Per-Client Revocable Identities
Each AI client can be issued an individual revocable key with its own capability profile (by default a shared launch token is used, which is not revocable in v1). Revocation takes effect on the next request.
These capabilities run in the current macOS build, providing multi-AI coordination and governed access.
Each AI client can be issued an individual revocable key with its own capability profile (by default a shared launch token is used, which is not revocable in v1). Revocation takes effect on the next request.
Mutating operations require a durable idempotency key. Prevents duplicate side effects, replays recorded results, and safely handles UNCERTAIN states without blind retries.
An in-memory lock for calls that pass through Mercury (screenshots, opening apps, AppleScript). A second client waits up to 3 seconds and is then refused; the first client keeps the lock for 10 seconds after its last call.
Operations write a row to the local audit.jsonl log with client, tool, allowed/denied status, duration, and result timestamp; request payloads are not stored.
Direct native automation on macOS host drivers, Android actions over adb, and connected iOS / iPadOS device list discovery.
Commands run as an explicit argument list without a shell; access is governed by the client profile.
Practical automation workflows running through the local daemon and MCP bridge.
Ask an AI assistant to read a project folder, summarise it and write the result to a file. Give a review-only assistant a read-only token.
Let an assistant run a program or script on your Mac with explicit arguments and read its output.
Take a screenshot, open an app or run an AppleScript. If two assistants try at once, the second waits or is refused.
List connected Android devices and send taps, swipes, text and key events with adb. iPhone and iPad are listed only.
Each call is written to a local operations log with the client, tool, result and time. Request contents are not stored.
Every action runs without a confirmation prompt, according to the profile you assign.
Tested with ChatGPT and Claude. Works with MCP clients; a sample configuration is available for Gemini.
Cloud sessions connect via user-configured tunnel to the local Mac daemon.
Local engineer CLI or desktop interface connected via standard stdio MCP bridge with designated clientId token.
A sample configuration is available for Gemini.