Skip to content
Documentation / Operate

Security & remote access

Owner authority, browser pairing and protected HTTPS access.

Understand host authority

MSO runs with its runtime user’s operating-system authority. Install as a normal user. Viewer, Operator and Owner device roles bound what sessions can request; Owner actions can change the host.

The public website and sample demo have no connection to your private host. Use your own instance URL to sign in.

Pair a new browser

Sign in with your owner password. A new browser remains pending until approved. Run the commands below from the owning host terminal or use Settings → Account → Devices in an approved browser.

Replace <deviceId> with the exact ID shown by the browser, then check again. Device identity is scoped to the origin: changing the hostname creates a different browser device.

Pair a new browser
mso device pending
mso device approve <deviceId> "my laptop"

Choose a protected transport

The default listener is 127.0.0.1:4005. Local access uses localhost. Remote access needs protected HTTPS because session cookies are Secure.

Use Tailscale Serve, a reviewed HTTPS reverse proxy or a named tunnel. Keep the raw listener on loopback. Configure and verify the chosen transport separately.

Choose a protected transport
tailscale serve 4005
Complete TLS, VPN and reverse-proxy reference →

Keep secrets private

Use hidden onboarding prompts for provider keys. Keep owner configuration and ~/.mso private. When sharing a doctor report or log, remove credentials, account details and private paths first.

Full current reference

These guides orient you; use the runtime reference for complete flags and operational procedures.

Read SECURITY.md on GitHub ↗

Reviewed against source 5c4f136a.