Remote access
Remote access: one access token, one device per browser
Everything Sessionboxer serves is behind a login. How the access token, the pairing link and the device list work, and how to revoke a browser or rotate the token.
Everything the Control Plane serves — the UI, the API, terminals, the desktop, VS Code — is behind a login, whether you reach it on 127.0.0.1 or through a tunnel. There is one access token per Control Plane, generated at first start into ~/.sessionboxer/config.json (SESSIONBOXER_ACCESS_TOKEN in the environment overrides it; sessionboxer token prints it). A browser logs in with it once, on the login screen, and gets its own device: an HttpOnly cookie that lasts a year, until you revoke it. npm start prints a one-time pairing link (http://127.0.0.1:4000/#pair=…, valid 5 minutes) so the first browser never sees the token.
Global settings → Devices and remote access lists the browsers that are logged in (name, last seen, from where), with Revoke per device and Log out for the current one. Pair another device shows a QR code and a link, good once for 5 minutes: scan it with the phone (or open the link on the other machine) and that browser is logged in as its own device — the token itself never leaves the browser you are on. Show access token reveals it on demand, and Rotate token makes a new one, logging out every other device and every CLI that used the old token (not available when the token comes from the environment). Wrong tokens and codes are rate-limited per address; cookies are SameSite=Lax and requests from another origin are refused.
This chapter is generated from docs/GUIDE.md in the Sessionboxer repository. Found a mistake? Open an issue.