Session Access and Security
An RPC-enabled session is open in two respects — to other clients on the same machine, and to other machines on the network. Both call for some care in how the session is run.
One Session, One Driver
Only one Cubit session on a machine can have RPC enabled. A second session started with -rpc reports an error and runs without an RPC server; commands sent with cubitc continue to reach the first.
Drive an RPC-enabled Cubit from a single LLM agent session. The current implementation carries no client identity or session lock, so any client that connects to port 50505 can operate on the same model with the same undo stack.
Network Exposure
On a shared or untrusted network, Coreform recommends running RPC-enabled sessions only behind a host firewall that blocks inbound connections to port 50505. The RPC server listens on all network interfaces and does not authenticate clients, so any machine that can reach the host can drive the session.