Menlo on iPhone
Menlo on iPhone is the private intent client for your Mac. The Mac remains the factory and Xcode build machine.
Set up for creation
Section titled “Set up for creation”Run menloapp or menloapp setup on the Mac with the intended iPhone connected and unlocked. Setup observes Xcode, Apple signing, Trust, and Developer Mode, installs and launches Menlo, then completes its private pairing. Installation alone is not completed pairing.
If you arrived for a specific linked app, that app installs first. Menlo on iPhone is optional afterward. Existing libraries remain accessible while pairing is incomplete or the phone is away.
Send a request
Section titled “Send a request”Use One Shot for a new app or Evolve App for a change. Requests can include text, native speech transcription, and up to eight PNG/JPEG references. The SDK persists signed commands and encrypted outbox bytes before send returns. An offline phone or sleeping Mac leaves a queued request, not an invented build result.
The Mac admits the authenticated request against its exact base, executes the bounded coding route, and applies real Xcode, signing, and delivery checks. Menlo on iPhone shows the resulting status and active-client update information.
Private connection
Section titled “Private connection”The content-blind relay transports encrypted envelopes without source, Apple signing identity, or command authority. Initial pairing uses an encrypted, signed, one-use invitation. It finishes after the Mac accepts the proof and publishes an authenticated snapshot.
The Mac can rename or revoke a paired device. Revoked commands fail admission even if old ciphertext remains in transport.
The visible iPhone app name is Menlo. Its com.tohseno.companion bundle identity, private data, DeviceKey, and pairing protocol retain continuity during upgrades.
Historical public authority
Section titled “Historical public authority”The retained Registry path uses the non-exportable Builder DeviceKey for exact public actions. Companion recomputes structured digests before explicit approval. Historical Claim gestures become Claims only after canonical chain evidence.
Ordinary GitHub deploy and app acquisition require no Companion publication signature or Claim ritual. Historical Registry rules remain separate.