Open this box from a phone or another browser
Sign in to app.v-code.dev with the account this box is linked to, and the box opens. There is no code to type. The box lists every device that has opened it, and removes them. A box that should only open for devices you pair by hand can require pairing for new devices instead.
Why you would use it
You want the same boxes on your phone, your laptop and a second browser without pairing each one with each box. Signing in is the step you already take; the box trusts the account.
How to use it
- On the phone, open app.v-code.dev and log in with your email (use-the-app). Every box on the account opens.
- On the box,
v-code box deviceslists the phone once it has opened the box.
Require pairing on one box
The settings sheet and the v-code box commands have no switch for this yet.
It is turned on from the box itself.
Devices the box already knows keep working. A new device gets the pair screen in
the app, with
This box asks for pairing. On the box, run v-code box pair and type the code it shows.
To pair it:
On the box, make a code:
v-code box pair # Pairing code: K7QM-3XRT (valid 10 minutes) # Box fingerprint: 0H1734S7NMRW5KJWOn the phone, check that the fingerprint the app shows is the one the box printed, tap Yes, type the code and tap Pair. See use-the-app.
A phone that opens the box cannot change the switch.
Remove a device
v-code box devices # <id> <name> paired <time> last seen <time|never>
v-code box forget <id> # remove one
A device you remove stays out of this box until you pair it again. It gets the pair screen next time, even with the switch off.
Options and settings
| Option | Default | What it changes |
|---|---|---|
| Require pairing | Off | On: a device the box has not seen needs a pairing code. Off: any device signed in to the account opens the box |
| Code length | 8 characters, shown XXXX-XXXX |
Fixed. Crockford base32. |
| Code lifetime | 10 minutes | Fixed. |
| Wrong tries | 5 | Fixed. The code is spent after the fifth wrong one. |
Limits and known gaps
- Your account is the key to your boxes. With the switch off, whoever can sign in to your v-code.dev account (for example, with access to your email) can open every box on it, and a box runs code as you. Turn the switch on for a box that needs more.
- A box lets a new device in only on the key that device registered when it
signed in. The sign-in token carries that key, so someone who steals a token
cannot open the box with a key of their own: they get
unpaired. - A device removed on one box is removed there only. To stop a device on every box, remove it from your account on v-code.dev: it can no longer sign in.
- One pairing code at a time. Make a new one and the old one stops working.
- Codes live in memory. A restart of VCode spends the current one.
- Unlinking removes every device. The removed ids and the switch stay, so a relink does not let a removed device back in.
- A box lets at most 100 devices in through the account. Past that, a new device has to pair with a code.
- Rotating
AUTH_TOKENor signing out does not remove a device. See sign-every-device-out. - Removing a device closes the channels it has open.
Related
- link-this-box — linking comes first
- add-a-computer — link a new computer with a join code
- use-the-app — the phone's side
- work-on-several-boxes — every box on the account in one strip