A detached smith serves any frontend — browser, attached TUI, editor, programmatic client — over one protocol.
Remote access is safe by default; unauthenticated remote control of an agent is remote code execution and is treated as such.
Protocol
One frontend protocol: smith-ui semantic intents plus a control channel (submit, abort, subscribe, queue).
Transports are pluggable carriers — websocket, p2p stream, stdio — and never change the vocabulary.
Degradation law applies per intent across every transport.
Frontends are clients; the daemon owns sessions, credentials, and the agent loop.
Daemon
The daemon is a detached smith embedding the same core crates as every interface mode.
It binds loopback by default.
Off-loopback binding requires a pairing token: one bearer secret per daemon, presented by every connection, revoked by restart.
Smith core contains no user management; richer authentication is plugin-contributed, gated by grants.
Topologies
Hub: many clients attach to one daemon; viewers and drivers share one running agent.
Roaming: one client switches between running daemons.
Fleet: many clients and many daemons act as one smith through session-home ownership (specified in the fleet spec).
Connection model
Connections authenticate with the pairing token before any control command.
Permissions are per connection: a connection is viewer or driver.
Every session event stream carries sequence numbers; reconnecting clients resume from last seen.
Per-connection backpressure follows the degradation law: progress drops, transcript persists.
Acceptance criteria
A daemon started with defaults is unreachable off-loopback.
Off-loopback daemons reject unauthenticated connections before any protocol processing.
A reconnecting client resumes a live turn from its last seen sequence without losing transcript entries.
Two attached clients see one coherent event stream; only a driver can submit or abort.
No credential material crosses any transport.
The same frontend works unchanged against websocket and p2p transports.
---
id: SMH-SPEC-RMTF0001
type: spec
title: "Remote Frontends"
---
# Remote Frontends
## Intent
A detached smith serves any frontend — browser, attached TUI, editor, programmatic client — over one protocol.
Remote access is safe by default; unauthenticated remote control of an agent is remote code execution and is treated as such.
## Protocol
One frontend protocol: `smith-ui` semantic intents plus a control channel (submit, abort, subscribe, queue).
Transports are pluggable carriers — websocket, p2p stream, stdio — and never change the vocabulary.
Degradation law applies per intent across every transport.
Frontends are clients; the daemon owns sessions, credentials, and the agent loop.
## Daemon
The daemon is a detached smith embedding the same core crates as every interface mode.
It binds loopback by default.
Off-loopback binding requires a pairing token: one bearer secret per daemon, presented by every connection, revoked by restart.
Smith core contains no user management; richer authentication is plugin-contributed, gated by grants.
## Topologies
- Hub: many clients attach to one daemon; viewers and drivers share one running agent.
- Roaming: one client switches between running daemons.
- Fleet: many clients and many daemons act as one smith through session-home ownership (specified in the fleet spec).
## Connection model
- Connections authenticate with the pairing token before any control command.
- Permissions are per connection: a connection is viewer or driver.
- Every session event stream carries sequence numbers; reconnecting clients resume from last seen.
- Per-connection backpressure follows the degradation law: progress drops, transcript persists.
## Acceptance criteria
- A daemon started with defaults is unreachable off-loopback.
- Off-loopback daemons reject unauthenticated connections before any protocol processing.
- A reconnecting client resumes a live turn from its last seen sequence without losing transcript entries.
- Two attached clients see one coherent event stream; only a driver can submit or abort.
- No credential material crosses any transport.
- The same frontend works unchanged against websocket and p2p transports.