YOUR MACHINES. ONE ENVIRONMENT.

Different machines.
Same setup.

Your shell, your packages, your familiar shortcuts. Tether keeps them in sync through a Git repo you control.

Open source · macOS · Linux

YOUR SYNC NETWORK Connected
Work laptopmacOS
Synced
Home desktopmacOS
Synced
Your Git repo Encrypted dotfiles
.zshrc.gitconfigpackages
Local files → Encrypt → Git → Your machines↔
YOUR TOOLS, ALREADY INCLUDED
Homebrewnpmpnpmbungemuv

LESS SETUP. MORE BUILDING.

Keep your environment
close, wherever you work.

Your repo. Your history.

Use your own Git repository. Track changes and restore earlier versions when you need them.

Explore the workflow↗

Private by default.

Tether encrypts dotfiles before they reach Git. Your passphrase unlocks them on your machines.

Read about encryption↗

More than dotfiles.

Sync global packages and project configs. Keep your tools and settings together across machines.

See what you can sync↗

THE RIGHT SETUP FOR EACH MACHINE

Connected.
Not identical.

Your work laptop and your server do different jobs. Use profiles to choose the files and packages each machine receives.

Keep your shell consistent. A package goes only to the profiles that have it, so the desktop apps stay on your desktop.

Explore machine profiles
ONE REPO. DIFFERENT PROFILES.
Your Git repoDotfiles + package manifests
WORK

Work laptop

  • Shell config
  • Editor settings
  • Desktop apps
SERVER

Remote server

  • Shell config
  • CLI tools
  • No desktop apps
Example profiles. You choose the files and packages.
BEFORE A SYNCED PACKAGE INSTALLS
  1. Signed by a machine you trustIts record lists this exact version
  2. Old enough. Not known malware.7-day release age · OSV check
  3. Installed with scripts offnpm · pnpm · bun
A package that fails a check waits for your approval.

SUPPLY-CHAIN CHECKS

Synced packages.
Checked first.

A line in a manifest does not install on its own. Each machine signs a record of its packages. Your machine installs a package on its own only when a machine you trust lists it.

Tether skips releases newer than 7 days. It checks npm, pnpm, bun, uv and gem packages against OSV for known malware. It installs npm, pnpm and bun packages with scripts off. A package that fails a check waits in the Inbox for your approval.

See how the checks work

FROM ONE MACHINE TO THE NEXT

A familiar setup.
A few simple steps.

  1. 1

    Connect your repo.

    Install Tether. Select your Git repository and set an encryption passphrase.

    Terminal
    tether init
  2. 2

    Add another machine.

    Run setup on your next machine. Select the same repo and enter your passphrase. Then trust each machine’s key once.

    Terminal
    tether init
  3. 3

    Get back to work.

    The daemon syncs every five minutes. Run a sync yourself whenever you need one.

    Terminal
    tether sync
YOUR SETUP. KEPT IN GIT.
  1. Old machineWiped or replaced
  2. Your Git repoDotfiles + package manifests
  3. New machinetether init
    Files + packages restored
Same repo. Same passphrase. Familiar setup.

MACHINE STATE BACKUP

New machine.
Nothing lost.

Tether keeps a record of your dotfiles and global packages in Git. Replace or reformat a machine, then run setup.

Tether restores your files and installs your packages at the versions your machines use. It asks before it installs packages from a machine you do not trust yet.

See how setup works

BETTER TOGETHER

Share the setup.
Keep your own keys.

Sync team dotfiles and encrypted project secrets. Give each teammate access through their own age key.

Explore team sync

A FEW THINGS TO KNOW

Your setup.
Your decisions.

Do I need a Tether account?

No. Tether uses your existing Git repository and Git authentication. You do not need a separate Tether account.

What gets encrypted?

Tether encrypts personal dotfiles by default. Package manifests remain readable in Git. Team secrets use age public-key encryption.

Read the security model ↗
Can I choose what syncs?

Yes. Select your dotfiles and package managers. Use machine profiles and feature toggles to control each machine.

See configuration options ↗
What if I replace my machine?

Run tether init on the new machine. Select the same repo and enter your passphrase. Tether restores your dotfiles and reinstalls your packages.

See how setup works ↗
Can someone with repo access install packages on my machines?

Not with a manifest change alone. A synced package installs only when a signed record from a machine you trust lists it. Other packages wait for your approval in tether packages inbox.

Read how trust works ↗
Does Tether run on Linux?

Yes. Install it with Homebrew or a release download. tether daemon install sets up a systemd user service. Tether skips Homebrew casks on Linux.

Read the Linux notes ↗
What happens when files conflict?

Tether lets you keep the local version, use the remote version, merge the files, or skip the conflict.

Learn about conflict resolution ↗

READY WHEN YOU ARE

Your next machine.
Already yours.

Install Tether, then run tether init to connect your Git repo.

Install with Homebrew
brew tap paddo-tech/tap
brew install tether-cli
Setup guide ↗macOS · Linux