How it works

The pieces

The desk

Setup is plain shell: `provision/apply.sh` builds the desk and can run again at any time, and `provision/verify.sh` checks it. Settings the apps share are plain files in `~/.config/dbbasic`: AI keys in `ai.env`, where documents go in `places.env`.

Security

A real certificate with a domain; your password is exchanged for a short-lived token; a device types the desk's PIN once and is then remembered through pairing; relay credentials are made per session. API keys stay on the desk and are never shown.

Built for AI

Every app can be driven by voice and scripts through its own control socket, with an honest label on each action: read, edit, file, paid or destructive. Voice's approvals follow that label.