Skip to content

Add @openagt/remote-access: a phone gets in with a QR code - #2054

Merged
suleimansh merged 1 commit into
mainfrom
remote-access
Oct 10, 2026
Merged

suleimansh merged 1 commit into
mainfrom
remote-access

Conversation

@suleimansh

Copy link
Copy Markdown
Member

The second step of the self-hosting plan (#1824): the door on the laptop.

👤

  • I open OpenAgent on my phone by scanning a QR code once. No password, no account.
  • Each device has its own key. I see the devices that are in, and I remove one alone.
  • One switch, "Phone on Wi-Fi", opens this on the Wi-Fi my laptop is on. It is off until I turn it on.
  • The link on the Wi-Fi is plain HTTP. Turning the switch on says so first. A real lock comes later.
  • The code holds my laptop's name on the network when it has one. The phone then stays in when the network gives the laptop another number. A link under the code switches to the number.
  • All of this is a new package, @openagt/remote-access. OpenAgent itself listens on its own computer only.

🤖 automated · Opus 5.5, effort high

The name is a working name

  • @openagt/remote-access waits for the names of the three pieces (Self-hosting #1824).
  • It is not published. A rename is one find-and-replace.

What a person sees

  • Settings has a "Devices" section: the switch, "Add device", and the list of devices with "Remove".
  • "Add device" shows a QR code. It works once, for five minutes.
  • A phone that opens the address without a code gets a page that says how to get in.
  • A removed device is out at its next request. Its open live feed is cut.

How

  • The door is a process of its own. It listens on the port after OpenAgent's (4201).
  • A request of a device that is in is passed to OpenAgent on the laptop, as the laptop's own browser would make it.
  • Only an address on one of the laptop's own networks may knock.
  • The devices are in a file in the home folder, readable by its owner only. It holds the SHA-256 of a key or a code, never the key or the code.
  • The core gained one rule. A package it brings may declare a service: a command OpenAgent runs for as long as it runs itself ("openagent": { "service": "<command>" }).
  • The Devices section runs the package's own command: remote-access status, on, off, add, remove.

Picks of mine

  • The door's port is OpenAgent's plus one, so the address is the same at every start.
  • A devices file someone broke by hand is never written over. Nobody gets in until it is corrected.
  • One new dev dependency, uqr, pinned. It draws the QR code in the browser. MIT, no dependencies of its own.

Temporary

  • A package's Settings section and its command are per project today. Devices are per computer. So the section runs the command in the first project that answers, and it does not show while no project is registered.

DECISIONS.md

  • The new package's file has seven lines. Each is a pick listed above or made in the plan on Self-hosting #1824.
  • The core's file has one new line: a package may bring a service.

Known limits

  • The dashboard is not made for a phone screen yet. At phone width the sidebar takes most of it. That is a step of its own.
  • The live browser view in the chat does not show on a phone. It is loaded from the laptop's own address.
  • The phone's key rides a cookie, and a cookie goes to every port of the laptop's address. A dev server on the laptop that the phone opens receives it.
  • The QR code was not tried with a real phone's camera. A second browser opened the code's link.

Not in this step

  • The --host flag and the shared key stay. Two machines still talk through them. Step 3 removes them.
  • An OpenAgent started with --host does not open the door, and the section says so.
  • "Watch only" comes with step 5.

Checks

  • Root build, typecheck and tests are green. 58 tests are new.
  • A real try on test ports with two real browsers, one as the laptop and one as the phone.
  • One fresh reviewer. No way in found. 11 robustness findings, all fixed, each with a test.

The door on the laptop, the second step of the self-hosting plan (#1824).
A device gets in by scanning a QR code once, has its own key and is removed
alone. One switch, Phone on Wi-Fi, opens the door on the network the
computer is on, over plain HTTP, after a warning. OpenAgent itself still
listens on its own computer only: a package it brings may now declare a
service, a command OpenAgent runs for as long as it runs itself.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@suleimansh
suleimansh merged commit 0f8cdb0 into main Oct 10, 2026
6 checks passed
@suleimansh
suleimansh deleted the remote-access branch October 10, 2026 23:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant