How Drover fits around your agents.
Product guide
Drover is a native iPhone surface for work that remains inside official Herdr on your own machine. Drover for Mac and droverd for Linux are available now; the iPhone app is coming to the App Store. This guide describes the system boundaries.
The system model
- Drover for iPhone
- The native iOS 18+ interface for viewing state and sending supported input. Desk and iPad clients are deferred.
- Drover Host
droverd, the small companion daemon beside Herdr on macOS or Linux. Desk and iPad clients are deferred.- Herdr
- User-installed official Herdr, compatible with Drover’s capability floor. Drover does not bundle Herdr, create a direct PTY, or provide another runtime fallback.
- Cloud control plane
- Minimal signaling, short-lived relay credentials, generic push hints, and entitlement checks. Terminal payloads remain end-to-end encrypted.
Objects you navigate
Herdr owns the runtime hierarchy; Drover presents the same objects through a paired, authenticated surface:
Host→Session→Workspace → Tab → Pane
A pane opens only with a current exact live route. Unavailable, ended, and stale panes remain visible and read-only with an explanation. The verified hostname is always visible where host identity matters; a nickname never replaces it.
Terminal rendering
Herdr remains authoritative for the PTY, process, terminal history, and controller. The iPhone uses the native Ghostty Surface for VT state, input encoding, selection, accessibility, and rendering; Drover does not interpret terminal text.
Connection order
- LAN direct: local discovery and an encrypted direct session.
- WAN direct: peer-to-peer WebRTC when the network permits it.
- Managed TURN fallback: an encrypted blind relay when a direct path cannot be established.
Capability status
| Capability | Status | Boundary |
|---|---|---|
| Herdr topology | Shipped | Host → Session → Workspace → Tab → Pane. |
| Prompt / terminal input | Shipped | Exact pane route and current capability only. |
| Approvals (Claude Code, Codex) | Shipped | Inbox cards — Deny · Allow once · Open. Nothing auto-approves. |
| Repo (diffs and commit history) | On the roadmap | Reading an agent's diff and commit history from your phone. Not shipping at launch. |
| Off-network connectivity | Free | Direct WebRTC when possible, otherwise an end-to-end encrypted Cloudflare relay. Never gated behind Pro — free on your first paired host. |
| A second host and beyond | Drover Pro | Free covers one paired host. Every additional host needs an active Drover Pro subscription. |
| Push notifications + Live Activity | Drover Pro | The alert when an agent needs you or finishes, and the Live Activity. |
| Other engines (OpenCode, Gemini CLI, shells) | Terminal only | Live terminal panes with no alerts or approvals for these engines. |
| Interrupt / stop a running agent | Typed input | Drover adds no stop or interrupt button. The terminal key row sends ctrl like your desk keyboard, so ctrl-C reaches the agent as typed input, the same as any terminal. |
Coming next
Not at launch, but on the roadmap — no dates set:
- Repo. Review an agent's diff and commit history from your phone, read-only, without taking custody of your workspace.
Roadmap features will be part of Drover Pro when they ship.
Where to go next
Keep your agents within reach.
Drover for Mac and Linux are available now. The iPhone app is coming to the App Store.