Skip to content
Historical revision — this record as it stood on 1 July 2026, not the current version. View the current record →

How to pair a new device

Pairing a device registers it with the platform using machine-based authorization — a cryptographic handshake that binds access to your hardware rather than to a username and password. Once a device is paired, it holds the keys required to establish connections. A device without a pairing has no pathway to the protected resources at all — not access-denied, but structurally unreachable.

For the theory behind this model, see machine-based-auth and pairing-as-permission.

Prerequisites

  • A PointSav account with at least P3 access (see personnel-permissions)
  • The os-console application installed on the device you are pairing
  • Network access to the Command endpoint assigned to your account

Steps

1. Open the pairing request from os-console

Launch os-console on the new device and navigate to Settings → Devices → Pair this device. The console generates a temporary pairing code — a short, human-readable string that is valid for 10 minutes.

2. Approve the pairing on a trusted device

On a device already paired to your account (your INPUT-tier daily machine), open os-console and navigate to Settings → Devices → Pending pairings. The new device's pairing code and hardware fingerprint appear here.

Verify that the fingerprint shown on the new device matches the fingerprint shown on your trusted device before approving. This cross-check prevents a rogue device from inserting itself.

3. Select the pairing type

Choose the access tier for the new device:

Tier What it can do
INPUT Full read/write access to your archives and data — use for your daily machine
USER Read-only access — use for shared or secondary devices
INTERFACE Metadata only — use for orchestration and monitoring integrations

ADMIN pairings require the approval of the system administrator and cannot be self-issued.

4. Confirm and complete

Approve the pairing from your trusted device. The new device's os-console refreshes automatically and the Totebox session becomes available. The pairing event is recorded to the audit ledger immediately.

Verify the pairing

On the new device, open os-console and navigate to Settings → Devices → This device. The device status should show Paired with the tier you selected and the timestamp of the pairing event.

Run a test read-operation on any archive to confirm connectivity.

Revoke a pairing

To remove a device from your account, navigate to Settings → Devices on any paired device, select the target device, and choose Revoke. The revoked device becomes mutually invisible to your resources immediately — no logout or TTL wait is required.

Key takeaways

  • The pairing IS the permission; there is no central access-control list to update
  • Always verify the hardware fingerprint cross-check before approving a new pairing
  • INPUT pairings grant full read/write access — assign them to machines you control directly
  • Revocation is immediate and hardware-level; no session or token expiry needed

See also

Important Information

Important Information

Corporate structure. PointSav Digital Systems ("PointSav") is a trade name of Woodfine Capital Projects Inc. ("Woodfine"). PointSav does not itself offer, sell, or solicit any security. Any securities offering associated with Woodfine's real-property direct-hold solutions is made exclusively by Woodfine, and only by means of the applicable Private Placement Memorandum.

No investment advice. This wiki's content is provided for engineering, operational, research, and development purposes. Nothing on this wiki constitutes investment advice or a solicitation to invest in any Woodfine partnership or direct-hold solution.

Intellectual property. The PointSav name, trade name, wordmark, and marks, together with all current and future PointSav- and Totebox-branded products, services, and offerings — and the software, source code, documentation, design system, and all related materials — are proprietary to Woodfine and its affiliates, except for components identified as open source. No rights are granted except as expressly set out in a written license or agreement. See TRADEMARK.md in this repository for the full trademark notice.

Open source components. Portions of the platform are made available under permissive open-source licenses identified in the accompanying repository. Use of those components is governed by their respective license terms.

No warranty; informational use. Content on this wiki is provided for general informational purposes only and does not constitute a representation, warranty, or commitment with respect to product functionality, availability, pricing, or roadmap. Some articles describe planned or intended features, capabilities, and milestones — language such as "planned," "intended," "targeted," "may," and "expected" marks this forward-looking content, which is subject to change and does not constitute a commitment regarding future performance.

Confidentiality. Where an article describes an operational or deployment detail that is not intended for public disclosure, that article is not published on this wiki. Content here is general-purpose engineering documentation, not customer-specific configuration.

Jurisdiction. Woodfine Capital Projects Inc. is organized in British Columbia, Canada. References to the Sovereign Data Foundation on this wiki describe a planned or intended initiative only, not a current equity holder or active governance body.

Changes to this notice. PointSav may update this notice from time to time; the version posted on this page governs.

Not a filing system. This wiki is not a securities filing system, an electronic disclosure repository, or a substitute for SEDAR+ or any other regulatory filing system. Formal securities filings are made through the applicable regulatory filing system, not through this wiki.

Full disclaimer. This notice supplements, and does not replace, the full Disclaimers article. In the event of any conflict, the full Disclaimers article governs.

Read the full disclaimer →