How Drover fits around your agents.

Product guide

Drover is a native iPhone surface for work that remains inside official Herdr on your own machine. Drover for Mac and droverd for Linux are available now; the iPhone app is coming to the App Store. This guide describes the system boundaries.

The system model

Drover for iPhone
The native iOS 18+ interface for viewing state and sending supported input. Desk and iPad clients are deferred.
Drover Host
droverd, the small companion daemon beside Herdr on macOS or Linux. Desk and iPad clients are deferred.
Herdr
User-installed official Herdr, compatible with Drover’s capability floor. Drover does not bundle Herdr, create a direct PTY, or provide another runtime fallback.
Cloud control plane
Minimal signaling, short-lived relay credentials, generic push hints, and entitlement checks. Terminal payloads remain end-to-end encrypted.

Objects you navigate

Herdr owns the runtime hierarchy; Drover presents the same objects through a paired, authenticated surface:

Host→Session→Workspace → Tab → Pane

A pane opens only with a current exact live route. Unavailable, ended, and stale panes remain visible and read-only with an explanation. The verified hostname is always visible where host identity matters; a nickname never replaces it.

Terminal rendering

Herdr remains authoritative for the PTY, process, terminal history, and controller. The iPhone uses the native Ghostty Surface for VT state, input encoding, selection, accessibility, and rendering; Drover does not interpret terminal text.

Connection order

  1. LAN direct: local discovery and an encrypted direct session.
  2. WAN direct: peer-to-peer WebRTC when the network permits it.
  3. Managed TURN fallback: an encrypted blind relay when a direct path cannot be established.

Capability status

Drover capability status
CapabilityStatusBoundary
Herdr topologyShippedHost → Session → Workspace → Tab → Pane.
Prompt / terminal inputShippedExact pane route and current capability only.
Approvals (Claude Code, Codex)ShippedInbox cards — Deny · Allow once · Open. Nothing auto-approves.
Repo (diffs and commit history)On the roadmapReading an agent's diff and commit history from your phone. Not shipping at launch.
Off-network connectivityFreeDirect WebRTC when possible, otherwise an end-to-end encrypted Cloudflare relay. Never gated behind Pro — free on your first paired host.
A second host and beyondDrover ProFree covers one paired host. Every additional host needs an active Drover Pro subscription.
Push notifications + Live ActivityDrover ProThe alert when an agent needs you or finishes, and the Live Activity.
Other engines (OpenCode, Gemini CLI, shells)Terminal onlyLive terminal panes with no alerts or approvals for these engines.
Interrupt / stop a running agentTyped inputDrover adds no stop or interrupt button. The terminal key row sends ctrl like your desk keyboard, so ctrl-C reaches the agent as typed input, the same as any terminal.

Coming next

Not at launch, but on the roadmap — no dates set:

  • Repo. Review an agent's diff and commit history from your phone, read-only, without taking custody of your workspace.

Roadmap features will be part of Drover Pro when they ship.

Where to go next

Keep your agents within reach.

Drover for Mac and Linux are available now. The iPhone app is coming to the App Store.

Get Drover