{"_id":"@bytedesert/apple-pi","_rev":"5-1b2707e4cc542cc8bfeabff22d8a73d0","name":"@bytedesert/apple-pi","dist-tags":{"latest":"0.2.4"},"versions":{"0.2.0":{"name":"@bytedesert/apple-pi","version":"0.2.0","keywords":["apple-pi","ios","pi","pi-package","tailscale"],"author":{"name":"Byte Desert"},"license":"MIT","_id":"@bytedesert/apple-pi@0.2.0","maintainers":[{"name":"bytedesert","email":"info@bytedesert.com"}],"pi":{"extensions":["./extension.mjs"]},"bin":{"apple-pi":"apple-pi-host.mjs","apple-pi-container":"container.mjs"},"dist":{"shasum":"0954f5063fc61adedbe89f9eae83dc6fe7c25b0c","tarball":"https://registry.npmjs.org/@bytedesert/apple-pi/-/apple-pi-0.2.0.tgz","fileCount":11,"integrity":"sha512-eIA1nACiL0B+2rRbsxEZ3wXxTE97QOiHpvyKFsb3oryuFaba2+5Jsj6sXysXhJqMR9UOa5QXkIjJ/Mw7Qnbgww==","signatures":[{"sig":"MEUCIQDBhltTqMwc+FfXdKwUyyYqfj3jhM1V8GRJyqiXFgdOZAIgbTGCSoqpwBnyqQmtwj2Cgajw3gFN+4cGvOCZ2t+y3Sg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1458483},"type":"module","_from":"file:dist/bytedesert-apple-pi-0.2.0.tgz","engines":{"node":">=22.19.0"},"_npmUser":{"name":"bytedesert","email":"info@bytedesert.com"},"_resolved":"/Users/andrewhoughton/Developer/apple-pi/dist/bytedesert-apple-pi-0.2.0.tgz","_integrity":"sha512-eIA1nACiL0B+2rRbsxEZ3wXxTE97QOiHpvyKFsb3oryuFaba2+5Jsj6sXysXhJqMR9UOa5QXkIjJ/Mw7Qnbgww==","_npmVersion":"11.4.1","description":"Pair your existing Pi harness with the native apple-pi iPhone app over Tailscale","directories":{},"_nodeVersion":"23.9.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"peerDependencies":{"@earendil-works/pi-tui":">=0.85.0 <0.86.0","@earendil-works/pi-coding-agent":">=0.85.0 <0.86.0"},"peerDependenciesMeta":{"@earendil-works/pi-tui":{"optional":true},"@earendil-works/pi-coding-agent":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/apple-pi_0.2.0_1788758867972_0.745261926905439","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@bytedesert/apple-pi","version":"0.2.1","keywords":["apple-pi","ios","pi","pi-package","tailscale"],"author":{"name":"Byte Desert"},"license":"MIT","_id":"@bytedesert/apple-pi@0.2.1","maintainers":[{"name":"bytedesert","email":"info@bytedesert.com"}],"pi":{"extensions":["./extension.mjs"]},"bin":{"apple-pi":"apple-pi-host.mjs","apple-pi-container":"container.mjs"},"dist":{"shasum":"6cc7994bc679cf1ad5abaaac06ff5a3446195e02","tarball":"https://registry.npmjs.org/@bytedesert/apple-pi/-/apple-pi-0.2.1.tgz","fileCount":11,"integrity":"sha512-K9uAsQ+PZy9oymX+G+OeE6RplRh2zfIpQuemqSLodW08tuvp+tMYnN2uGC55vzdk4Tc5qChI2WBNObTjX3Z6Rw==","signatures":[{"sig":"MEQCICTpC2Gfsggr0xfEk+qSdPse2FNIHB2Li9drpErAXx2ZAiBrjcMnkB4FNes+kQe7sMYwF+EGbCJohby5GQeKC0Tbug==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQCaa+/uZlizgBagPeOKS6F0RCebw5K4/bGuSA2tJ/HIpwIhAM2fhx2j/8Ha/MG6Apty7ziIB/TnhOYgXU79ttESbim+","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1464016},"type":"module","_from":"file:ios/build/bytedesert-apple-pi-0.2.1.tgz","engines":{"node":">=22.19.0"},"_npmUser":{"name":"bytedesert","email":"info@bytedesert.com"},"_resolved":"/Users/andrewhoughton/Developer/apple-pi/ios/build/bytedesert-apple-pi-0.2.1.tgz","_integrity":"sha512-K9uAsQ+PZy9oymX+G+OeE6RplRh2zfIpQuemqSLodW08tuvp+tMYnN2uGC55vzdk4Tc5qChI2WBNObTjX3Z6Rw==","_npmVersion":"11.4.1","description":"Pair your existing Pi harness with the native apple-pi iPhone app over Tailscale","directories":{},"_nodeVersion":"23.9.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"peerDependencies":{"@earendil-works/pi-tui":">=0.85.0 <0.86.0","@earendil-works/pi-coding-agent":">=0.85.0 <0.86.0"},"peerDependenciesMeta":{"@earendil-works/pi-tui":{"optional":true},"@earendil-works/pi-coding-agent":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/apple-pi_0.2.1_1788800525110_0.7908029305195741","host":"s3://npm-registry-packages-npm-production"}},"0.2.2":{"name":"@bytedesert/apple-pi","version":"0.2.2","keywords":["apple-pi","applePi","ios","pi","pi-package","tailscale"],"author":{"name":"Byte Desert"},"license":"MIT","_id":"@bytedesert/apple-pi@0.2.2","maintainers":[{"name":"bytedesert","email":"info@bytedesert.com"}],"pi":{"extensions":["./extension.mjs"]},"bin":{"apple-pi":"apple-pi-host.mjs","apple-pi-container":"container.mjs"},"dist":{"shasum":"13ec8828b3721afbd6efb1ec3b0eb216614a97b1","tarball":"https://registry.npmjs.org/@bytedesert/apple-pi/-/apple-pi-0.2.2.tgz","fileCount":11,"integrity":"sha512-PzYDPjaY2EAYFKjgGJpQkHEZAuJFq5SncSxBxU08xXWyOGQ2OkLFFs6GAV8tIRnIqpw/k1q/w08O4i75o5V7uw==","signatures":[{"sig":"MEYCIQDvxhst1Qo6hcYveJP25i0fvryOJ8JSk/Zlwgx+YenzawIhALBx3Zu4UwPyZid8Y8w1ZkVZFPtRboNswQx3Qq941IRq","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIBKBOHPRRAl3P2EO+o780E/RuTaH/yTO43/DAUIua4lKAiEA1YGJFC2TJKwXAeBWPtg9WsB09+M6iWj70i1OlEHhfrU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1464186},"type":"module","_from":"file:ios/build/bytedesert-apple-pi-0.2.2.tgz","engines":{"node":">=22.19.0"},"_npmUser":{"name":"bytedesert","email":"info@bytedesert.com"},"_resolved":"/Users/andrewhoughton/Developer/apple-pi/ios/build/bytedesert-apple-pi-0.2.2.tgz","_integrity":"sha512-PzYDPjaY2EAYFKjgGJpQkHEZAuJFq5SncSxBxU08xXWyOGQ2OkLFFs6GAV8tIRnIqpw/k1q/w08O4i75o5V7uw==","_npmVersion":"11.4.1","description":"Pair your existing Pi harness with the native applePi iPhone app over Tailscale","directories":{},"_nodeVersion":"23.9.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"peerDependencies":{"@earendil-works/pi-tui":">=0.85.0 <0.86.0","@earendil-works/pi-coding-agent":">=0.85.0 <0.86.0"},"peerDependenciesMeta":{"@earendil-works/pi-tui":{"optional":true},"@earendil-works/pi-coding-agent":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/apple-pi_0.2.2_1788805000469_0.11539353375997097","host":"s3://npm-registry-packages-npm-production"}},"0.2.3":{"name":"@bytedesert/apple-pi","version":"0.2.3","keywords":["apple-pi","applePi","ios","pi","pi-package","tailscale"],"author":{"name":"Byte Desert"},"license":"MIT","_id":"@bytedesert/apple-pi@0.2.3","maintainers":[{"name":"bytedesert","email":"info@bytedesert.com"}],"pi":{"extensions":["./extension.mjs"]},"bin":{"apple-pi":"apple-pi-host.mjs","apple-pi-container":"container.mjs"},"dist":{"shasum":"3a54d2e992aad19ec21bcc3553f3d040e55f1ffe","tarball":"https://registry.npmjs.org/@bytedesert/apple-pi/-/apple-pi-0.2.3.tgz","fileCount":11,"integrity":"sha512-9wzFwfF7WMH6zF3a6ys+VLekfxmZmEoifK0UorXPFg0CKOoSOEAYBNG+1dbsH428TrSRHBxpYNPNZzOK+Ekc7Q==","signatures":[{"sig":"MEQCIBxDkWs/lkutF5NN41d05jN+UjVXSMbWNxjm6Jq+etVwAiBQCrW30e9I9X852pGNSZNDuXp6bwpOkzUu4x34b0PfnQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQDw2daai03ss5kvFHIQaC55ubhPxm2yDE5VkSe6xzkb3QIhANNZrJF7r3IJ409ewueJDQePXnW9PhY8J3DzQskEXKzD","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1469822},"type":"module","_from":"file:dist/bytedesert-apple-pi-0.2.3.tgz","engines":{"node":">=22.19.0"},"_npmUser":{"name":"bytedesert","email":"info@bytedesert.com"},"_resolved":"/Users/andrewhoughton/Developer/apple-pi/dist/bytedesert-apple-pi-0.2.3.tgz","_integrity":"sha512-9wzFwfF7WMH6zF3a6ys+VLekfxmZmEoifK0UorXPFg0CKOoSOEAYBNG+1dbsH428TrSRHBxpYNPNZzOK+Ekc7Q==","_npmVersion":"11.4.1","description":"Pair your existing Pi harness with the native applePi iPhone app over Tailscale","directories":{},"_nodeVersion":"23.9.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"peerDependencies":{"@earendil-works/pi-tui":">=0.85.0 <0.86.0","@earendil-works/pi-coding-agent":">=0.85.0 <0.86.0"},"peerDependenciesMeta":{"@earendil-works/pi-tui":{"optional":true},"@earendil-works/pi-coding-agent":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/apple-pi_0.2.3_1788809783268_0.44987297718712327","host":"s3://npm-registry-packages-npm-production"}},"0.2.4":{"pi":{"extensions":["./extension.mjs"]},"_id":"@bytedesert/apple-pi@0.2.4","bin":{"apple-pi":"apple-pi-host.mjs","apple-pi-container":"container.mjs"},"dist":{"shasum":"7e4f24ea46a3e710ef78d2a0645476b40c69059a","tarball":"https://registry.npmjs.org/@bytedesert/apple-pi/-/apple-pi-0.2.4.tgz","fileCount":11,"integrity":"sha512-Nmnk56tRXmXIAg4UvAhkvouT6gnLOUGSMMpbUtMaGfj+RpvelQYnvvDGnwEmKTeA4A5aCHa97w+SX4RoPhWHKQ==","signatures":[{"sig":"MEQCIGLGcDaXYhHs8OSm3V9/F4m3Q58vHRQlWk3ljRT0s8tiAiAEnfbUr+e7RZ8HyGnSy/HSk1t/23ptREHUgalWHFpY3A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIGVPjVRdMJzV+/Orn+s6vztpeHXRAkdK3B9G4eCgvWRxAiEA9u5OJlKE3i46fVmIirCse8+r5X3dND1i6LtPiVKtzY0="}],"unpackedSize":1483684},"name":"@bytedesert/apple-pi","type":"module","author":{"name":"Byte Desert"},"engines":{"node":">=22.19.0"},"gitHead":"a0d1f6c9dd1a7a83569dc6e7250eccd02688b96f","license":"MIT","version":"0.2.4","_npmUser":{"name":"bytedesert","email":"info@bytedesert.com"},"keywords":["apple-pi","applePi","ios","pi","pi-package","tailscale"],"_npmVersion":"11.4.1","description":"Pair your existing Pi harness with the native applePi iPhone app over Tailscale","directories":{},"maintainers":[{"name":"bytedesert","email":"info@bytedesert.com"}],"_nodeVersion":"23.9.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"peerDependencies":{"@earendil-works/pi-tui":">=0.85.0 <0.86.0","@earendil-works/pi-coding-agent":">=0.85.0 <0.86.0"},"peerDependenciesMeta":{"@earendil-works/pi-tui":{"optional":true},"@earendil-works/pi-coding-agent":{"optional":true}},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/apple-pi_0.2.4_1788820202743_0.6507771875703687"}}},"time":{"created":"2026-09-07T05:27:47.823Z","modified":"2026-09-07T22:30:02.996Z","0.2.0":"2026-09-07T05:27:48.130Z","0.2.1":"2026-09-07T17:02:05.200Z","0.2.2":"2026-09-07T18:16:40.593Z","0.2.3":"2026-09-07T19:36:23.420Z","0.2.4":"2026-09-07T22:30:02.836Z"},"author":{"name":"Byte Desert"},"license":"MIT","keywords":["apple-pi","applePi","ios","pi","pi-package","tailscale"],"description":"Pair your existing Pi harness with the native applePi iPhone app over Tailscale","maintainers":[{"name":"bytedesert","email":"info@bytedesert.com"}],"readme":"# applePi\n\nPair your existing **Pi harness** with the native **applePi** iPhone/iPad app over **Tailscale**. Install this Pi package, open a working Pi session on your computer, run `/apple-pi pair`, and scan the QR on your phone.\n\nPairing is per phone and harness, not per conversation. Afterward you can close the Pi terminal and create Chat or Code sessions from your phone. The background daemon starts at login. Your computer must remain awake, logged in, and connected to Tailscale; your model services must be available.\n\nThe iOS app is currently in TestFlight. This package works with applePi **1.0 build 7 or later**; build 8 includes these package setup instructions. Installing the npm package does not grant access to the private TestFlight group.\n\n## First connection: Windows, macOS, or Linux\n\n1. Install and connect **Tailscale** on the computer and iPhone, on the same tailnet. Confirm your normal Pi harness can answer a message on the computer. This release is tested against **Pi 0.85.x** and requires **Node 22.19 or later**.\n2. In your harness directory, install the package using the Pi CLI:\n\n   ```sh\n   pi install -l npm:@bytedesert/apple-pi\n   ```\n\n   This registers the package in the project's `.pi/settings.json`. Keep using your harness's normal Pi launcher, agent directory, model settings, and provider sign-in.\n3. Start Pi normally, or run `/reload` in an existing interactive Pi session. Inside Pi, run:\n\n   ```text\n   /apple-pi pair\n   ```\n\n   The extension captures your current model, launch flags, harness configuration, and environment. It detects MagicDNS and the Tailscale IP, chooses a free port starting at 6768, and installs a background service for this harness. On Windows, allow the **Windows UAC prompt** if a Tailscale-only firewall rule is needed. It does not request administrator access for the Pi daemon itself.\n4. The computer displays a five-minute QR in Pi and, outside a container, opens a local pairing page. In applePi, choose **Pair harness → Scan pairing QR**, scan it, review the computer name, and tap **Pair and connect**. The QR fills in MagicDNS automatically; you do not need to type it. If the QR is too wide for your terminal, use the browser page or enlarge the terminal.\n5. Create a **Chat** for general conversation, or choose **Code** and select a project directory. Both use the harness's installed agents, extensions, skills, commands, and model configuration. You can close the computer's Pi terminal now.\n\nRun `/apple-pi pair` again to add another phone, replace an expired QR, or re-enable a stopped daemon. It does not revoke existing phones or interrupt a running daemon. Each QR pairs one phone.\n\n## Harness repositories that manage npm/Bun dependencies\n\nInstead of `pi install`, add the package to the repository:\n\n```sh\nbun add @bytedesert/apple-pi\n# or: npm install @bytedesert/apple-pi\n```\n\nThen **append** its local path to the existing `packages` array in your Pi settings file. For a harness with `PI_CODING_AGENT_DIR=agent` and `agent/settings.json`:\n\n```json\n{\n  \"packages\": [\n    \"../node_modules/@bytedesert/apple-pi\"\n  ]\n}\n```\n\nPreserve the other packages and settings. The path is relative to the settings file. An npm/Bun dependency alone does not register Pi resources. Start the harness using its usual launcher, then `/apple-pi pair` inside Pi. Do not create another Pi installation or change your model's API keys for the phone.\n\n## Commands inside Pi\n\n| Command | Result |\n| --- | --- |\n| `/apple-pi pair` | Enable background startup and show a fresh QR. Existing phones stay paired. |\n| `/apple-pi status` | Show daemon readiness, version, address, and paired-phone count. |\n| `/apple-pi devices` | List paired phones; select and confirm to revoke one. |\n| `/apple-pi disable` | Confirm, stop active phone runs, and remove startup. Keep saved conversations and paired-phone hashes. |\n\nThese controls run only in a **local interactive Pi session**. The extension factory performs no setup, and phone/RPC workers cannot start daemons or issue pairing codes. Reloading, forking, or closing the local Pi session leaves the daemon alone.\n\n## What is preserved\n\nThe daemon uses the harness's installed Pi CLI. New phone sessions resolve the harness's current package settings using Pi's package manager, including resource filters. Project extensions, skills, prompts, and themes remain available in Chat's private directory. Changes to installed packages are picked up by new sessions; existing running sessions keep their loaded resources.\n\nProvider credentials stay on the computer. For startup without a terminal, the launch environment is stored locally with the harness profile, including environment variables required by extensions and model providers. This directory is restricted to the current OS user (and SYSTEM on Windows). It is not included in npm packages or pairing QR codes. Pi's existing agent directory remains the source of auth files and model configuration. Changes to shell-supplied environment variables or launch flags require running `/apple-pi pair` again and restarting the daemon when active work has finished.\n\nChat gets a private working directory; Code gets the selected project directory. The default project browser root is the harness repository's parent. Chat is behavioral guidance, **not a filesystem sandbox**. Extensions that assume every session's `cwd` is the harness root need to use their configuration/package path instead; Code intentionally changes `cwd` to the selected project. Arbitrary custom terminal screens cannot be reproduced automatically on a phone; supported Pi dialogs, tools, commands, statuses, and bridge components use the native app.\n\n## Background startup and updates\n\nVersion 0.2.4 fixes photo/file uploads over the Node host and retains completed\nartifact files even after scratch cleanup. The gallery shows final deliverables\nrather than every intermediate write. Background-task creation positions and\ncompletion state survive reconnects. Update to applePi build 16 for the matching\nchat layout and activity-card changes. Existing phones remain paired.\n\nVersion 0.2.3 adds composer `@agent` activation for applePi build 13. The app lists\nthe harness's configured agents as you type `@`; choosing a handle and sending a\ntask starts that subagent through the harness's background queue. Its card stays\nat its creation point in the conversation and opens the live transcript, including\nthinking. Failed launches preserve the phone's draft. Existing pairing credentials\nremain valid. Older hosts still support normal chat; update the host for `@agent`.\n\nVersion 0.2.2 updates visible branding to **applePi**. Package names, commands, pairing links, and saved credentials are unchanged. The iOS UI improvements also work with host 0.2.1.\n\nVersion 0.2.1 adds native agent conversation reading for `@tintinweb/pi-subagents`:\nthe iPhone can open an agent's messages, thinking, and tool results while it runs.\nExisting pairing credentials remain valid. Update both the Pi package and iPhone\napp to use the new conversation sheets.\n\n- **Windows:** current-user Task Scheduler job, at login, limited privileges, no stored Windows password. Firewall allows only the chosen Tailscale IPv4 and tailnet source range. Windows logout stops interactive-user hosting; a locked desktop continues hosting.\n- **macOS:** current-user LaunchAgent. It continues after closing Pi and starts at login.\n- **Linux:** `systemd --user` service. A user systemd session is required. To run across logout, configure user lingering with your system administrator; default setup promises startup at login.\n- **Docker:** use the included supervisor with the existing harness image as described below.\n\nUpdate with `pi update npm:@bytedesert/apple-pi`, or update your repository dependency and lockfile. Reload Pi and run `/apple-pi pair` to stage the updated runtime. This leaves current runs intact. When those runs finish, use `/apple-pi disable` followed by `/apple-pi pair` to activate the update. Phones do **not** need to scan again. Login/restart also uses the staged runtime. Runtime files are copied to an immutable per-version folder, so replacing an npm installation does not remove files needed by running sessions.\n\nState lives in `~/.apple-pi/harnesses/<harness-id>/`. Keep this directory and your Pi agent configuration when upgrading. Moving the harness or agent directory changes its identity; it requires setting up that new location. Existing legacy Bun-server conversations are not automatically migrated.\n\nPhones paired to the same harness share its sessions and filesystem authority. Use separate OS users/harness profiles for isolation. Revoking a phone closes active connections within five seconds. The phone stores a random credential in device-only Keychain; the daemon stores only its hash. QR tickets expire after five minutes and daemon restart invalidates unused tickets.\n\n## Docker\n\nDocker needs one-time image and networking integration. A dependency cannot publish a container port by itself. Keep your existing harness image, provider environment, users, and persistent volumes.\n\n1. Add this package to the image's harness dependencies and Pi settings using the repository instructions above.\n2. On the PC, obtain `tailscale ip -4` and the computer's full MagicDNS name. Set `TAILSCALE_IPV4` and `TAILSCALE_MAGICDNS` in the existing Compose environment.\n3. Merge `compose.example.yaml` into the harness service. Adapt its command to wrap your existing long-running service with `node /harness/node_modules/@bytedesert/apple-pi/container.mjs -- YOUR_EXISTING_COMMAND`. If the container's only long-running service will be the harness daemon, omit `-- YOUR_EXISTING_COMMAND`. Keep the image's existing entrypoint if it performs setup; make sure it executes the wrapped command.\n4. Persist the container user's home, including `.apple-pi`, as well as the existing Pi agent configuration and session/model volumes. Keep the same container user and paths across recreations. The host port must be published **only on the PC's Tailscale IP**, never every interface. Use your normal Compose deployment process to recreate the container with the port mapping.\n5. Open Pi in that running container, from the harness directory and with its usual launcher:\n\n   ```sh\n   docker exec -it --workdir /harness YOUR_CONTAINER pi\n   ```\n\n6. Verify the normal model works and run `/apple-pi pair`. Scan the terminal QR with applePi. The supervisor restarts enabled harness daemons after container recreation; new phone sessions do not need the local Pi terminal.\n\nUse one paired harness per published container port. The container must receive `APPLE_PI_CONTAINER_HOST` and `APPLE_PI_CONTAINER_PORT` (default 6768). Tailscale runs on the PC; it is not required inside the harness container. Inside Docker the daemon binds `0.0.0.0`; the host's Tailscale-only publication is its network boundary. Check your actual Docker networking platform permits binding its Tailscale IP, especially on Windows Docker Desktop.\n\n## Troubleshooting\n\n- **No `/apple-pi` command:** check `pi list`, the active agent directory and package registration, then `/reload`. Use Pi 0.85.x. Phone/RPC sessions intentionally do not expose setup commands.\n- **Daemon not starting:** run `/apple-pi status`. Inspect that profile's `daemon.log`. The service waits for Tailscale to become available. A missing Node/Pi executable after changing your runtime installation requires `/apple-pi pair` from the new working environment.\n- **Windows setup prompt denied:** run `/apple-pi pair` again and allow Windows to add the Tailscale-only firewall rule. Existing model/Serve ports are unaffected.\n- **Phone times out:** keep both devices on the tailnet, allow their connection in your tailnet policy, and confirm the computer is awake. Pairing does not alter tailnet ACLs or start the model server.\n- **Expired or lost QR:** run `/apple-pi pair` again. Existing phone credentials are unaffected.\n- **Paired but model does not answer:** verify the model and services in the computer's ordinary Pi session. Local models and API services such as OpenRouter remain entirely harness-managed.\n- **Already using build 7:** its QR protocol is compatible. Follow the same package steps. Build 8 replaces the old manual-host instructions.\n\nThere is no public relay, Funnel, SSH setup, or separate desktop app. HTTP/WebSocket traffic is private and encrypted by Tailscale/WireGuard. Native hosts bind only the Tailscale IP and reject non-tailnet peers, unexpected Host headers, and browser Origins. Pairing administration uses an authenticated local socket, not a public HTTP endpoint.\n\nThe bundled `apple-pi` shell command retains the older foreground portable-host workflow for existing deployments. New users should use `/apple-pi pair` **inside Pi** for background startup.\n","readmeFilename":"README.md"}