Clawnet refactor (protocol + auth unification)

Clawnet refactor (protocol + auth unification)

Scope

This page is a placeholder generated from the official source file structure.

What to verify

  • TODO: Add prerequisites and validation checklist.

Outline (from official headings)

  • Hi
  • Purpose
  • Goals (from discussion)
  • Non‑goals (explicit)
  • Two protocols
    1. Gateway WebSocket (control plane)
    1. Bridge (node transport)
  • Control plane clients today
  • Nodes today
  • Current approval flow (exec)
  • Presence + identity today
  • One protocol, two roles
  • Role behaviors
  • Key rule
  • Client identity
  • Pairing flow (unified)
  • Device‑bound auth (avoid bearer token replay)
  • Silent approval (SSH heuristic)
  • Reuse existing bridge TLS
  • Apply to WS

Further reading

  • Official source file: refactor/clawnet.md