Devices & remote control
Enroll independent machines with revocable credentials, metadata sync and acknowledged commands.
On this page
Enroll a fresh local ledger
An owner or admin signs in through a browser-approved device code, then registers the machine. Use the real control API URL for your deployment. Device credentials are separate from your human login and are saved in ~/.leash/device.json with mode 0600.
export LEASH_HOME="$HOME/.leash-work"
export DATABASE_URL=""
leash login --api https://YOUR_CONTROL_PLANE_DOMAIN
leash device register --name work-laptop
leash startSync and receive commands
leash start runs the background poll, execute and acknowledgement loop when device credentials are present. Usage, sessions and kills sync as metadata from the SQLite ledger. Repeated sync is deduplicated.
leash device list
leash sync --device
# One explicit cycle against a running local proxy:
leash agent --onceRemove access from a lost machine
Settings → Devices shows connection status, last seen time and command acknowledgements. Revoke a device there or from the CLI. Its transport token immediately stops authenticating and pending commands expire; local safety settings are not erased.
leash device revoke DEVICE_ID