All docs

Security & access

Understand device grants, task permissions, credential exposure and revocation.

Ophio isn’t released yet. These docs describe the development version; app downloads are not available.

Network reachability is not authorization. Ophio checks pairing, TLS certificate pinning, device grants and desktop input leases separately. These controls do not isolate every program running as your computer’s user.

Task permissions

Skip permissions is on by default for new coding Work tasks. Native agent approval prompts are bypassed. Codex also bypasses its command sandbox. Use this only for trusted work and repositories.

Choose Ask for approval in Launch flags for native approval requests. Other policies have different edit and sandbox behavior. Ask and Plan remain read-only. See Agents & task permissions. Task instructions, completion checks and stop conditions are not enforced security boundaries.

Claude Work started from a device ignores project .claude settings, hooks, skills and agent definitions unless the owner enables them at the computer:

ophio projects settings <PROJECT-ID> on

Project CLAUDE.md still applies to Work. Read-only runs have separate instruction restrictions. Check Library’s Instructions report, but do not treat a discovered file as proof the agent read it.

Device grants

Under Settings → Connections and devices, a device with Manage access can review Devices with access. Grants separately control Watch desktop, Control input, Terminals, Agent tasks, Agent approvals, AI computer use, Read Library, Edit Library, File transfers, Manage access and Accounts.

Input requires desktop viewing. Editing Library requires reading it. Account access can only be granted at the computer; a phone may remove it. Lost management access must be restored by the computer or another authorized device.

A terminal belongs to the device that opened it. Other devices cannot list, read or attach to it. Revocation ends that device’s shells. Commands entered in a terminal run as the computer’s user and are not restricted by coding-task launch flags.

Revoke a lost device

From an owner terminal on the computer:

ophio devices --help
ophio devices revoke --help

Use the listed device identifier. If you cannot establish who has access, stop Ophio on the computer. Deleting the phone app or forgetting a saved computer does not revoke pairing. Revocation does not erase downloaded files from the phone.

Never share pairing offers, device keys, certificates’ private keys or account tokens. Verify an unexpected certificate change before pairing again.

Phone app lock

Under Settings → Lock, Lock the app uses the phone’s biometrics or secure screen lock where available. Lock again offers On leaving the app, After 1 minute away, After 5 minutes away or After 15 minutes away. Lock now locks immediately.

Unlocking never approves a request or grants computer control. App lock does not revoke pairing or protect copies already exported from the app.

Credentials and website actions

Accounts gives every active service credential to every newly started task on that computer. There is no per-project account restriction. Pausing an account does not remove credentials already received by a running task.

Agent logins is a separate, initially disabled website-login store. A logged-in agent may send, post, buy or delete as you. A login-use approval is not approval for each subsequent website action. Keep banking and payment accounts out of it.

Known exact secrets are masked where supported. Encoded values, images, scripts and unrelated software can still expose them. Use owner-side provider revocation if a credential may have escaped.

Owner controls and stop limits

The local owner-control channel is restricted to the computer’s OS user. Agent descendants and device-terminal processes may run ordinary checks and permitted setup commands, but Ophio refuses person-only operations from them: pairing or changing grants, answering approvals, starting or instructing tasks, authorizing the queue, granting credentials or project settings, changing GitHub mode or merging, unlocking the desktop, deleting a one-off, revealing secrets and quitting Ophio.

This guard uses process ancestry and available containment. It is not complete OS-user isolation. A same-user program can use detached processes, startup files or external services outside that containment. Do not treat a refused CLI operation as a sandbox around an untrusted agent.

A stop request is not a confirmed stop. Check the Stop receipt and Still running / unknown. Written files remain. Externally delegated jobs may continue. Force stop is only offered for processes Ophio can identify as its own. See stopping tasks.

A private desktop step reports which observation routes were paused. It cannot cover unrelated software. Earlier screenshots stay in conversations. Remove sensitive information and inspect the current picture before returning control.

Where data goes

The phone connects directly to the computer without an Ophio relay. Agents use their native providers. Voice control uses Jev access and TypeSafe’s data policy; agent selection does not use Jev. Telegram, Discord and GitHub receive information when their configured workflows post it.

Uploads, captures and task evidence can remain on the computer. Clearing a phone record does not delete a delivered file. Backups, journals and migration snapshots can contain secrets. Protect them like the originals. Restoring an old backup can restore old access grants; review them before reconnecting.

Report a vulnerability

Report privately, never in a public issue. GitHub private vulnerability reporting is the approved support direction, but its public repository and exact URL remain gated. Use only the contact actually published on the security page. Do not infer one from commit authors.

Include version, platform, expected and observed behavior, and a minimal example with sample data. Remove secrets, screenshots and personal paths. No response deadline is promised.