DeskVNC DeskVNC

Attended support with Boundary, end to end

Boundary is DeskVNC's attended support mode. It is for helping someone at a remote machine when the two of you are not on the same network, and the person at the other end stays in charge. This page walks the full flow, from downloading the support app to closing the session, including the shorter handoff with a code service.

The shape of the flow is simple: you send the support app to the person who needs help, they generate a one time invitation or a short code on their machine, they approve your connection, and you join from DeskVNC. Boundary tries a direct encrypted path first and uses its relay as a fallback when the networks do not allow a direct path. No account is required, and the recipient can revoke control or end the session at any moment.

Install the worker side

Boundary support opens from inside DeskVNCViewer, the same client that drives VNC, RDP and SSH. Download the build for the host that will be running the support session from the latest DeskVNC release and open it once to register the helper.

Platform File
macOS 12 or newer DeskVNCViewer_<version>_universal.dmg
Windows 10 or 11 DeskVNCViewer_<version>_x64-setup.exe
Linux, x86_64 the x86_64 binary in a tarball
Any Linux DeskVNCViewer_<version>_amd64.AppImage

The macOS build is signed and notarized, so it opens normally. The Windows installer is signed too. On Windows, if SmartScreen asks, choose More info, then Run anyway; the publisher line should read Open Source Developer Godwin Josh.

Send the support app

The same release page carries DeskVNC Support, a small app whose only job is to give a person a way to invite you in. Send the file to the person who needs help. The file is small and self contained, and the recipient does not need to install anything else. On macOS it is signed and notarized, on Windows it is signed, and on Linux it ships as an x86_64 binary in a tarball.

A practical handoff is to send the file as an email attachment, a chat message, or a link to a specific asset on the release page. The recipient downloads it, opens it, and is ready for the next step.

Recipient: get a code or create an invitation

DeskVNC Support opens to a single screen with two buttons. The choice between them depends on whether a Boundary code service is configured for the recipient.

If a code service is configured, the recipient presses Get a code. DeskVNC Support reaches the code service, gets a fresh code, and displays it as four digit groups, like 1234 5678 9012. The recipient reads the groups out loud, over the phone, in a chat, or however the two of you communicate. The code is good for one lookup. Once you look it up on your side, the code is spent, and the person at the remote computer still approves the session. That separation is the safety property: a code is not a credential, it is an address, and the recipient makes the decision to let you in.

If no code service is configured, the recipient presses Create invitation instead. DeskVNC Support generates a single use invitation, displays it as a long string, and waits. The recipient copies the invitation and sends it to you out of band. The full invitation remains available when no code service is configured, and it works the same way: you paste it on your side and the person at the remote computer approves the session.

The recipient is shown the access request on screen before the session starts. The prompt names who is asking, and the recipient either approves or declines. A decline is final, and the code or invitation is spent.

Worker: open Boundary support and connect

On the worker side, open Boundary support from inside DeskVNCViewer. The dialog asks for the invitation or the code, depending on which the recipient gave you.

For a code handoff, the worker types the four digit groups in the order they were spoken, separated by spaces, exactly as 1234 5678 9012. The server looks the code up against the code service and resolves it to a live invitation. The lookup is the single allowed use; the code is spent the moment the worker submits it.

For an invitation handoff, the worker pastes the long invitation string. The dialog accepts it as a single block.

Once the code or invitation resolves, the worker side shows a connection summary: the name of the recipient's machine, the address Boundary will try, and a button to start the session. The worker presses the button, and Boundary tries a direct encrypted path first. A direct path is a peer to peer negotiation between the two machines: Boundary opens a UDP path, negotiates keys, and verifies that the recipient's machine is reachable. When the networks cooperate, the session runs over that direct path and no traffic is relayed.

When the networks do not allow a direct path, Boundary falls back to its relay. The relay carries the encrypted session traffic without being able to read it, and the same security properties hold. The worker side does not have to know which path is in use; the connection just opens.

During the session

The session is a normal DeskVNC session. The worker has the ordinary toolbar at hand: input, display, scaling, clipboard, file transfer, screenshot, fullscreen, and a clean way out. The remote machine appears as a tile in the worker's window with an indicator showing that it is a support session.

Two things are different on the recipient's side and worth naming. First, on macOS the support app prompts for Screen Recording and Accessibility permissions the first time sharing or control needs them. Granting them is required for the session to work, and they can be revoked later in System Settings without breaking the rest of the app. Second, the recipient can revoke control or end the session at any moment. A revoke releases the worker's held keys and buttons so a half finished drag cannot strand the desktop, and the worker side sees the session end with a clear message.

A worker who needs to hand the machine back to the recipient during the session can do so by clicking the Take the wheel control on the recipient's pane, which revokes the worker's control without ending the session. The worker resumes by pressing the same control again.

Code service vs private service

The default code service is the shared Boundary service, which is good enough for most one off help sessions. Configure it by pointing the support app at the public Boundary service during the first launch, and the recipient's Get a code button starts producing codes that resolve through that service.

For a shorter handoff inside an organisation, run a private Boundary code service. Private services have the same shape as the shared one: the support app reaches the service over the network, gets a code, and the worker side looks it up against the same service. A private service means codes only resolve inside the organisation, which is a tighter trust boundary and a shorter handoff. The repository's 14-support-codes.md file documents private code services for operators who want to run their own.

In every case, the security property is the same: the code is an address, not a credential. A person at the remote computer still approves the session, and a code is spent the moment the worker side resolves it.

Closing the session

When the work is done, the worker presses the end session button on the Boundary support dialog, or quits DeskVNCViewer. The recipient's side ends the session immediately, the screen sharing stops, and the support app returns to its home screen. The recipient can also end the session at any moment from the same dialog, and the worker side sees the session end with a clear message.

A code or invitation is one use, so a follow up session needs a fresh code or invitation from the recipient. The boundary design treats each session as a deliberate act on both sides, and the work to send a code or paste an invitation is the price of that deliberation.