Security & consent — eyes and hands, owner-controlled
Every API session requires explicit rig-owner consent. Traffic uses TLS/WSS to the gateway and DTLS-SRTP for Live View media. We meter and audit sessions — we don’t ship a Glasswarp back-office screen feed.
Owner consent per-rig
API access must be explicitly enabled per-rig by the machine owner. No silent access, no ambient permissions. An on-screen “API session active” indicator shows during sessions.
Kill switch & audit
Owners can kill any session from the console. Every session is logged with timestamps and metering. Live View is an owner console action — not a Glasswarp staff feed.
Scoped API keys
Keys can be scoped to specific rigs and capabilities. Revoke instantly from the developer console.
Encrypted in transit
REST and host links use TLS/WSS. Optional Live View media is DTLS-SRTP between host and viewer. Screenshot and input bytes are handled transiently to fulfill agent calls — not sold as a recording archive.