Miblo 1.24.0
Released
Sem o aparelho
- The Miblo gadget is optional. Miblo installs and runs without one: the Miblo app, the pet and your sessions' status (on your phone too, with a free Miblo account) work on their own, and Miblo+ stays the paid plan. What a gadget adds is a screen on your desk, the pet at your desk, and visits between Miblos. A computer can be linked to your Miblo account with no gadget at all.
- Pairing is a step you can skip. The installers (
install.sh,install.ps1, "Install Miblo.command") ask "Have a Miblo on your desk?": Return pairs it now,l(ordin Portuguese) leaves it for later. The Miblo app asks the same at the end of the install (Pair now / Later).--no-pairstill skips the question. - No Miblo answering is never an error. When nothing answers on your network, the pairing wizard says the gadget is optional and finishes (Esc in the picker, Return in the plain questions;
rsearches again), and the installers end normally with how to pair one later./miblo:pairandmiblo pair --wizardwork as before. - Empty states instead of errors. With no Miblo paired, the app's My Miblos says "No Miblo paired" with Add a Miblo,
miblo statusand/miblo:statussay the same in one line, and the app's Now tab, the status line and the hooks work as usual. The Claude Code start-of-session note about pairing is shown once, and says the gadget is optional (it used to come back every day).
Linking the account (audit 2026-10-08)
- An AI agent can no longer link this computer to a Miblo account or unlink it. The account decides which phones may join this computer, so
miblo account linkandmiblo account unlink(and so switching accounts) are refused under an AI agent;/miblo:plusnow tells you the command to run in your own terminal (or Sign in with your Miblo account in the Miblo app) instead of running it. - With a Miblo paired, a change of account needs the code on its screen, as
miblo server setalready does. Linking asks for it once you confirmed the link code on miblo.ai, names the account about to be linked, and writes nothing before it (a refused link gives its token back to the site). Unlinking asks for it too. In the Miblo app you type the code on the Phone screen; from elsewhere,miblo account confirm <code>finishes it. No longer have that Miblo? Forget it in My Miblos and link again. - With no Miblo paired, linking still needs your own terminal or the Miblo app, the site asks your second factor again when you confirm the code, and your account gets a security e-mail for every computer linked or unlinked, with its name ("computer linked" / "computer unlinked", within the account's hourly notice budget). Unlinking still takes the account's phones off this computer.
A tela do Miblo no app
- The Miblo's screen, live, in the Miblo app. The Now tab shows the Miblo's screen as it is right now: your sessions, the limit rings, "needs you", the quiet Desk, pet mode and the greetings. It is the gadget's own screen code (built from the firmware as WebAssembly), so it behaves exactly like the gadget. It wears the look of your first paired Miblo, My pet included, or the factory look when you have no Miblo. It follows the app's language and your computer's time zone.
- No gadget needed. The screen in the app works the same with or without a Miblo on your desk. With a Miblo paired, the app reads its look from it every few minutes, only while the app asks.
- Light on the computer. The screen draws 10 frames a second only while the Now tab is on screen, and stops while the window is hidden or another tab is open.
- What the app's screen does not show: Wi-Fi and pairing screens, updates, visits between Miblos, and what reaches the gadget through its own commands (focus, timer,
/miblo:say, reminders, meeting mode). See [docs/screen-in-app.md](../screen-in-app.md). - For tools:
miblo status --screenadds the snapshot the gadgets get and the first Miblo's look (plainmiblo statusis unchanged). Firmware developers:make screenwebbuilds the module (emcc 6.0.10) and tests it.
Responder pelo celular em todas as IAs
"Você responde pelo celular. Se a sessão está trabalhando, a resposta entra quando ela termina a vez; se está parada, ela acorda e responde." No channel to accept, no new window, no system dialog.
- Every AI tool Miblo shows takes replies from the phone (Miblo+). A reply typed while a session works goes in when it finishes its turn, through each tool's own end-of-turn hook: Claude Code, Codex, GitHub Copilot CLI, Gemini CLI and Cursor. The phone says "Entra quando a sessão terminar a vez", then "Entregue".
- An idle session wakes up and answers. Claude Code (a background hook that wakes the session), Codex (
codex queue) and OpenCode (Miblo's OpenCode plugin) through their official ways. Copilot CLI, Gemini CLI and Cursor have none: when the session runs in tmux or GNU screen, Miblo types the reply into its own terminal after checking that the session is the one in front; otherwise it goes in at the next turn end. - Approvals from the phone for Codex and OpenCode, as for Claude Code: only the prompts the tool itself shows, never anything it would not have asked. Copilot CLI, Gemini CLI and Cursor keep their own flow (status and replies).
- Remote tasks continue from the phone. Answer a Claude Code task and it goes on, still in the background, with the same safe mode, time limit and Stop;
miblo plus tasks open <id>(and the app's Abrir) opens it in your terminal where it stopped. - Fixed: remote Claude Code tasks inherited a marker of the session that started Miblo's bridge and could run without saving their transcript.
- Every reply is shown on the computer (the gadget and a notification naming the phone) and kept in
miblo plus audit. After updating, runmiblo setup codexagain (or let the bridge add it) and trust Miblo's two new hooks in Codex's/hooks; restart OpenCode, Copilot CLI, Gemini CLI and Cursor sessions to pick up the new hooks. Claude Code sessions started before the update keep the old reply channel.
Pareamento protegido na rede local
- The pairing code never goes on the network any more (audit 2026-10-08, M1). Pairing a Miblo now runs a password-authenticated key exchange with the 4-digit code on its screen: your computer and the Miblo prove to each other that they know the code without ever sending it, and the pairing token is worked out on both sides, never sent either. Someone else on the same Wi-Fi who intercepts the pairing gets one guess at the code per attempt, counted by the Miblo's wrong-code lockout, and nothing they can study afterwards. The token signs every request from the first one (no rotation needed).
- Firmware 1.24.0 only pairs this way. An older Miblo app or plugin can no longer pair it: update Miblo on that computer first. Pairings you already have keep working as they are.
- A Miblo on an older firmware is updated first, in the same step. Miblo never falls back to sending the code in clear. When you pair a Miblo still on 1.23 or older (
/miblo:pair,miblo pair, the installers' pairing step), Miblo says "This Miblo is on 1.23: updating it first", pairs it the old way only to run the update at once (the signed release, the update code on its screen), then asks for the new pairing code and pairs it the protected way, in the place of that temporary pairing. If the update cannot run (no internet, no firmware for that board, you stop), the temporary pairing is dropped and nothing stays paired on the computer (the Miblo's settings page may still list it until you remove it there). A Miblo once seen pairing the protected way is never paired the old way again from that computer. - For tools: on that path
miblo pair <ip> <code>ends with exit code 5 (type the update code:miblo pair <ip> --update <code>, which ends with 6 once updated), andmiblo pair <ip> --update-cancelgives up;/api/infoand the mDNS TXT advertisepair: 2/pv=2. Details in [docs/lan-pairing-pake.md](../lan-pairing-pake.md).
Fixes/Segurança
- Security audit 2026-10-08, the computer-side Lows:
plus.json's signature now also covers the history, the approval timeout and the task time limit (aplus.jsonfrom 1.21-1.23 keeps its switches;miblo plus statusnames the three to confirm again, once, with onemiblo plus set …on your phone); the bridge reads at most one body per challenge and refuses an oversized one before reading it; "Parar" also stops what a remote task started outside its process group (setsid), and on Windows stops the whole tree from the first step;approvals.logis signed and chained, checked by the newmiblo plus audit verify;miblo update rollbackis refused under an AI agent; redaction also hides long random tokens, a hex key after a secret word,password Xin a command and the values a tool gives under secret-named keys.