What Vibivibi does: a small CLI, `vibi`, finds the sessions your coding agents keep locally (Claude Code, Codex CLI, OpenCode, Pi), encrypts one on your machine and uploads it. On another machine `vibi pull` puts it back where the agent expects it, so `claude --resume <id>` just continues. `vibi push` can also send a session to someone else by email.
Our service cannot read session content. Each user has a key pair made on their first machine; the private key reaches the server only wrapped with a key derived from an encryption password that never leaves the user's machines. Every session version is encrypted with its own random key, which is then wrapped for each recipient (X25519, HKDF, AES-256-GCM). The server sees account emails, public keys, machine names, sizes, timestamps, who sent what to whom, and an optional plain-text label.
Sending to someone who doesn't have an account yet works too: the sender's client makes a key pair on their behalf, locks it with a random 12-character passphrase, and shows the sender that passphrase to pass on out of band. When the recipient signs up and enrolls a machine, their client unlocks it locally and re-keys the session to their own key.
The client is open source (Apache-2.0): https://github.com/subconscious-systems/vibi-cli The crypto and the schemas of everything the client sends live in one package, so the claims above can be checked against the code. It ships as a single executable, no Node or npm needed: `curl -fsSL https://vibivibi.com/install.sh | sh`, or build it yourself. The server (Next.js on Vercel, Postgres, blob storage) is not open source.
Pricing: free for 200 MB of encrypted storage and unlimited sends; Pro is $8/month for 20 GB; Team is $15/seat with an admin view and a "send only inside the team" policy.
Honest limitations: - There is no password recovery. Forget the encryption password and the key, and everything encrypted for it, is gone.
I'd like to hear where the threat model falls short, and which agents or workflows you'd want supported next.