Share only what participants should see
Live Share lets participants receive terminal output from a shared session. Read-only access prevents typing; it does not hide output. Before sharing, close sensitive views and consider what the next command, scrollback or session snapshot may reveal.
Start a live share
- Open the intended terminal and choose Share.
- Choose Current Session, not Server Access.
- Select read-only access unless participants genuinely need to type.
- Review approval, invitation expiry, connection expiry and transport options offered by your deployment.
- Start the share and send the invitation through a trusted channel.
- Monitor participants and end the share when the work is finished.
The invitation viewer checks the room's actual state. Typing is available only when the session grants write access. A display name or visible cursor does not itself grant permission.
Treat the complete invitation as a secret
Live terminal content is encrypted before the sharing service forwards it. The invitation password is carried in the link's fragment rather than an ordinary request query. That protects it from being sent as part of the initial page request; it does not make a copied link safe to publish.
Browser history, clipboard managers, screenshots, extensions and recipients can still expose an invitation. Send the entire invitation only to intended participants. Do not paste it into public issues or support logs.
Approval applies to the room, not to a verified personal identity. Anyone holding the current invitation and password may join while the room is approved. A requester's display name is self-reported.
For a sensitive session, confirm recipients separately and end the room when the intended collaboration is over. Do not assume approving a familiar name creates a non-transferable invitation for that person alone.
End access deliberately
Use the sharing controls to end the room or revoke access, and check the result. Expiry and revocation can prevent admission independently of the displayed participant name. An unconfirmed cutoff is not proof that every remote connection has stopped.
Ending the room cannot retract output already received, undo commands already run, or stop every detached process. A viewer reconnect must obtain current permission; interactive input is not meant to be replayed as an automatic recovery mechanism.
For ongoing access through an enrolled agent rather than a view of your current terminal, read delegated server access. For connection choices, see transports and fallback.