Working together
Drawbridge can put two or more people in the same diagram at the same time, live. It works in the desktop app and in the browser, and they are the same session: someone in a browser tab can host, and people on the desktop app can join them, or the other way round.
Everything lives in the App menu (the ☰ button at the right of the toolbar), under Share… and Join….
Start sharing
- Open App menu → Share…
- Type Your name — it is the label shown at your cursor for everyone else.
- Press Start sharing.
You become the host. Sharing stays up while this window is open — but closing it no longer scatters everyone: the session is handed to whoever has been connected longest, and the rest follow them automatically. Nothing is lost either way, because every participant already holds the whole diagram.
While you host, the Share popover shows:
- Three tabs — Invite, View-only and Personal — over one link field. They are three ways to invite someone to the same session, so you see one link at a time, with one line explaining it and that link's own buttons underneath. Invite is the everyday one.
- The link with a Copy button. It is an ordinary
https://…#c=…link, short enough to paste into a chat without being broken up, and it opens in any browser on any machine. The secret sits in the part after the#, which browsers never send to any server. - Copy app link — the same invite as a
nudge://collab/v1#…link, which opens the installed desktop app directly instead of the web app. Both builds offer both forms; send whichever suits the person you are inviting. - Copy code — the same invite encoded as plain text, for chat apps that mangle links.
- Regenerate — makes a new session secret. Old invites stop working; people already connected stay connected.
- Let anyone in — opens the door for twenty minutes so guests skip the lobby. See below; it is never on until you press it.
- People — everyone in the session, each with their colour dot, a Follow button, and, for the host, a Kick button. Peers are labelled
directorrelaydepending on how they connected. - Stop sharing.
Share from the current version. When a newer build is waiting in your browser (the brand mark is lit), the Share panel says so before you start and offers Update now. Nothing stops you from sharing anyway, but the people who follow your link get today's build, and a session between two versions is one nothing has tested — so update first.
View-only links
The View-only tab holds a second invite for the same session. Whoever follows it sees the diagram and every live edit, has a cursor and a name like anyone else — and cannot change anything.
It is enforced by your machine, not theirs. Their edits are refused as they arrive, so nobody else in the session sees them either, even for a moment. That matters: a view-only guest is running the same app you are, and an app that only greyed out its own buttons would be relying on the guest's good manners.
The rest works exactly like the editing link: view-only guests wait in the lobby for you to let them in — and walk straight in while the door is open, described below — they show up in People tagged view only, and Regenerate revokes the view-only link along with the editing one.
If you join with a view-only link, Drawbridge tells you so on arrival and quietly ignores your edits until you leave. Leaving hands you back your own editable copy — the restriction belonged to the session, not to the diagram.
Join a session
An https://… invite opens in a browser and goes straight to the join dialog. A nudge:// one does the same in the installed desktop app — but only there: a browser has no idea what to do with it and clicking one does nothing at all. If you have been sent a link your machine will not open, use App menu → Join… and paste the link or the invite code, which accepts every form.
Enter your name and press Join. Because joining opens the host's diagram in your window, Drawbridge first asks to confirm if you have unsaved work — you can Cancel, Save first…, or Replace and join. Your file on disk is never touched.
The dialog then walks through the connection steps: finding the host, connecting, checking the invite, waiting for the host to let you in, syncing the diagram, live.
Common failures are reported plainly: the host declined your request, the invite is invalid or was regenerated, or the invite uses a newer link version and you need to update Drawbridge.
Leave session returns you to your own window with the diagram intact.
The personal link
The ordinary invite link is tied to the current sharing session. The link on the Personal tab is reusable: it keeps a persistent secret, so anyone who saves it can rejoin whenever you are hosting — you never have to send a fresh link again.
Being the link people keep is also why it is the one link Let anyone in never opens. Someone holding a personal link knocks every time, however busy you were twenty minutes ago.
It has its own Copy, Copy app link, Copy code and Reset. Resetting mints a new personal link and invalidates every personal link you handed out before. That is how you revoke access for someone.
Approval and the lobby
A valid link only lets someone knock. Nobody sees your diagram until you say yes, and there is no setting anywhere that changes that. When you are letting a roomful of people in at once you can open the door for twenty minutes, described below, and it shuts by itself afterwards.
When someone knocks you get a notification (Review) and a Waiting to join section at the top of the Share popover, with two actions:
- Allow — let them in.
- Deny — decline the request.
Approval is per session: if you stop sharing and start again, the same person knocks again. Nothing is remembered, and there is no list of people to maintain or forget.
There used to be a switch that turned this off, and it is gone. Turning it off was the moment the risk was taken: invite links are reusable and people keep them, so from then on anyone still holding one — including from a link you shared months ago — walked in and could edit, with no prompt. A setting whose only setting is "less safe" is not worth having.
Letting a roomful of people in
Ten people arriving at a workshop is twenty clicks, and wanting out of that is fair. Press Let anyone in and, for the next twenty minutes, anyone holding this session's Invite or View-only link joins without knocking. While it runs, the popover counts the time down and offers End now — on whichever tab you happen to be looking at, since the door belongs to the session rather than to one link — and the toolbar pill reads · open so you can see it from anywhere in the app.
Then it shuts on its own, which is the half that makes it worth having. It is an action, not a mode: nothing is stored, there is nothing to find switched on next week, and every new sharing session starts with the door shut. The twenty minutes are not adjustable — a choice of durations would put a decision in front of you at the one moment you are busy letting people in.
Two things it deliberately does not do. It never opens the personal link, because that is the one meant to be kept and reused. And it is not a skeleton key: someone you kicked stays kicked, a view-only guest is still view-only, and an invite you have since regenerated is still dead. It changes who has to wait, not who is allowed.
Saved sessions and "joinable now"
Your invite to a session is saved so you can rejoin in one click. Open Join… and the Saved sessions list appears above the paste box; click a host's name to rejoin, or × to forget it.
Each saved host has a status dot, probed when the dialog opens and every 20 seconds while it is open: Online — joinable now, Offline, or Checking….
Saving the secret is only safe because a human still has to let you in each time. An open door does not change that: it is twenty minutes inside a policy that is still approval, so what you saved is still a knock, and a saved invite is saved the same way whether you arrived through the lobby or through the door. If you ever meet an older host that does not gate on a lobby at all, Drawbridge tells you it did not save the invite — storing that secret would amount to standing, silent access to that host's diagrams.
Seeing each other
- Each person has a colour. Their cursor is drawn on the canvas with their name on a tag.
- Nodes a person has selected get an outline in their colour.
- Presence is per page: you only see someone's cursor and selection when they are on the same page you are. The pages bar shows who is on which page.
- Cursors and presence are never saved into the file.
Following someone
Press Follow next to a name in the People list and your view matches theirs: their panning and zooming moves your canvas, and if they switch to another page you go with them. It is the fastest way to be walked through a diagram without anyone saying "scroll left a bit, no, up".
Two things make it safe to try:
- Any pan or zoom of your own stops it. Reaching for the canvas is stopping following, so there is nothing to remember to turn off. Press Follow again if you want it back.
- It never changes the drawing. Following moves your view and nothing else, and the person you follow cannot tell you are there.
While you are following, the toolbar pill reads Following name instead of the usual count, because a canvas that moves on its own with no explanation reads as a fault.
Because everyone's window is a different size, you get at least what they can see rather than an exact copy of their screen — showing less would hide the very thing being pointed at.
The toolbar shows a live pill — Live · 3, plus · relay when at least one connection is going through a relay and · open while you have let anyone in. Click it to open the Share popover. It also reports Reconnecting… during a blip, Waiting to be let in… when you are asking a host to admit you, and Session ended afterwards, with a banner offering Share again.
When the host leaves
Close the window while other people are connected and Drawbridge hands the session on rather than ending it. The longest-connected participant becomes the new host — they are told so, and given the new link to invite anyone else — and everyone else reconnects to them on their own.
Nothing is transferred to make that work. Every participant already holds the complete diagram, which is why the hand-over is instant and lossless.
You will be asked to knock again, and that is deliberate: the lobby belongs to whoever is hosting, and the new host has not admitted anyone yet. Your pill reads Waiting to be let in… until they answer — so if a hand-over seems to be taking a while, the thing to check is whether the new host has an unanswered request waiting, not the network.
Two details worth knowing:
- A view-only guest is never made host. A host who cannot edit the diagram is not a host.
- If nobody else is connected, closing the window is just closing the window.
If the host's machine dies rather than closing cleanly — a crash, a pulled cable — there is no hand-over, because there was no chance to arrange one. That is the old behaviour: the session ends, everyone keeps their copy, and anyone can share again.
Changing your name mid-session
Your name is the label at your cursor and the entry others see in People. You do not have to get it right before you start: open the share panel (click the status pill, or App menu → Share…), click your own name in the People list, type a new one and press Enter. Everyone sees the change straight away — nothing reconnects, nobody is dropped, and the session carries on. Escape puts the old name back if you change your mind.
This works whether you are hosting or have joined, and the new name is remembered for next time.
An AI assistant can join too
A collaborator does not have to be a person. An AI assistant connected to Drawbridge's local MCP server can join a session you are hosting and edit the diagram beside you — so instead of asking for a whole new drawing every time something is wrong, you ask for a change, watch it appear, and say "no, put the firewall above the core" while the diagram is still in front of you.
It is invited exactly like anyone else:
- Press Share… and start sharing, then copy the ordinary Invite link — or the invite code. The View-only link will not do: an assistant needs to be allowed to edit, and one that joined view-only would have every change refused.
- Give that link to the assistant and ask it to join. It connects through the MCP server running on your own machine; nothing about the session passes through anything of ours.
- It knocks, and waits in the lobby like any other joiner. Press Allow, and it appears in People under the name it joined with, with a colour of its own.
From then on it is an ordinary participant. Its edits arrive on your canvas as it makes them, the pages bar shows which page it is working on, your undo undoes your own work and never its, and Kick removes it the moment you want the diagram back to yourself. When it is finished it leaves like anyone else.
Two things are worth knowing. An invite is a password, so handing one to an assistant hands your diagram to whoever runs that assistant — the same choice you make when you invite a person. And this is the local MCP server only: the hosted one deliberately cannot join a session, because joining would mean our servers holding your invite secret and sitting in the middle of every edit. AI assistants (MCP) covers how the assistant is set up.
What "peer-to-peer" means here
Traffic goes directly between the participants' machines over QUIC, using iroh. There is no Drawbridge server, no account, and no copy of your diagram stored anywhere but on the participants' own machines.
- All traffic is outbound. No port forwarding, no inbound firewall rules, no UPnP.
- When a direct path cannot be punched through (symmetric NAT, hostile firewalls), the connection falls back to the Drawbridge relay. It forwards encrypted traffic it cannot read, and hands off to a direct path if one becomes available later. The status pill tells you when you are relayed.
- The invite secret is what proves you are allowed in — a joiner must prove knowledge of it before any diagram data flows. Treat an invite link like a password.
Known limits
- In the browser, you are always relayed — through our relay. A browser cannot open the kind of network connection a direct link needs, so browser participants always show
relay. That relay now runs on the Drawbridge site itself rather than on a public one, which is what lets the whole thing work through a firewall that only allowsdrawbridge.fortiknight.comon port 443. Your drawing is encrypted end to end between the participants, so what passes through is something the relay cannot read, and none of it is stored. The desktop app relays through the same place when it cannot connect directly — which is also what lets a browser and a desktop share a session at all, since the two have to meet on the same relay to find each other. - The browser needs a secure page. Collaboration only appears on
https://(orlocalhost). If you self-host Drawbridge and serve it over plainhttp://, the browser hides the sharing controls entirely — the encryption the invite handshake needs is not available to a page served that way. Serve your instance over HTTPS. - In the browser, your identity lasts as long as the tab. Reloading is fine and your invite keeps working, but closing the tab means a new identity — so a personal link shared from a browser stops working once that tab is gone. The desktop app remembers it properly.
- Two tabs of the same browser can collaborate, which is handy for trying it out — but they are two separate participants, so you will need to let the second one in.
- The host holds the session. Everything flows through the host; if the host's window closes, the session ends. Everyone keeps their own copy, and anyone can start a new session from it.
- Joining replaces your open diagram in that window (save first if you need it).
- One diagram per session. Sharing shares the document you have open.
- Sharing lasts only as long as the window is open — there is no persistent room to come back to, which is exactly why the personal link exists.
- Invite links are reusable until regenerated, so leaking one matters; use Regenerate, or Reset on the personal link, to cut access.
- Saved invites are stored in plain text in the app's local storage. Anyone with access to your user profile on the machine can read them.
- Undo is per person: you undo your own edits, not your collaborators'.