Skip to content

Pairing devices

Offsite has no account, so there is nothing to log in to. A device gets access to a host by being authorised on that host, once, by you.

  1. In the Mac app, open the host’s menu and choose Show iPhone QR.
  2. Point the iPhone’s Offsite app at the code on the Scan on iPhone sheet.

That transfers the host’s address and its pairing material. From then on the phone connects on its own, over whichever path is reachable.

Passwords are never in the QR code. What it carries is the host’s address and a one-time enrolment token; the device’s own key is what authorises it afterwards.

QR tokens are single-use. A code that already paired one device will not pair a second one — show a fresh QR for each device.

They are also invalidated when the host’s agent restarts, so a screenshot of a QR code from last week is not a credential lying around.

The usual cause is an already-used code. Show a fresh one from the Mac app (the host’s menu → Show iPhone QR) and scan that.

An error mentioning Remote Login is misleading on a current host: Remote Login is not involved in normal operation, and the message almost always means this device is not authorised yet.

Each device pairs with each host separately. Pairing your iPhone with the Mac at home says nothing about the VPS — scan that host’s QR too.

  • Enrolment is redeemed by the host’s own agent, on-device, whichever path the connection arrived on. Authorisation no longer depends on the relay being enabled.
  • Devices are recorded in ~/.offsite/devices.json on the host, together with their per-device notification settings.
  • Pairing material is pinned per host on the client; a host key that changes — for example after a VPS rebuild — is a deliberate re-confirmation, not a silent reconnect.
  • Scan the QR from inside the Offsite app, which reads the pairing payload directly.