Reach the board from your phone
Reach the board from your phone to answer an agent, approve a plan or merge while you are away from your desk. You end with the board installed on your phone’s home screen, signed in and sending you notifications.
The phone does everything the desktop does. Two things are involved: a transport (how your phone’s connection reaches this machine) and an access token (so not just anyone who reaches the port can drive your agents).
Before you begin
Section titled “Before you begin”-
An access token. The one-line installer and the desktop app create one for you. The board reads it from
REV0_AUTH_TOKEN, in the environment or in~/.rev0/.env. To make one yourself:Terminal window python -c "import secrets;print(secrets.token_urlsafe(32))"and add it to
~/.rev0/.envasREV0_AUTH_TOKEN=.... -
For the recommended path, Tailscale on this machine and on the phone.
1. Tailscale (recommended)
Section titled “1. Tailscale (recommended)”Works from anywhere, encrypted, nothing public, and the only path that gives the phone a secure (https) address, which installing the app and phone notifications both need.
-
Sign this machine and the phone into the same tailnet (
tailscale upon the machine). -
In your tailnet admin, enable MagicDNS and HTTPS certificates.
-
Start the board on all interfaces:
Terminal window uv run -m rev0.cli serve --with-runner --host 0.0.0.0 -
Open Settings > Workspace > Board address (or read the startup banner) and find the
https://<machine>.<tailnet>.ts.netaddress, labelled “secure, from your phone”. -
Open that address on the phone.
Result: the board loads on the phone with a real certificate, over Wi-Fi or cellular, and nothing is exposed publicly.
The board turns on tailscale serve by itself when it is bound off loopback and your
tailnet is up. If Tailscale is missing or signed out, it quietly falls back to plain http,
and the banner lists the Tailscale 100.x address (“Tailscale, from anywhere”) instead of
the https one. Control it with REV0_TAILSCALE_HTTPS:
| Value | What it does |
|---|---|
| unset (default) | serve (private tailnet https) when bound off loopback; off on localhost. |
serve | Private tailnet https, even on a loopback bind. |
funnel | Public https through Tailscale Funnel, for a phone that is not on your tailnet. Refused without an access token. |
off | Never touch Tailscale (use --ssl-keyfile and --ssl-certfile, or a reverse proxy). |
2. LAN (same Wi-Fi only)
Section titled “2. LAN (same Wi-Fi only)”-
Start the board on all interfaces:
Terminal window uv run -m rev0.cli serve --with-runner --host 0.0.0.0 -
Open Settings > Workspace > Board address, or read the startup banner:
rev0 is reachable at:http://192.168.1.143:8000 (same Wi-Fi / LAN)http://127.0.0.1:8000 (this machine) -
Open the “same Wi-Fi / LAN” address on a phone on the same network.
Result: the board loads on the phone over plain http. Use it only on a network you trust. Browsers do not allow installing the app or push notifications on a plain http address, so use Tailscale for those.
3. Public tunnel (highest risk)
Section titled “3. Public tunnel (highest risk)”A tunnel such as
Cloudflare Tunnel
or ngrok http 8000 gives a public https://... URL with no router config. The board does
not start one for you, and it cannot tell it is behind one: a tunnel to a board bound to
localhost starts without a token and is wide open. Set REV0_AUTH_TOKEN before you start
the tunnel, and ideally add an identity layer in front (for example Cloudflare Access).
Result: the board is reachable from anywhere, behind your token.
Sign in on the phone
Section titled “Sign in on the phone”- On this machine, open Settings > Security > Access token and click Copy.
- On the phone, open the board’s address. It shows Sign in.
- Paste the token into Access token and tap Sign in.
Result: the phone stays signed in for 30 days.
Install it as an app
Section titled “Install it as an app”- Open the board’s https address on the phone.
- On Android (Chrome), tap Install on the Install rev0 banner. On iPhone (Safari), the banner reads Add to Home Screen: tap the Share button, then Add to Home Screen.
Result: the board opens full screen from its home screen icon, like an app. Dismissing the banner hides it for 30 days; you can still install from the browser’s menu.
Turn on phone notifications
Section titled “Turn on phone notifications”- In the installed app, open Settings > Workspace > Browser notifications.
- Tick Enable notifications on this device and allow notifications when the phone asks.
Result: a plan to review, a question, a due result or a finished ticket reaches the phone even with the app closed; tapping one opens the ticket. On iPhone this only works in the installed app. More in Choose how the board notifies you.
How the token works
Section titled “How the token works”- Set it with
--auth-token, theREV0_AUTH_TOKENenvironment variable, or (recommended) aREV0_AUTH_TOKEN=...line in~/.rev0/.env, which is loaded on startup. Keeping it there keeps the start command free of the secret, and a server restart picks it back up by itself. Unset and bound to localhost means no auth, the zero config local behaviour. - The CLI, MCP server and in-process runner pick the token up from
REV0_AUTH_TOKENby themselves (sent asAuthorization: Bearer), soserve --with-runnerkeeps working with auth on. - Browsers sign in once at
/login; a cookie holding a hash of the token then rides every request, including the live/eventsstream. - HTTPS removes the “Connection is not secure” label. The easiest route is Tailscale, as
above. Without it, put Caddy (or another reverse proxy) in front with your own domain
and Let’s Encrypt (DNS-01 issues certificates even for a private LAN IP), which is also
browser-trusted with no per-device CA.
servestill accepts--ssl-keyfileand--ssl-certfile. Avoid self-signed or mkcert-style local CAs: phones reject them unless you install a root certificate on every device.
If something goes wrong
Section titled “If something goes wrong”Refusing to start: binding to a non-loopback host
Section titled “Refusing to start: binding to a non-loopback host”You started the board with --host 0.0.0.0 (or another network address) and no access
token. Set REV0_AUTH_TOKEN as in Before you begin and start again.
Incorrect token. Try again.
Section titled “Incorrect token. Try again.”The token you pasted is not the board’s. Copy it again from Settings > Security > Access token on this machine. If that section is missing, the board runs without a token.
The phone cannot reach the board
Section titled “The phone cannot reach the board”Check that the board was started with --host 0.0.0.0: bound to 127.0.0.1 it answers only
this machine. On the LAN path, check the phone is on the same Wi-Fi.
The token changed and the board still wants the old one
Section titled “The token changed and the board still wants the old one”The board reads ~/.rev0/.env when it starts, so restart it. Restart server is under
Settings > Advanced > Updates when a newer release is waiting on a source install, and
under Settings > Advanced > Board & debug when Debug tools is on; otherwise stop and
start serve yourself.
Related
Section titled “Related”- Choose how the board notifies you, to decide what reaches the phone.
- Security, for what the token protects.
- Install rev0, for the desktop app and the installer.