Skip to content

Team Profiles ​

On the Team plan, everyone on the team can share one set of saved connection profiles. The team owner turns it on once, gives members the team passphrase, and from then on a profile shared with the team appears on every member's devices, cluster token included, so nobody has to pass tokens around by hand.

Team profiles use the same zero-knowledge encryption as personal Account Cloud Sync. The cloud only ever stores ciphertext, and the cluster tokens in shared profiles never reach it in the clear.

Requirements ​

  • An active Team license (see Accounts & Licensing).
  • Each member signed into their Clusto account in the app.
  • The team passphrase, which the owner hands to members themselves.

Team profiles live in Settings > Account, in a Team profiles card below the personal Cloud sync card. You see one card for each active Team license you belong to.

Setting it up (team owner) ​

Only the team owner can set up profile sharing.

  1. Open Settings > Account and find the Team profiles card.
  2. Choose a team passphrase.
  3. Give the passphrase to your members yourself, through whatever channel you trust (in person, a password manager, an encrypted message). Clusto never sends it anywhere, and it never reaches the cloud.

Until the owner does this, members see "Your team owner has not set up profile sharing yet".

Joining (members) ​

Once the owner has set it up, the card asks for the team passphrase. Enter it once to unlock. The passphrase is remembered on that device, so later launches unlock silently, the same way personal cloud sync does. Repeat on each device where you want the team's profiles.

Encryption ​

  • Encryption is AES-256-GCM.
  • The key is derived from the team passphrase with PBKDF2-SHA256 (600,000 iterations).
  • Encryption and decryption happen on each member's device. The cloud stores one encrypted vault per Team license and cannot read it.

Because the server never holds the passphrase, it cannot recover it. A lost passphrase is handled with Reset passphrase.

Sharing a profile ​

On the Connection page, open a saved profile's menu and choose Share with team. The option shows once a team vault is unlocked on this device.

  • Shared profiles carry a Team badge and appear for every member.
  • Any member can edit a shared profile, and the edit reaches everyone.
  • Any member can delete a shared profile. Clusto asks for confirmation first, because it is removed for everyone on your team.
  • Stop sharing takes the profile out of the team for everyone, but keeps your own copy as a personal profile.

A profile belongs to exactly one place: your personal cloud sync or the team vault. Sharing moves it out of your personal cloud sync into the team vault, and Stop sharing moves it back. The per-device Default flag is not shared, so each member picks their own default.

Name conflicts and concurrent edits ​

  • If you already have a personal profile with the same name as a team profile, the team profile is not added on that device. The Team profiles card lists the conflicting names. Rename your personal profile to get the team copy.
  • If two members edit the same shared profile around the same time, the newest edit wins.
  • Deletions stick. A deleted shared profile does not come back from an older copy on another member's device.

Card controls ​

  • Sync now - push and pull team changes immediately.
  • Turn off on this device - removes the team's shared profiles from this device and forgets the passphrase here. The team keeps its profiles, and other devices and members are unaffected.
  • Reset passphrase (owner only) - see below.

Reset passphrase ​

The owner can reset the team passphrase from the card, or from Forgot it? Reset on the unlock form. A reset:

  1. Clears the encrypted team copy in the cloud.
  2. Lets the owner set a new passphrase. The owner's shared profiles are then uploaded again under the new key.
  3. Requires every member to unlock again with the new passphrase.

Reset the passphrase after someone leaves the team, and rotate the cluster tokens they had access to. A reset alone does not change the tokens on your nodes, and a former member may still have a copy of them.

Leaving or removal, and lapsed subscriptions ​

  • When a member leaves or is removed from the team, their app removes the team's shared profiles from their devices on the next sync.
  • If the Team subscription lapses, sharing pauses. Profiles already on each device stay there as local copies.

Command palette ​

Press F1 for these actions:

  • Manage team profiles
  • Sync team profiles now
  • Share "<name>" with team
  • Stop sharing "<name>"

Clusto - remote AI coding agents over WebSocket.