Optional extension trust sheet
Add RemoteEndpoints to LocalEndpoint Connect
Review a protected request away from your PC. RemoteEndpoints needs a separate account, extension setup, and local enablement. Every protected action still waits for the current policy and visible decision on your PC. Current-package live remote proof remains open.
Integration boundary
Remote review is optional. Local approval still decides.
Core local chat, models, memory, and on-device approvals need no RemoteEndpoints account or extension. Add it only when away-from-PC review fits your workflow.
- Setup available
- Separate account
- Local approval required
- Current live proof open
- Adds
- Protected request review while you are away, not unrestricted remote control.
- Works without it
- All core local use remains account-free after the app and model files are present.
- Destination
- RemoteEndpoints.com, only after separate setup, sign-in, and local enablement.
- What may leave
- Remote-workflow data for the protected request. The current catalog does not publish a field-level payload inventory.
- Credentials
- Website authentication uses its dedicated sign-in flow. LocalEndpoint Connect does not collect or store the website password.
- Authority
- Selection, sign-in, and enablement do not approve an action. Exact session, hash, target, expiry, capability, and current local policy still bind each instruction.
Four deliberate steps
Set up RemoteEndpoints in four deliberate steps.
Review the boundary before adding the setup file. Nothing on this public page can approve a request on your computer.
- 01Install or update Connect
Use the checksum-backed Windows build, then open
Get LocalEndpoint ConnectSettings > Plugins. - 02Add the extension
Save the accepted template as
Download setup fileremoteendpoints.com.plugin.json, refresh plugins, and confirm its identity. - 03Sign in, then enable locally
Use the separate service flow, then enable Remote access on this PC only when you intend to receive requests.
Open the connection guide - 04Send one bounded test
Confirm the visible request, exact target, expiration, and local decision before relying on the workflow.
The setup file selects the extension for local intake; it does not connect an account, enable hosted access, or approve runtime work.
Evidence, not a badge
Historical proof, current gates.
The latest bounded dispatch proof is historical, not a current-package live round trip. Version 0.2.241.0 passed dogfood with a simulated authenticated plugin session: one exact instruction-hash-bound request completed after one local approval, then the same request was rejected after the remote, command, and desktop gates were disabled. That proof was not rerun for current version 0.2.242.0.
Evidence supports
- One bounded, simulated authenticated-session dispatch
- Exact instruction hash and one local approval
- Denial after the local gates were disabled
Still open
- No live production remote-session round trip
- No current-package dispatch rerun
- No keyboard, hotkey, pointer, or click execution proof
- Production signing and clean-machine qualification remain open
Stop locally: turn off Remote access or disable the extension in Settings. Emergency stop revokes active local grants; a separate server-side disconnect workflow is not documented here.
Ownership: RemoteEndpoints.com is a related first-party service. This is product-owned integration documentation, not an independent security audit.
Setup-file details and technical references
The template includes enabled and userApproved values for accepted local intake. They do not prove a connection or grant action authority. Its installedUtc value is template metadata, not this device's connection time.