Devices

A device is a computer associated with a Metnos user on which remote executors can run. A small component called the Metnos client is installed on the device and communicates with the server. When an action must run on that computer, the server sends the client an authorised, signed request. If the required executor is not already present, the client downloads its signed version and verifies its integrity. It then runs the executor locally within the authorised limits, records the outcome, and returns the result to the server. The executor may remain in a verified cache for later executions.

Pairing and identity

To pair a new computer, the administrator gives it a recognisable name and selects its owning user. Metnos then creates a link that remains valid for a limited time and must be opened on the computer being paired. The client on that computer creates an Ed25519 cryptographic key pair: the private key stays on the device, while the server records the public key. A digital fingerprint derived from the public key lets the administrator check that Metnos is communicating with the expected device. Once pairing is complete, the temporary link expires; subsequent communications are authenticated with the keys.

A heartbeat is an automatic message that one program sends at regular intervals to tell another that it is still active. The Metnos client sends this message to the server every thirty seconds. It signs the message and includes the device identifier and a small technical profile, such as the operating system, architecture, client version, and available isolation level.

Whenever the server receives a valid heartbeat, it records the time. If the last message is recent, the page marks the device as reachable. This means that the client is running, the network connection works, and the server has verified its identity. It does not mean that every action can run. Metnos separately checks that the device is requesting work, the executor is compatible, and the required resources are available.

What “remote executor” means

An executor's properties are independent:

AxisAlternativesQuestion it answers
PlacementLocal or remoteOn which computer does execution take place?
ConcurrencySerial or parallelisable within a limitHow many independent invocations may proceed together?
ProcessingDeterministic or assisted by an LLM/VLMDoes the function use code and data only, or does it also use a model?
EffectPure, idempotent, reconcilable, or manualWhen may an interrupted attempt be repeated?

“Remote” therefore does not mean “intelligent”, and “local” does not mean “serial”. A remote executor may perform a deterministic read; a local executor may use a vision model. The central scheduler still applies authority, availability, and concurrency limits.

Install, inspect, and revoke

  1. Open Settings → System → Devices on the server.
  2. Choose Another PC, then assign a recognisable name and the correct owner.
  3. Open the link on the target computer and wait for the procedure to reach Client active.
  4. Check operating system, client version, fingerprint, last heartbeat, and state.
  5. Use Revoke if the computer is no longer trusted or must stop receiving invocations.

Revocation invalidates subsequent tokens from that device; it does not delete the owning user's data. A manual path is available for environments without a browser. It is intended for experienced operators and uses a short-lived token.

Network boundary. The device channel is intended for a local network or private overlay. Do not expose the client port directly to the public Internet.

The Devices screen

The real, anonymised Metnos remote-devices screen in an Italian-language instance.
When opened on the server, the page explicitly offers the procedure for installing the client on another computer.
  1. Devices section. Brings together pairing functions and remote-client status.
  2. Recommended flow. Guides installation without requiring terminal commands.
  3. Identity and owner. Name, ID, and user make device ownership explicit.
  4. Observable state. Version, fingerprint, heartbeat, and reachability help verify the client.
  5. Revocation. Deliberately removes the authority granted to the device.

The name, owner, ID, fingerprint, and timestamp are anonymous examples; the layout comes from the real web interface.