Pairing a phone

A phone pairs with a short code that you open from the panel or a terminal. What the code is, how long it lives, when it burns, and what the phone keeps afterwards.

Open a code #

With remote access on, the Remote access section of the panel shows the public address as text and as a QR code. Press the QR code to open it in an editor tab, large enough to scan, or press Copy the URL. Then press Pair a device. The section shows Pairing code XXXX-XXXX · expires <time>, and Copy the code puts the code on the clipboard. Pressing it again replaces the code, and the label becomes New pairing code, because only one code is ever open.

A terminal can open one too, on the machine that runs the server:

powershell
autodev serve pair

It prints Pairing code: XXXX-XXXX (expires <time>) and the public address on the next line. When remote access is not running it says so and exits with an error.

The code is 8 characters, written as two groups of four. The letters I, L, O and U are left out, because they are hard to tell from other characters on a phone keyboard. On the phone, the letter case does not matter, and the dash and spaces are ignored.

Open the public address on the phone. The page says Enter the pairing code shown in the panel. Type the code and press Pair. The QR code carries the address only, never the code.

What the code allows #

RuleWhat the server does
LifetimeThe code expires after 10 minutes.
UseIt works once. A successful pairing closes it.
Wrong guesses5 wrong attempts close it. After the fifth, even the right code finds no pairing open.
At a timeOne code is open at a time. A new one replaces it.
With none openEvery attempt is answered no_pairing_open. There is nothing to guess.

A phone that is not paired sees a page with the AutoDev name, the request for a code, and the reason a pairing failed: wrong_code, no_pairing_open or missing_code. It shows no project name, no status and no counts.

A code is opened from the machine, and only there: from the panel or from autodev serve pair. The route that opens and reads it accepts the server's token and nothing else, so a paired phone cannot open a code for another device.

A successful pairing sets a cookie named autodev_device. It holds a random 192-bit token, and it is marked HttpOnly, Secure and SameSite=Lax, with a maximum age of about 400 days, the longest a browser keeps a cookie. The server remembers the token in memory, and the phone presents it on every request.

SameSite=Lax is what lets a link opened from a chat or a note arrive already paired, where Strict would have shown the pairing page. Every route that changes something is a POST, and a Lax cookie is not sent on a cross-site POST.

The cookie does not decide how long a phone stays paired. The address and the server process do: the phone stays paired for as long as the same server runs on the same address, and a server that runs for days does not ask the phone to pair again. Nothing about pairing is written to disk. The hostname of a quick tunnel is different on every run, and a cookie belongs to one hostname, so a phone paired last night cannot present its cookie to tonight's address.

Disconnecting #

The phone's menu has Disconnect this device. It revokes that phone only and clears its cookie, and every other paired device stays paired. The panel shows how many devices are paired.

Nothing in the panel revokes one device, or all of them, short of turning remote access off. The limits of the tunnel says what that means for a phone you have lost.

What you can do from the phone covers what a paired phone shows and sends. Turning remote access on covers the server the code belongs to.