📡 beacon.primals.eco

Commensal Relay — free sovereign RustDesk relay for good-faith humans

What this is: A free RustDesk relay server. Your traffic is end-to-end encrypted — the relay sees only ciphertext. No analytics, no tracking, no cookies. Use it in peace.

📥 Get RustDesk

Download the official open-source client. Then point it at this relay.

RustDesk is open source (AGPL-3.0). We run the relay. You run the client. Neither side has to trust the other — E2E encryption handles that.

⚡ Quick Setup (2 steps)

  1. Open RustDesk → Settings → Network → set ID/Relay Server to relay.primals.eco
  2. Set a permanent password on your machine (Settings → Security)

That is it. You are connected. No key needed, no account needed.

🔑 Server Key (anti-MITM)

This key verifies you are talking to this relay, not an impersonator. Paste it into Settings → Network → Key.

utlNOAWUDdV+Q+ifG3zHrQ5HU0FtQnOTHiAnu6prV7Q=

If your client shows “key mismatch” — clear the old key, paste this one, and restart RustDesk.

📋 Pre-Configured Config

Download the config file and place it at the path for your OS. This sets the relay address and the server key in one step.

⬇ Download RustDesk2.toml
Config paths by OS:
Linux → ~/.config/rustdesk/RustDesk2.toml
macOS → ~/Library/Preferences/RustDesk/RustDesk2.toml
Windows → %APPDATA%\RustDesk\config\RustDesk2.toml
Or from the terminal:
curl -sO https://beacon.primals.eco/RustDesk2.toml

🔧 Key Mismatch Fix

If a gate shows “Authentication failed - invalid key” in the relay logs:

  1. Stop RustDesk on the gate: sudo systemctl stop rustdesk
  2. Download the correct config: curl -sO https://beacon.primals.eco/RustDesk2.toml
  3. Copy to config dir: cp RustDesk2.toml ~/.config/rustdesk/
  4. Delete stale key state: rm -f ~/.config/rustdesk/RustDesk.toml
  5. Restart: sudo systemctl start rustdesk

The old RustDesk.toml caches a key_confirmed flag. If the server key changed or was never set correctly, this cache prevents re-verification. Deleting it forces a fresh key exchange.

🛡 Privacy Model

Tier 1Beacon — you are here. Open relay, E2E encrypted, no registration.
Tier 2Family — seed-gated access to sovereign mesh services.
Tier 3Sovereign — lineage-verified access to the inner membrane.

Each tier is nested inside the previous one. The relay does not know which tier you belong to. Trust is earned, not granted.

🔒 Trust Model

  1. Your password — only you can accept incoming connections to your machine
  2. End-to-end encryption — the relay cannot inspect your sessions
  3. Rate limits — NAT-aware firewall protects the relay from abuse
  4. Zero knowledge — the relay cannot map your ID to anyone else’s