Can ConfigWatch change my device configuration?
No. It runs only the commands that display configuration, and that list is fixed in code with tests that fail if a write command is ever added. Rollback commands are generated as text on screen for you to review and run yourself — ConfigWatch never sends them. Use a read-only account regardless; that is the correct level of access for a tool whose entire job is reading.
What happens to passwords inside the configuration?
They are masked before anything is written to disk. ConfigWatch knows the shapes each vendor uses — enable secret, SNMP communities, pre-shared keys, wireless passphrases, API tokens — and replaces the value while leaving the surrounding line intact so diffs still make sense. If a line looks like it holds a secret that was not fully masked, the whole configuration is rejected rather than stored, and the reason is shown.
How is this different from RANCID or Oxidized?
Mostly in who it is for. Those are excellent, free, and run on Linux from the command line with a configuration file and a cron job — if that is already your environment, use them. ConfigWatch is for the person who administers a network but does not run a Linux server to babysit it: you add a device in a window, the diffs are readable, and the rollback commands are written for you. The trade is convenience for a licence fee, and the honest answer is that the free tools do the core job well.
How does it know which vendor a device is?
From what the device says about itself when you connect, matched against known banner patterns. If the evidence points to two vendors at once, ConfigWatch stops and asks rather than picking the higher score — a wrong guess means running the wrong command, which produces a backup that looks fine and contains nothing useful. You can also set the vendor yourself when adding a device.
My switch is old and SSH fails. Now what?
ConfigWatch tries current SSH algorithms first, and if the key exchange itself fails it retries automatically with the legacy algorithms that older firmware needs. That retry only happens on a negotiation failure — an authentication failure is never retried, because repeated attempts are how accounts get locked out. If both attempts fail, the error tells you which stage failed.
How often does it back up?
On Free, whenever you press the button. Pro adds a schedule that runs in the background and skips a run if the previous one is still going, so a slow device cannot cause overlapping sessions. Devices are collected a few at a time rather than all at once — a hundred simultaneous SSH sessions is a good way to get noticed by whoever runs the network.
Does it store a copy every time it checks?
No. If the configuration is identical to the last stored version, ConfigWatch updates the “last checked” time and stores nothing new. History is a list of changes, not a list of runs — a device that never changes uses almost no disk.
Up to 100 versions are kept per device, oldest pruned first. Whatever happens, the most recent version is never deleted: a backup tool that prunes its way down to no backup at all would be the worst bug it could have, so that case is written into the code and pinned by a test.
Where are my credentials kept?
In an encrypted file in your home directory, sealed with the operating system's keychain — the macOS Keychain, or DPAPI on Windows. They can be entered but never read back out: the application window has no way to retrieve a stored password, because it has no need to. If you use an SSH key, ConfigWatch stores the path to the key file, not the key.
Does anything leave my computer?
Only the SSH connections to the devices you added. Configurations, history and diffs are written to a folder in your home directory and go nowhere else. There is no telemetry and no licensing callback — the licence key is verified locally against a public key built into the app, so activation works on an air-gapped network.
How does Pro activation work?
After checkout you receive a licence key by email. It is sent from license@meshwatch.app, usually within a minute — if it is not in your inbox, check your Junk or Spam folder before writing to support. Paste it into the License box in the app and press Activate. The key carries its own expiry date and is checked on your own computer, so it works offline. When you renew, a fresh key is emailed to you.
Does it work with MeshWatch Central?
Optionally. Connect ConfigWatch to your own MeshWatch Central server and its alerts join whatever CertWatch, DeviceWatch, TrafficWatch, SyslogWatch and TrapWatch are reporting into one shared inbox — a config change on the same switch where an interface just dropped shows up as one incident, not two. ConfigWatch sends Central a one-line summary like “3 lines changed on GigabitEthernet0/3” — never the configuration itself, never a secret. Central is a separate product you run on your own server; ConfigWatch works exactly the same with or without it.