Client details
Open a paired client from Clients to rename it, edit its AI review instructions, end temporary access, or suspend or revoke its pairing.
Name and client information
Section titled “Name and client information”Rename client changes the name used in Agentknock. It doesn’t change the computer’s hostname or its CLI configuration. Names cannot be blank; leading and trailing whitespace is removed when you save. Names don’t have to be unique. Cancel leaves the existing name unchanged.
Expand Client information for the available details:
| Field | Meaning |
|---|---|
| Hostname | The name reported by the client’s operating system. |
| Operating system | The reported OS version, or the platform name when no version was supplied. |
| Last request | The most recent request recorded for this client. Finishing pairing also sets this time; it isn’t an online-status indicator. |
| Architecture | The client’s reported processor architecture. |
| Client software | The application name and version reported by the client. |
| Agentknock library | The reported library name and version, shown separately when they differ from the application. |
| Paired | When the phone completed this pairing. |
| Machine ID | An operating-system identifier, if the client supplied one. |
| Client ID | The identifier of this particular pairing. Pairing the same computer again creates a different client. |
Host and software information provides context supplied by the client. It isn’t independent verification of the computer’s identity. Fields the client didn’t supply are omitted.
AI review instructions
Section titled “AI review instructions”Client AI instructions adds guidance about this client’s purpose, environment, and expected work. The AI reviewer receives these alongside the global instructions and instructions for the requested secrets.
You can save instructions even when AI review is inactive. They take effect when a request is reviewed by AI; they don’t change a secret’s approval mode or restrict an approval that bypasses AI review.
The editor saves only when you select Save. Leading and trailing whitespace is removed, and saving an empty field clears the instructions. Leaving with unsaved changes offers Discard or Keep editing.
Renaming the client or changing its instructions during an AI review can make that request require your decision because the review used the previous information.
Secret approval settings
Section titled “Secret approval settings”Approval modes belong to secrets. To change the mode for one client, open the secret’s details and set its client override there. A client pairing by itself doesn’t bypass these settings.
Temporary access
Section titled “Temporary access”This section appears when the client has unexpired temporary access. Each entry identifies the secret, permitted operation, and expiry time:
| Operation | Scope |
|---|---|
| Secret values | That secret’s values for any command from this client. |
| Git signing | That secret’s SSH key for Git signing in any repository from this client. |
| SSH authentication | That secret’s SSH key for authentication to any server from this client. |
These are separate grants. Temporary access for one operation doesn’t cover another, and it isn’t limited to the command, repository, or server in the request that created it.
While a grant is valid, it skips manual and AI review for that secret and operation. The effective Deny setting still blocks access, and other secrets in the same request must satisfy their own approval settings.
Select End to remove a grant immediately. This restores the secret’s normal approval behavior for subsequent access; it doesn’t set the secret to Deny or recall values already supplied. Expired grants disappear automatically. Grants are created from request approval controls, not from this page.
Suspend and resume
Section titled “Suspend and resume”A client can make requests only while Active. Pending means the pairing isn’t yet usable; finish pairing on the client and allow the relay update to complete.
Suspend prevents the client from making requests while keeping the pairing. Resume enables it again. Neither action needs a confirmation dialog.
The app records the change locally and sends it to the relay. Changing to suspended… or Changing to active… means the relay hasn’t confirmed it yet. The phone blocks new requests as soon as suspension is requested; resuming access waits for the relay to confirm that the client is active.
Suspension pauses existing temporary access without extending its expiry time. Resuming the client before a grant expires makes the remaining time available again. End the grant separately if that access should not resume.
Revoke a client
Section titled “Revoke a client”Revoke client… asks for confirmation, then permanently ends the pairing. The phone removes the client from this page and deletes its pairing keys and temporary grants immediately, while the relay update is synchronized in the background. Revocation cannot be undone by resuming the client.
Secrets and existing request and audit history remain on the phone. Values already received by the client cannot be recalled.
The CLI still has its local pairing record. To reconnect, remove that record locally and pair again. The new pairing is a new client and doesn’t inherit the revoked client’s instructions, approval overrides, or temporary access.