* feat(remote): remote MCP access over tailscale (tailnet + personal mode)
* docs(remote): deploy section — remote access, home server & VPS, connecting agents
* chore(remote): fix pre-existing format and import-order debt
* feat(cli): add ok remote connect command
* fix(remote): reset revocation edge case and doc fixes from review
* fix(remote): revocation hardening, loopback bind coercion, and diagnostic/doc fixes from review
* fix(remote): correct agent config paths in docs, roll back grants on save failure, review nits
* feat(remote): rescope to R0 trust-the-tunnel; serve UI over the tunnel
Cut the embedded OAuth AS/RS and Tailscale classifier; add ok start --remote with a loud banner and forwarded-header tripwire; serve the SPA + MCP on one pinned port; admit the tunnel origin/Host across the browser gates; docs rewritten tunnel-agnostic with add-mcp.
* fix(remote): admit UI collab/thread + keepalive over the tunnel
Widen the /collab/thread + /collab/keepalive WS upgrade gates to admit tunnel clients (Ask-AI panel + keepalive over the tunnel); widen the forgot-the-flag forwarding tripwire to common vendor headers; log WS-upgrade rejections.
* style(remote): biome-format the /collab WS rejection log
* docs(remote): restructure and tighten remote-access and connecting-agents
* chore(remote): revert turbo docs-typecheck edit and trim verbose comments
* docs(remote): cross-link remote-access and connecting-agents with related pages
* docs(remote): reword the cloud connectors note
---------
GitOrigin-RevId: 291cf7ce864915ef11c0ca3f314e0c557dc05bd1