How remote control works
How a browser reaches a workbench through Mojo Up's relay, without opening a port, and what keeps it safe.
Remote control lets you use a workbench from somewhere else: the Cloud console in a browser, or your phone. The workbench might be behind a home router, a corporate firewall or mobile data. None of that matters, because the workbench never accepts a connection. It makes one.
The workbench dials out
When a workbench is approved, it receives a device token of its own. From then on, while it runs, it keeps one connection open to the platform's relay: an ordinary HTTPS request that stays open and carries a stream of events. It also sends a heartbeat, so the console can show whether it is reachable. A workbench that has not been heard from for a while shows as offline.
Because the connection goes out from the workbench, it works behind NAT and most proxies, and nobody has to open a port or set up a VPN.
A request, end to end
- You ask. In the console you allow a request, send a prompt or open a view. The console sends that to the platform, naming the workbench.
- The platform checks you. You must be signed in to the workbench's organisation, and be the person the workbench belongs to or one of the organisation's owners or admins. Otherwise the workbench does not exist as far as you are concerned.
- The platform signs and forwards it. The request goes down the workbench's open stream with the scopes the workbench was approved with, signed by the platform with its Ed25519 signing key.
- The workbench checks the platform. It verifies the signature against the platform's published keys, and serves the request only within the signed scopes. A request without a valid signature, or outside the scopes, is refused.
- The answer comes back the same way, and the console shows it. If the workbench does not answer within the time limit, you are told so.
The relay passes requests and answers through; it does not keep them. Everything travels over HTTPS.
Scopes: what a remote client may do
A workbench is approved with a set of scopes, and every remote request is limited to them.
| Scope | Allows |
|---|---|
agents:read, agents:write | Seeing agents and what they are doing; acting on them |
prompts:write, composer:write | Sending prompts |
permissions:write | Answering agents' requests for permission |
teams:write | Changing agent teams |
tasks:read, tasks:write | Seeing and changing tasks |
memory:write | Changing memory |
settings:write | Changing settings |
git:write | Git actions |
ui:view, ui:control | Seeing the screen, and controlling it |
Approval grants every scope except the two screen scopes. Screen mirroring and taking control are not offered on Mojo Up AI Cloud.
Keeping the workbench's access safe
- Tokens are stored hashed. The platform keeps a one-way hash of each device token, never the token.
- Tokens can be bound to the machine. A workbench can bind its access to a key that never leaves the machine (DPoP), so a copied token is useless anywhere else. The console notes this on the workbench's page: "its access works only with a key that stays on this machine".
- Access ends when it should. Revoking a workbench, signing it out, or its owner leaving the organisation ends its access straight away.
Your own network instead
If you would rather nothing went through Mojo Up, a team can run its own hub on its own network. See Keep it on your own network. Self-hosted AIOE can also carry remote control over its own WireGuard overlay.