Current unattended-control contract
Start device authorization in Connect, confirm the short code in an authenticated browser, exchange the one-time access token, and register the extension installation for a durable revocable device credential.
After enrollment, Connect checks in, uploads private desktop pictures, atomically leases prompts, reports strict command-state transitions, receives stop signals, and survives normal browser or Connect restarts without another target-side handoff.
While one command is running, Connect polls /work-items?control_only=1. That exact authenticated mode returns stop requests and the current extension, account, and effective authority gates without claiming the next queued prompt.
Historical implementation evidence (version-specific)
LocalEndpoint Connect accepts authenticated prompts from an enabled RemoteEndpoints extension, plans work with its local AI, and uses its Windows desktop-control lanes to operate programs, browser sessions, pointer input, keyboard input, and the network available to the signed-in Windows account. Exact capabilities depend on the installed Connect build and Windows session state.
This first-party documentation is not an independent audit or certification. Do not infer current package compatibility from historical evidence unless that package has been retested.