Set up remote screen access
Remote screen access is a Legend feature. Before connecting, tokenstat checks that both devices are signed in and paired, the host is online, the requesting device has an explicit grant, the operating-system capture permission is enabled, and incoming files have a destination.
On the host, open Devices → Screen access and enable View for the requesting device. Enable Control only when that device should send pointer and keyboard input. View-only access needs Screen Recording on macOS. It does not need Accessibility. Control additionally needs Accessibility.
If access has not been granted, the viewer can send a fixed, content-free request. The notification contains no screen image, window title, filename, command, or user-entered text. It asks the host owner to open tokenstat and review the per-device permission card.
The session is encrypted between the two device identities. A direct connection is used when possible. Otherwise the relay forwards encrypted bytes it cannot decrypt. Closing the viewer ends its session. Revoking View immediately ends screen and file-transfer access for that device, while revoking Control leaves view-only access intact.
A direct connection does not use the hosted relay. tokenstat tries a direct path first. When the relay is needed, all relayed traffic shares one rolling 30-day allowance: 100 MiB on Free, 1 GiB on Supporter, 5 GiB on Patron, and 20 GiB on Legend. The window is today plus the previous 29 UTC days. Older usage leaves the window as those days pass. This is not a daily refill. Remote screen remains Legend-only, one relayed screen session at a time, and up to ten minutes per relayed session before reconnecting. See pricing and the terms.
Incoming files default to Downloads/tokenstat on macOS and Android and the Files-visible tokenstat folder on iPhone and iPad. You can choose another destination before receiving anything.
More in Desktop app
