devpit

Remote

This machine's terminals, board and waiting questions, from your phone or another computer, over Tailscale.

Remote lets you reach this machine from your phone or another computer: watch its terminals, and type into them when you allow it; move the board's cards; answer an agent's question; read the chats. It travels over your own Tailscale tailnet, and nothing listens beyond the machine and that tailnet.

It is off until you turn it on, in Settings → General → Remote, under Other devices.

Getting in

  1. Install Tailscale on this machine and on the phone or computer, and sign in on both as the owner of this machine in the tailnet. Anyone else in the tailnet is refused.
  2. Turn Remote on. Settings shows the address to open.
  3. Open that address on the other device.
  4. Press Pair a device on this machine. It shows a code and a QR: scan it, or type the code on the other device. The code is good once, for two minutes.
  5. Choose what that device may do.

Two things are needed to get in, every time: being the machine's owner in the tailnet, and a device paired here with a code read off this machine's screen. If Tailscale is missing or logged out, Settings says which.

How it is reached

devpit serves its own viewer, never on every interface.

Tailnet How the viewer is reached
HTTPS certificates on devpit listens on this machine only, and tailscale serve publishes it to the tailnet at an https address
No HTTPS devpit listens on the machine's tailnet address alone, over the tailnet's own encryption

Settings suggests turning on HTTPS certificates in the tailnet's admin for an https address. If Tailscale refuses to publish it, the message says what to run once: sudo tailscale set --operator=$USER.

What each device may do

Set on this machine, per device, and only here:

Permission What it allows
watch Always. See the terminals, the board, what is waiting and the chats.
type Send keys to terminals, and move cards.
answer Allow or deny a question an agent is waiting on.

A new device starts with watch alone. A device that only watches is attached to a terminal read-only by tmux itself, not by the page, and a phone never shrinks the terminal on the desk. Changing a device's permissions drops its connections, so it comes back with the new ones. Forget unpairs it.

What the other device sees

  • Terminals of a project, up to four at a time. With type: Esc, Tab, Ctrl+C, the arrows and Enter, and a field that sends a line.
  • The board, with its lanes and cards. With type, a card moves only into a lane that runs no step — moving into one that does starts work, and that stays yours, at the desk.
  • Waiting: each question an agent is waiting on, with Allow and Deny, and a confirmation before either.
  • Chats, to read. They are not written from there.

That is the whole list. It does not reach files, Settings, the browser pane or starting an agent, and orchestrators are not listed.

While a device is connected

The status strip says Watched by 1 device. A click drops every connected device, without unpairing them.

A log keeps who connected and what they did — paired, connected, watching a terminal, sent a line, moved a card, allowed or denied a tool — and never what was on screen. It is ~/.devpit/remote-log.jsonl.

Limits

  • At most 16 paired devices. Forget one to pair another.
  • A terminal question reaches the other device through the island, so with the island off, or devpit in front, or a pause on, it is asked in the terminal instead.
  • With the Windows installer, terminals cannot be watched remotely: psmux has no grouped sessions, which a remote viewer needs.

Remote shows the screen of an agent you are not sitting in front of. Pair only devices you hold, and allow type and answer only where you would type and answer yourself.