends are authenticated from keys you exchanged by hand, and every byte is encrypted on the way.

Nothing automatic

Commands are printed into a visible terminal for you to run. No workspace arrives able to make this app execute something.

Explains every skip

Denylisted files, missing runtimes, unset variables — anything that couldn't come across is listed in the report rather than quietly missing.

Mac and Windows, either way

Built as a Mac app and a Windows installer. The manifest is cross-platform by construction — it describes intent, not paths.

419Rust tests across crypto, adapters, planner, transfer
102Frontend tests over routing, theming, receive flow
0Servers involved in moving your work

Under the hood

Open source, all the way down.

Tauri shell, a Rust workspace behind it, React in front. Every claim on this page is checkable in the repository.

ShellTauri 2
FrontendReact 18 · TypeScript · Vite · Tailwind
BackendRust workspace — 9 crates
TransportNoise_IK · X25519 · AEAD · mDNS
DataSQLite via SQLx, offline migrations

Get StackHandoff

Pick up on the other machine.

Download

  • Install on both devices
  • No account, ever
  • Nothing leaves your network
  • Builds for macOS and Windows