Skip to main content

NetCurfew

A production-grade local screen-time and internet control system for parents.

NetCurfew runs a privileged background daemon that manipulates OS firewall rules. Access is granted by the parent via an interactive menu, CLI, or local web dashboard — from any device on the same network, including a smartphone.


Architecture

 Menu (netcurfew-menu.bat)   CLI (netcurfew)   Web UI (browser)
           |                       |                  |
           +----------+------------+------------------+
                      | HTTP REST  (localhost:5000)
                      v
           NetCurfew Daemon  (FastAPI / runs as admin)
                      |
                      v  OS firewall commands
           Windows netsh / Linux iptables / macOS pfctl

Default state: internet BLOCKED. Access must be explicitly granted.


Installation

# Requires Python 3.11+
pip install netcurfew

# Or install from source
pip install -e .

Check version and updates

netcurfew --version

Prints the installed version and checks PyPI for a newer release automatically.

Optional: set a parent PIN

netcurfew set-pin 123456

Once set, all internet access changes (start, stop, extend, allow) require the PIN.


Quick Start — Interactive Menu (Recommended)

The easiest way to operate NetCurfew is the included menu script. Double-click netcurfew-menu.bat or run it from a terminal:

netcurfew-menu.bat
+------------------------------------------+
|        NetCurfew - Internet Control       |
+------------------------------------------+
|                                          |
|   SERVICE                                |
|   [1] Start Daemon                       |
|   [2] Stop  Daemon                       |
|                                          |
|   INTERNET ACCESS                        |
|   [3] Show Status                        |
|   [4] Allow 15 Minutes                   |
|   [5] Allow 30 Minutes                   |
|   [6] Allow  1 Hour                      |
|   [7] Allow  2 Hours                     |
|   [8] Unlimited  (Work Mode)             |
|   [9] Block Internet Now                 |
|                                          |
|   SETTINGS                               |
|   [P] Set Parent PIN                     |
|   [0] Exit                               |
+------------------------------------------+

Option [1] starts the daemon in the background with --no-block-on-exit so closing the menu window does not cut internet. Option [2] finds and stops it.


Running the Daemon Manually

The daemon must run with elevated privileges.

Windows (Run as Administrator)

netcurfew serve

For work machines where you don't want Ctrl+C to block internet:

netcurfew serve --no-block-on-exit

To install as a Windows Service (using NSSM or sc.exe):

sc create NetCurfew binPath= "C:\Python311\Scripts\netcurfew.exe serve" start= auto
sc start NetCurfew

Linux (systemd)

Create /etc/systemd/system/netcurfew.service:

[Unit]
Description=NetCurfew Internet Control Daemon
After=network.target

[Service]
ExecStart=/usr/local/bin/netcurfew serve
Restart=always
RestartSec=5

[Install]
WantedBy=multi-user.target
sudo systemctl daemon-reload
sudo systemctl enable --now netcurfew

macOS (launchd)

sudo netcurfew serve

CLI Usage

# View current state
netcurfew status

# Check installed version and whether an update is available
netcurfew --version

# Grant internet access — defaults to the first allowed_durations entry (15m)
netcurfew start

# Grant a specific duration
netcurfew start 30m
netcurfew start 1h
netcurfew start 2h

# Allow internet indefinitely — no timer (Work Mode)
netcurfew allow

# Block internet immediately
netcurfew stop

# Add time to the current active session
netcurfew extend 15m

# Supply PIN via flag (skips interactive prompt)
netcurfew start 30m --pin 123456
netcurfew allow --pin 123456
netcurfew stop --pin 123456

# Skip PIN prompt entirely (useful in scripts or when no PIN is configured)
netcurfew start -i
netcurfew allow -i
netcurfew stop -i
netcurfew extend 30m -i

If no parent PIN is configured, the PIN prompt is skipped automatically. Use --immediately / -i to bypass the prompt when a PIN is set.


Web Dashboard

Open http://<machine-ip>:5000 in any browser on the local network.

Features:

  • Live status badge: 🟢 INTERNET ACTIVE (timed), 🟡 INTERNET UNLIMITED (work mode), 🔴 INTERNET BLOCKED
  • MM:SS / HH:MM:SS countdown for timed sessions; ∞ for unlimited
  • Quick-start buttons: +15m, +30m, +1h, +2h
  • ∞ Unlimited (Work Mode) button for uninterrupted access
  • Extend (+15m, +30m) and Stop Now buttons when a session is active
  • PIN modal appears automatically if a parent PIN is configured
  • Mobile-responsive, no internet required (fully self-contained — no CDN dependencies)

Configuration (config.json)

Key Default Description
parent_pin_hash null Scrypt-hashed PIN (set via netcurfew set-pin)
default_port 5000 Daemon listen port
allowed_durations [15,30,60,120] Allowed session lengths (minutes)
lan_only true Bind only to localhost/LAN

Security Notes

  • All firewall changes require the daemon to run as Administrator / root.
  • The daemon binds to 127.0.0.1 by default; LAN access requires binding to a local network interface (handled when lan_only: true).
  • Session timing uses time.monotonic() — immune to OS clock manipulation.
  • Fail-safe: the daemon blocks internet on startup and shutdown by default.
  • Use --no-block-on-exit only on trusted parent/admin machines.

Metadata

Release files for netcurfew 0.1.9

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for netcurfew 0.1.9
File Size Uploaded
netcurfew-0.1.9.tar.gz 21.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for netcurfew 0.1.9
File Interpreter ABI Platform
netcurfew-0.1.9-py3-none-any.whl Python 3 none any Details

Total release size: 40.6 kB

Release files / netcurfew-0.1.9.tar.gz

Download URL netcurfew-0.1.9.tar.gz
Size 21.6 kB
Tags Source
SHA-256 checksum
How to use checksums
2831bc62d7fb4a561f2153476c8ebf46308332a06edc474025438798b904d1f3
BLAKE2b-256 checksum
How to use checksums
2439dc88dfaede457c0f4cbe0616fef6e57d11ca32cdbd449436b629a9fc2f33
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 10, 2026.

Transparency log

Release files / netcurfew-0.1.9-py3-none-any.whl

Download URL netcurfew-0.1.9-py3-none-any.whl
Size 19.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5f5c07a26a6d26c71d55cbaf7c6dde2095292df0b67a4d4a9ad0bbcdc40b4a6f
BLAKE2b-256 checksum
How to use checksums
f0eadddffef55a9b7e70c3bd1dd1854bc63b7fe65d8e0fc50fe5cff317cf1e42
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 10, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.9 This release

2 release files

0.1.8

2 release files

0.1.7

2 release files

0.1.6

2 release files

0.1.5

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page