Pro help topics

User-operated connection

Remote bridge and security

  • Pro only
  • Android
  • Windows preview
  • Verified: Pro 1.3.0

What the bridge does

Remote mode connects SciREPL Pro to a SciREPL-MCP broker that you or someone you trust operates. The developer does not run a default broker. A compatible external client can then use the notebook tools that your app permissions allow.

Get SciREPL-MCP on GitHub and follow the installation and pairing guide.

Connect safely

  1. Start the broker and record its pairing token.
  2. In AI Assistant → gear → Remote bridge, enter the broker URL and token.
  3. Read and accept the Remote-data disclosure.
  4. Select Connect, then enable Remote in the Assistant panel.

Plain ws:// is accepted only for loopback addresses such as localhost. Other hosts require wss://. Tailscale Serve prints an https:// root; for the app connection, change the scheme to wss:// and append /app.

Terminal is broader than notebook tools

Terminal mode sends every keystroke and terminal output to the broker host and may expose a real shell there. Enable it only for a broker and host account you trust. Notebook tool permissions do not turn a host shell into a sandbox.

Notebook network controls

The network guardrail is on by default and applies allow/block rules to notebook-originated requests. With an empty allowlist, requests are denied rather than prompting before the privacy/security disclosure has been understood. Provider and saved-broker routes use their own scoped paths.

  • A policy block means SciREPL refused the destination under the effective settings.
  • Failed to fetch can instead mean CORS, DNS, TLS, offline state, or an unreachable server.
  • The optional isolated Android connection is a separate switch and is off by default.

The guardrail is not a sandbox. Notebook JavaScript shares the app’s page realm, and the guardrail is best-effort protection against mistakes. It does not establish a hostile-code security boundary.

Permissions and mixed sessions

Manual notebook code and agent-originated code can have separate allow/block lists. After both origins have executed in one page session, unattributed requests must satisfy both lists until reload. This is deliberately conservative because delayed callbacks do not carry reliable ownership.

Current limitations

  • Full-screen Agent cannot use Remote yet; it requires reviewed editor context and local draft tools that the Remote route does not carry.
  • Broker support varies by client and version. Keep app and broker documentation together when troubleshooting.
  • Termux/Tailscale loopback behaviour is device- and configuration-dependent.