BrainwriteDocs
Mobile

iOS companion

Pair an iPhone directly with the Brainwrite instance running on your computer.

The iPhone app is a window onto the Brainwrite running on your Mac. Your Mac remains the only machine that runs your bots and keeps their credentials, chats and computers.

The Brainwrite iPhone app is coming soon to the App Store.

What it can do

  • Discover and pair on the same LAN, connect through Tailscale, or use an optional account-provisioned HTTPS address
  • List bots and rooms, read paged transcripts, send messages, and interrupt work
  • Answer approvals and questions, including narrow always-allow grants
  • Search, manage tasks, react, share, and navigate message versions
  • Follow resumable live updates and optionally view a bot's managed Boat cloud computer. The loopback-only VPS SSH viewer currently opens in the desktop app.

Pairing

The desktop opens a two-minute pairing window with a high-entropy QR credential and a six-digit manual fallback. Redeeming either closes the window and returns a separate per-device token stored in iOS Keychain.

The computer stores only a digest of the device token. Revoking the phone from desktop Settings invalidates future requests.

Network options

  • Same trusted Wi-Fi: Bonjour discovery and direct HTTP.
  • Away from home: Tailscale on both devices with the computer's MagicDNS name.
  • Hosted HTTPS: sign in by email on the desktop to provision a private Cloudflare Tunnel address; the phone still pairs to that specific computer.

For hosted HTTPS, Brainwrite's account service stores only which account and computer the address belongs to, never your chats; Cloudflare passes the phone's traffic through to your Mac. Bonjour does not cross Tailscale, so that direct remote option uses manual address entry.

Your computer must remain on, awake, and running Brainwrite. In Settings → Remote access, Keep this computer awake can prevent sleep while Remote access is on; it is off by default, allows the screen to turn off, and may use more battery. A sleeping or powered-off computer cannot be reached even through hosted HTTPS.

Security boundary

The companion sidecar uses a default-deny route allowlist. Provider keys, pairing administration, Local VM lifecycle, webhook secrets, team import/export, and internal peer-agent routes remain unreachable from the phone.

Foreground-oriented connection

Live and replayed events can produce alerts while the companion is connected, but a terminated iOS app cannot be awakened without a future APNs relay.

On this page