Skip to content

Device setup

Agentknock opens setup on first launch and whenever its saved device keys are unavailable. Setup registers the phone with the relay and claims the public pairing address that clients use to find it.

After the welcome screen, the app suggests a random three-word address. Use it, select Another suggestion, or type your own. The address contains lowercase English letters with single hyphens between words; a single word is also valid. Spaces, digits, uppercase letters, and empty words aren’t accepted.

This address is public. Knowing it allows a client to request pairing, but each pairing still requires you to compare and accept its verification code. It doesn’t reveal secrets or grant access by itself.

During initial setup, choose how Agentknock uses Android authentication:

Setting Behavior
Rely on device lock The default. Agentknock relies on Android’s screen lock and adds no authentication prompts for actions in the app.
Protect sensitive actions Authenticate before viewing, copying, or editing sensitive values, creating non-sensitive values, reducing sensitivity, or accepting a new client. Ordinary navigation remains available.
Lock Agentknock Authenticate to open the app’s contents. A brief return within 15 seconds of leaving keeps the authenticated session.

Selecting a different mode can require Android authentication. The choice is saved when that change succeeds, independently of claiming the address. You can change it later in device authentication settings.

The screen links to the service terms and privacy notice, and states that claiming the address accepts the terms.

Claim pairing address creates the phone’s device identity and communication keys, stores the credentials encrypted on the phone, and contacts the relay. Internet access is required. The app opens its main interface after the relay accepts the claim.

If another device already uses the address, choose another. Connection failures and rejected or invalid relay responses are shown on the setup page. Try again retries the saved attempt; it doesn’t require starting setup over. You can also edit the address and retry with the same pending device identity.

New pairings are enabled after setup. Your address appears in Clients, where you can copy it, change it, or pause new pairings. Setting up the phone doesn’t create a client pairing or add any secrets. See Getting started for those steps.

After initial setup, the app offers Allow notifications or Not now. Allowing them opens Android’s permission flow where required. Notifications alert you when a request needs your decision, including while the app is closed.

Declining doesn’t prevent pairing or request handling in the app. You can enable notifications later under Notifications.

Device keys unavailable can appear after restoring a backup or transferring the app to another phone. The saved device information may still exist even though Android no longer has the keys needed to read its credentials.

Claim a different available address to create a replacement device identity. This differs from an ordinary address change: existing clients must pair again, their approval overrides and temporary access are removed, and unfinished requests tied to the old identity are ended. New pairings start enabled.

Secret records, history, and global AI instructions remain. Creating a new device identity doesn’t recover sensitive secret values or private keys whose encryption keys are also unavailable. See Security and backup for that distinction.