Skip to content
Local OperatorDocs

Agent Mesh

Note:

Preview. The full Agent Mesh guide is being written. Pairing is done from the CLI today; the guide will cover roles, trust, and incident controls.

A mesh pairs your devices into one network, so a session on your laptop can see — and hand work to — sessions on another machine: the always-on box at home, the workstation at the office, a teammate's machine with the right access.

The mesh panel on a fresh device: no identity yet, no networks, no peers, relay not running, and the next command named for each.
A fresh device: the mesh panel names the next command at every step.
#

Pairing

Pairing is a shared-secret handshake with a human on both keyboards: one device mints a single-use invite, the other joins with it and derives a 6-digit code plus a fingerprint, and a person compares them with what the inviting side shows before confirming. An agent can drive the joining side up to that compare — no agent path can complete a pairing, and that is a designed interlock, not a gap.

Mesh pairingA token, a code, and a person comparing the two1234Device A mints the invitelop network invitea single-use token file (0600) — default TTL 10 minA person carries it acrossout of band — moved by hand, never through a chatDevice B derives its own codelop network join @<token>both screens now show the same 6-digit code + fingerprintA human compares and confirmsthe joiner types the code read off the other device's screenagents can park the ceremony — never complete a pairinginvite tokensingle-use · TTL'dcarried by hand481 926fingerprint alongsidePaired — every link after this is device-to-device; no service in the middle.
A token, a code, and a person comparing the two
The mesh panel after pairing: this device, two networks with roles and member counts, peers with reachability, and a running relay.
Paired: networks with their roles, peer reachability, and relay health in one panel.
#

What you can do across devices

  • Sessions across devices — list the sessions a peer is running, start one there (/new remote <peer>, or lop network sessions --peer <peer> --create from a shell), or send it a task.
  • Roles, not guesswork — read means see, drive adds prompting and steering, and admin adds moving, deleting and membership changes.
  • Hand off. Move a conversation between devices with its transcript intact and bring it home the same way — the session keeps its history, todos and tool trail wherever it runs.
The /new remote picker listing paired devices with their network and role.
Starting a session on another device: the picker lists the peers you can reach.
The session sidebar with a remote device's sessions grouped under a heading naming that device.
Remote sessions in the sidebar, grouped under the device that owns them.
#

Staying in control

  • Trust is explicit — a device you have not admitted sees nothing, and you can revoke access per device: lop network member rm <network> <device> rotates the shared secret and withholds it from the removed device.
  • Leaving is a command, not a hope — lop network disconnect stops trusting the network, closes links, and deletes the local secret; the audit trail stays.
  • An incident has one command — lop network panic broadcasts a revoke, rotates the secret, and marks the network untrusted here; every other device must be re-admitted before it can connect again.
  • Compare what you can see — never type a pairing code you did not see on the other device's screen, and never print an invite token.

Until the full guide lands, lop network --help is the reference.