Hello~! pocketty is an SSH terminal for iPhone and iPad, made for herdr. herdr keeps your agent panes alive on your computer and knows the state of each one: working, needs you, or done.
I made this in anger/desperation for the latter half of my recent paternity leave. Nap traps are sweet, but there's only so much doom-scrolling and movie-watching I can handle... In any event, I've been using it for the last couple months and no longer have to be my desk anymore to be productive. Now the nap-traps are still productive (when i want them to be) !
How it works:
- The app talks to your computer directly over plain SSH. Tailscale is the easy way to reach it from anywhere but any SSH host you can reach works.
- A small Rust daemon on the host watches herdr. When a pane needs you, it seals the alert to your phone's key with HPKE (X25519, ChaCha20-Poly1305). A stateless relay (pocketty's) on Cloudflare Workers passes the sealed bytes to APNs (Apple Push Notification servers), and a notification extension opens them on the phone. The relay can't read them and keeps nothing.
- Your SSH key is made in the Secure Enclave and can't be exported.
- The terminal uses libghostty-vt for state and draws with wgpu on Metal, so full-screen TUIs look like they do on your desk, albeit narrower.
- Diffs for each agent turn, a file browser, and previews of `localhost` dev servers your agent starts, all through the same SSH connection. No port forwarding to set up.
herdr and the daemon are optional. Without them, it's a normal SSH client.
There's no account to set up and no analytics or tracking in the app. The app runs a 14-day free trial, with full feature access. Then, if you're as happy as I am with it, then it can be yours forever with a one-time purchase: $99 for the first two weeks (launch promo) then $129 after that.
Happy to answer anything about the sealed push setup or running libghostty on iOS.
antoniomika44 minutes ago
Was looking for something like this but stumbled upon herdr-web-ui [0] first. They seem to do the same thing, but herdr-web-ui is completely free and self hosted and sets up as a PWA with webpush support. Seems to work decently well and it’s under heavy development. Will have to try this too!
sailfastan hour ago
Nice! I did something like this running tailscale to my laptop with a TUI and it worked well for awhile. And then I realized I didn't want to be notified when my agents weren't working because I'd had enough.
Enjoy your nap traps! They don't last very long.
lukeedopan hour ago
Thank you <3 These days, it's mostly for walks or errands or random a-ha moments. The nice part about trusting the notifications & the pipeline is that I don't have to babysit my agents at all & can just focus on the baby~
11235813215 hours ago
Neat. Thought about syncing the key with iCloud Keychain towards supporting any of the user’s devices connecting? Optionally; I understand the appeal of the current storage method.
lukeedop5 hours ago
Thanks! Perhaps we have different trust levels, but I prefer to have an ssh key per service/identity/device so that I can revoke specific items as needed. Plus, getting the key onto the host device is automated once you have the sibling daemon (brew install lukeed/tap/pocketty) running. It just takes a device-pairing code, much like adding a new Apple device to your iCloud acct
lukeedop5 hours ago
That said, if this is a requirement I can definitely look into adding it... optionally, as you said :)
1123581321an hour ago
Thanks. Just something to consider! You’re right that it wouldn’t be a big deal to add two or three devices individually.
worldisaduck3 hours ago
right after connecting to my workstation it says: “herdr is not installed on this host” while it clearly is. Running it in shell directly works, but it’s impossible to scroll inside herdr session like that. What exactly should I pay 99 for?
lukeedop2 hours ago
Are you running fish shell? If so, this was fixed and waiting on AppStore approval to release it.
Let me remind you that this is/was my ironclad setup. It should work for others, but may not due to preferential or not-my-machine technical reasons. The latter is solved by bug reports. Either way, there's a free trial and you pay nothing & shouldn't unless you like it.