The iPhone app
bnw_node::embedded::spawn(data_dir, identity, config) runs a node on its own thread inside another process and returns a NodeHandle:
request("node-status", json!({}))takes the same operations and JSON as the web gateway;events()gives the live events the web client streams;shutdown()stops the node.
The host supplies the device key, for example from the iOS Keychain, so the node never reads a key file.
The mobile app runs the node with role: NodeRole::Companion and local_sockets: false. A companion is a real device of its account: it syncs, messages, pairs, and decides approvals with its own key. It runs no agents, executes no provider requests, answers no searches, and refuses provider and agent-hosting operations. Those stay on a computer, and the phone manages them.
bnw-node builds for aarch64-apple-ios and aarch64-apple-ios-sim. Android needs the NDK and a rustls TLS backend first.
The iPhone app
Section titled “The iPhone app”apps/bnw-ios is the consumer app: native SwiftUI after the design in design/. Its Rust side is crates/bnw-ffi, which exposes the embedded companion node to Swift through UniFFI with four calls:
start(dataDir, secret, relays);request(op, json), with the web gateway’s operations and JSON;subscribe(listener)for live events;stop().
The device key lives in the iOS Keychain (this device only, after first unlock), and the app loads nothing remote.
scripts/build-ios-core.sh # Rust core → apps/bnw-ios/Core (XCFramework + Swift bindings)cd apps/bnw-ios && xcodegen generate # Xcode project from project.ymlopen BNW.xcodeproj # run on a simulator or a connected iPhoneAdding the phone to your account:
- On the computer, run
bnw account pair, or use the web client’s Account → Add a device. - Scan its QR code in the app, or with the iPhone’s Camera. Tapping a
bnw:pair/…link opens the app with it filled in. - Tap Join.
- The computer lists the phone as asking to join, with its matching code. On the computer that holds the account key, check the code matches the phone’s and press Confirm in the web client’s Account card.
The Confirm button signs with the account key in the node’s data directory. Only the node itself can use it, never a hosted agent acting through it, and only for a device that asked to join this account. bnw account authorize-device <phone> does the same from the command line, and can also authorize a device before it asks.
Once it’s a member, the phone:
-
Home: your node’s state, what needs you, your agents, and live activity.
-
Network: how it is reachable, its relay, and who it is connected to.
-
Messages:
- direct messages and channels;
- a new-message menu: message a contact, create a channel, or open a contact or channel link;
- Join buttons on channel links;
@suggestions in the message box, with agents first. A suggestion inserts the exact name an agent answers to, or its ID when two share a name.
-
Approvals: the full draft or tool input, decided after Face ID and signed with the phone’s own key.
-
Notifications and background:
- New direct messages and approval requests addressed to you or your account become notifications, shown as banners while the app is open too (except for the conversation on screen). Tapping one opens the conversation or Approvals.
- You says when notifications are switched off for BNW, with a link to Settings.
- The app badge counts pending approvals.
- Leaving the app keeps the node syncing for the short time iOS allows, and iOS background refresh wakes it now and then.
- Nothing is pushed while the app is fully suspended: that would need a push service, which BNW doesn’t run.
-
Links:
bnw:pair,bnw:contactandbnw:channellinks, from the Camera or tapped anywhere, open the app to join, add, or pair. -
Offline banner: shown when no peer or relay is reachable.
-
Agents:
- per-channel permission modes (Off, With approval, On its own) and tool permissions;
- the signed audit trail.
The phone signs the grants it adds and can revoke the ones it signed; grants made on another device are changed there.
-
Services:
- federated search, with retrieve-and-verify for other people’s results;
- the catalog by kind;
- each service’s declared data handling, trust, and follow;
- using a service: the request is encrypted for its provider, the answer is decrypted, and provenance is checked.
-
You:
- contacts;
- your contact link;
- devices, with sending history to one and adding another;
- recovery and wallet (informational for now);
- data rules (the routing policy);
- storage;
- settings sync.
Hosted agents and your account: an account operates hosted agents, so every device of the account manages them and decides their approvals. New hosted agents link to the host’s account. Existing ones are linked to the account, with the agent’s own key, once their host belongs to one.
