Hash-only credentials
Device credentials and reservation correlation data are stored as hashes or safe summaries. Raw device credentials are returned only once where existing APIs intentionally do so.
Security
Runmote combines bounded metadata, explicit ownership checks, encrypted private task content, strict generic envelopes, and server-side duplicate suppression.
Device credentials and reservation correlation data are stored as hashes or safe summaries. Raw device credentials are returned only once where existing APIs intentionally do so.
Strict agent-task envelopes reject malformed or unknown fields while preserving prompt and report text without coding-semantic interpretation.
Normal users see safe device lifecycle fields. Admin APIs expose sensitive client metadata only to users with the explicit permission.
The owner-selected workspace and Codex sandbox remain local. Runmote creates no extra file-plan or execution approval ceremony.