Security & remote access
Owner authority, browser pairing and protected HTTPS access.
Pair a new browser
Sign in with your owner password. A new browser remains pending until approved. Run the commands below from the owning host terminal or use Settings → Account → Devices in an approved browser.
Replace <deviceId> with the exact ID shown by the browser, then check again. Device identity is scoped to the origin: changing the hostname creates a different browser device.
mso device pending
mso device approve <deviceId> "my laptop"Choose a protected transport
The default listener is 127.0.0.1:4005. Local access uses localhost. Remote access needs protected HTTPS because session cookies are Secure.
Use Tailscale Serve, a reviewed HTTPS reverse proxy or a named tunnel. Keep the raw listener on loopback. Configure and verify the chosen transport separately.
tailscale serve 4005Keep secrets private
Use hidden onboarding prompts for provider keys. Keep owner configuration and ~/.mso private. When sharing a doctor report or log, remove credentials, account details and private paths first.
These guides orient you; use the runtime reference for complete flags and operational procedures.
Read SECURITY.md on GitHub ↗Reviewed against source 5c4f136a.