Documentation menu
On this page

Notifications on a locked phone

When the agent runs a command that needs your signature, the request reaches the phone even if it lies locked on the table. The notification tells you whether it is urgent: which server, how risky, how much time is left. It never lets you approve: tapping it opens the card, and the app asks for your fingerprint, face or passcode before it signs.

What the lock screen shows (Android)

Approval request
pi · risk: high · 1:40 left

The first time the service starts, the app explains why it needs the notification permission before Android asks for it. If you said no, Mode → Notifications has a button to the settings.

Like an incoming call (Android, optional)

Mode → Notifications → Like an incoming call opens a new request full screen over the lock screen and turns the screen on, like a call: host, risk, the countdown, and two buttons, Open (unlock, then the card) and Later (the notification stays). Nothing can be approved there. The mode is off by default.

It uses Android’s full-screen intent. Since Android 14 that needs a permission the user grants: if WardenClaw does not have it, the switch opens the system page (“Full-screen notifications” on a Pixel; the name differs between Android versions).

Google Play. Play grants USE_FULL_SCREEN_INTENT by default only to apps whose core function is calling or alarms; for every other app installed from Play it is revoked, and the app must ask the user to allow it, as WardenClaw does. An app on Play also has to fill in the full-screen intent declaration in Play Console, and Google may reject it if the use does not fit. That is why the mode is optional and off by default: the regular notification already reaches the lock screen.

Battery (Android)

Without a push service, the app keeps a long-poll connection to your own wardend from a foreground service. Android may still put the app to sleep:

iPhone

iOS does not let an app keep its own connection in the background, so on the iPhone the server sends a push through Apple (APNs) when a card appears.

For a self-built iOS app, the App ID com.wardenclaw.app needs the Push Notifications and Time Sensitive Notifications capabilities in Apple Developer (Certificates, Identifiers & Profiles → Identifiers), and the provisioning profile must be generated again after you turn them on. See the checklist on iPhone app.