vibivibi: encrypted coding agent session backup and sharing

vibivibi backs up, synchronizes, and shares end-to-end encrypted coding-agent sessions across machines and teammates while storing only ciphertext.

Visit Website
vibivibi: encrypted coding agent session backup and sharing

Introduction

Overview

vibivibi is an encrypted backup and sharing service for sessions created by Claude Code, Codex CLI, OpenCode, and Pi. Its vibi command-line client lets users move a session between machines, resume its original history, or send it to a teammate.

Session transcripts and metadata are encrypted locally before upload. The service stores ciphertext and cannot read titles, working directories, model names, transcript messages, passwords, or private keys.

Core Workflow

  • Enroll a machine with a code generated in the dashboard and choose a password that protects the private key.
  • Push a session from its project directory, selecting either personal synchronization or encrypted sharing with another user.
  • Pull an available session on another machine so it is installed where the supported coding agent expects it.

Each session keeps one identifier as it moves between machines. Pushes preserve earlier versions, and integrity checks help prevent incomplete or corrupted transfers from being installed.

Encryption Design

The client generates an X25519 key pair on the user's machine. Its private key is protected with AES-256-GCM using a key derived from the password with scrypt, while each session receives a fresh random 256-bit content key for its transcript and metadata.

Content keys are wrapped separately for recipients using ephemeral X25519 exchange and HKDF-SHA256. A SHA-256 ciphertext hash is verified after upload and before installation. There is no support override or password recovery, so losing the encryption password makes stored sessions unreadable.

Sharing and Teams

A sender can encrypt a session key for a teammate's public key without uploading the full session again. Recipients use their own identity and password to pull shared sessions, while team accounts pool storage and retain visibility into where sessions were sent.

The server can see limited operational data such as the agent type, session identifier, size, timestamps, recipient key fingerprints, and sharing relationships. An optional session name may also remain plain text.

Plans and Limits

  • Free: $0 per month, 200 MB storage, files up to 50 MB, two machines, the latest three versions, and 5 GB monthly downloads
  • Pro: $8 monthly or $6 monthly with annual billing, 20 GB storage, files up to 200 MB, unlimited machines, full history, and 50 GB monthly downloads
  • Team: $15 per member monthly or $12 monthly with annual billing, 100 GB pooled storage per member, files up to 200 MB, full history, administration features, and 200 GB monthly downloads per member

All plans include unlimited sends and use the same end-to-end encryption. Paid plans include a 14-day free trial.