All docs

Desktop control

Watch or control the desktop, review computer-use tasks and open project previews.

Ophio isn’t released yet. These docs describe the development version; app downloads are not available.

Desktop sharing is off until you enable it from the computer’s graphical session:

ophio desktop enable
ophio doctor

The desktop may ask for screen-sharing and remote-input consent. Linux also needs a desktop notification service that supports input-approval actions. Device grants remain separate from this consent.

Watch and take control

Open Control → Screens and choose a reported display, window or browser target. Open its picture to view it. Viewing is read-only. Take over requests its input lease. One controller holds the lease at a time. Wait for confirmed ownership before typing.

Full-screen controls

The picture fills the screen when you have control or turn the phone to landscape. Landscape viewing alone does not grant input. Floating controls provide Keys, Jev when available, Touchpad or Direct, Right, Drag, zoom, Fit, Tilt and Hide. Show controls brings hidden controls back.

  • Touchpad moves the computer pointer relative to your finger; Direct targets the place you touch in the picture.
  • Pinch to zoom. Two fingers moving together scroll the computer when input is allowed; a two-finger tap right-clicks.
  • Use Right for a right-click and Drag when you need to drag with a held pointer button.
  • Fit restores the whole picture. Tilt pans a zoomed picture using the phone’s motion, where available; it does not move the computer pointer.

The current computer-use task keeps its own Stop control. Other running tasks remain reachable from the activity controls.

Use Keyboard to type. If typing is refused and Paste instead is offered, it replaces the computer’s clipboard and sends Ctrl+V to the focused app. Check focus first. Discard saved text removes the retained typing draft.

Leave control stops input from this device. Check the result if release is unconfirmed. It does not stop a coding task. The ordinary display view’s More menu offers Lock desktop, which separately requests the computer’s lock screen; it is not a button in the full-screen overlay.

Stale pictures, changed geometry and expired leases block input. Ophio does not guess new coordinates. A person at the computer can still move the pointer and type. Input goes to the focused app, not necessarily the window you intended.

Computer-use tasks

In Control → Screens, choose Start computer use. Review Target, Agent, Model and account, and Goal. Only eligible agents and available targets can start. Pictures go to the selected agent’s computer specialist. Earlier pictures remain in the conversation.

The specialist’s controls cannot run shell commands or write files directly. It acts through the target’s interface. This is separate from ordinary coding Work and from a coding task’s Browser option for agent website logins.

Open a running computer-use task to check ownership and Pictures for the agent. Take over pauses agent input and opens your controls. Before Return to agent, remove sensitive information and review the current picture. The agent must observe the target again. Keep input paused leaves it paused.

Private human steps

In the computer-use view, Start private step requests a pause of agent input, screenshots and the native agent session. Check Private step ready and any uncovered routes. If privacy is unconfirmed, do not type secrets.

Earlier pictures remain in the conversation. The pause cannot cover unrelated software on the computer. Enter passwords yourself rather than in task chat.

End private step leaves the agent paused. Remove sensitive information and review the picture before Resume computer use. Ending the private step alone does not resume it.

Apps and windows

Control → Screens → Apps and windows lists supported windows and installed apps. Use Find an app or window and Refresh list. Focus window changes focus; Close window… opens a confirmation and can lose unsaved application work. Open app launches the selected installed app.

Availability depends on the desktop and input permission. A stale window entry is not permission to act on a replacement window. Read the computer’s reported result.

Project previews

Open Control → Previews. A localhost URL means the computer’s localhost, reached through the private paired connection, not the phone’s localhost. Other URLs open in the phone’s browser; computer reachability does not prove phone reachability.

Use Open for a preview and Check again if its server is unreachable. A private preview opens edge-to-edge, with a close X, its title, a camera button and Annotate. Pinch to zoom. Closing the view does not stop its server. Taking a picture saves a local capture for feedback. Review the selected task before attaching or annotating it; capturing a picture does not send a task message.

To register a preview manually, open Settings → Connections and devices → Previews → Add preview. Choose Project, enter Preview label and Preview URL, then Register preview. Registration requires management permission. Removing an entry leaves its server running.

Automatic discovery on Linux

On Linux only, local HTML servers started in registered project folders can appear automatically. The deepest matching nested project owns the entry. API servers, debugger ports, databases, non-HTML responses and unreachable listeners are omitted. Titles are checked for known secrets, but still review what you share.

A discovered server that stops is hidden immediately and its entry is removed after 30 seconds unless it returns. Removing a found entry suppresses that running server until it restarts.

Manually registered and agent-shared loopback previews also follow their listening port: after a previously seen server stops, its entry is removed after 30 seconds. A server never seen listening since registration or companion startup gets ten minutes. External URLs are not removed by this check. Different loopback addresses using the same port remain distinct previews.

A changed-file notice does not prove the preview loaded new code. A server without automatic reload may still show the old version. Restart that server on the computer and reopen the preview.

System readings

Control → Screens → System shows available CPU and per-core activity, memory, swap, network, graphics, disks, temperature, battery, uptime and processes. It needs desktop-view permission. Polling and bounded history run while the view is visible. Slow disk queries can be omitted.

Process listings show short names, not full command lines. Readings may be unavailable or old. They are not evidence that an agent completed or stopped.

Unlock a locked computer

On Linux, you can unlock a locked computer from the phone with the computer account’s password. This needs both Control and Manage on the paired device, because the password opens the whole computer. A device with Control only is told why it cannot unlock instead of seeing the button.

When the computer reports that its screen is locked, a notice saying the computer is locked appears at the top of Control and on each display’s screen. Displays take no input until the computer is unlocked.

  1. Tap Unlock with password.
  2. Enter the computer’s password. It is checked against the account’s password, sent once and not kept on the phone.
  3. Tap Unlock, or Cancel to leave it locked.

The computer checks the password and releases its lock screen. Ophio reports the unlock as done only when the computer confirms that its screen is unlocked within five seconds. If it does not confirm, the app says the password was right but the unlock was not confirmed. Check the computer’s screen.

One unlock is checked at a time. If the connection drops during a check, the app asks the computer how it ended once it reconnects and does not send the password again.

Wrong passwords

After two tries that do not unlock the computer, Ophio stops accepting passwords for 15 minutes and asks you to unlock at the computer. Tries from Ophio never count toward the computer’s own lockout and never clear it. If the computer has already locked the account after wrong passwords, unlock it at the computer.

A second factor that the computer’s own login asks for, such as a code or a security key, is not asked for here. The device’s Control and Manage access stands in for it. Agents cannot unlock the computer.

When unlocking is not offered

Unlocking from the phone is not available:

  • on Windows;
  • when the computer’s PAM library is missing or older than Linux-PAM 1.4;
  • when Ophio has no login session or Wayland display to unlock, or runs as a service with NoNewPrivileges=yes;
  • for accounts that are not in /etc/passwd, such as LDAP, SSSD or systemd-homed accounts;
  • when the computer’s PAM configuration gives pam_faillock its own settings instead of using /etc/security/faillock.conf, or uses pam_tally or pam_tally2.

GNOME and KDE lock screens, hyprlock and swaylock can be released. Other lock screens are not released even by the right password, and the app reports that the unlock was not confirmed.

Limits and recovery

Linux capture uses the desktop portal and PipeWire. On GNOME 46, a display-scaling change can end capture. Reopen sharing starts a new stream and may require consent again. A revoked sharing permission must be enabled again at the computer.

Wayland needs suitable capture and virtual-input protocols. X11 is not qualified. Elevated or secure prompts cannot be controlled. Lock screens cannot be controlled by input; see Unlock a locked computer. Windows is not physically qualified for the initial release. See Platform qualification.

With Jev configured, spoken or typed commands can control a focused app or a private browser target. See Voice control.

Turn sharing off

ophio desktop disable

On Linux this also forgets saved portal consent. Enabling sharing again asks for consent again.