Remote access
Sessionboxer on the phone: one pane at a time, push notifications
Below 800 px the UI becomes a phone layout with tabs, a keyboard bar for the desktop and an installable app. Web Push tells you when a turn ends or a PR gets feedback.
Below 800 px wide the same UI becomes a phone layout: the session list is a drawer behind the ☰ button, the session shows one pane at a time picked from tabs along the bottom — Chat, Desktop, Code, plus PRs (with its unread count), Verify and Scheduled when the session has any — and the header's other entries (Terminal, Context, Snapshot, Fork, Pull, Session settings, branch, Stop/Delete) sit in a sheet behind ⋯. The composer follows the on-screen keyboard (the app resizes to the visual viewport instead of scrolling away) and respects the notch and home indicator. The Desktop pane's Keyboard button opens a bar that brings up the phone's keyboard and adds the keys it lacks — Ctrl, Alt, Shift, Super as sticky modifiers, Esc, Tab, Enter, Backspace and the arrows — everything is sent as key events to the box, so Ctrl+c or Alt+Tab work; noVNC's touch gestures (tap, two-finger scroll, long-press for right click, pinch) are unchanged. The app is installable: Add to Home Screen on iPhone, Install app on Android, and it opens full-screen without browser chrome.
Notifications while the phone sleeps. In Global settings → Devices and remote access, Notify this device when a turn ends or a pull request gets feedback subscribes that browser to Web Push (needs HTTPS — the tunnel or your own address — and on iPhone the app added to the Home Screen first, iOS 16.4+). The Control Plane generates its VAPID key pair into config.json on first start, encrypts every message per RFC 8291 itself (no third-party service beyond the browser vendor's push relay, which only sees ciphertext) and sends one when an agent's turn ends (with the first line of its last message) or a pull request gets new comments or reviews — to every subscribed device except those with the page on screen, which see it happen live. Tapping the notification opens the session, the PR overview or the single PR. Send a test notification checks the path end to end. Subscriptions belong to the device: revoking a device or logging out drops its subscription, a push service answering 404/410 does too, and the endpoint and keys are never shown in the UI or the API.
This chapter is generated from docs/GUIDE.md in the Sessionboxer repository. Found a mistake? Open an issue.