Your computers
Install the waper desktop app on a computer, or the waper-node command-line daemon on a server, and that machine becomes one your agent can use. Start a conversation on the web, on your phone or in the desktop app and ask the agent to read and write files, run commands, open apps, or use the browser you're already signed in to.
The agent itself runs in the cloud; your computer only carries out the requests it sends. That's why it behaves the same wherever you start, and there is only one copy of your conversations, memory and approvals.
Connect a computer
- Mac: install the desktop app; it connects as soon as you sign in.
- Servers, a Mac mini or other machines without a screen (macOS, Linux): install the command-line daemon.
Once connected, the computer shows up under Settings → Computers, where you can see whether it's online. Its name defaults to the computer's name; you can rename it or Disconnect it. Disconnecting signs it out immediately; to use it again, sign in again.
A computer is online while the desktop app or waper-node is running. When it sleeps, shuts down or quits waper it shows as offline and the agent can't use it.
How a conversation picks a computer
You never have to choose a computer first. The rules:
- Conversations don't use a computer by default. Search, reading pages, research and writing documents all happen in the cloud.
- A conversation started in the desktop app uses that computer automatically; the message box shows "On this computer", which you can remove.
- When a conversation started on the web or your phone needs a computer (local files, local apps, running a command), the agent connects one, choosing in this order:
- the one you name (by its name, e.g. "on studio");
- the only one online, if just one is;
- the one you used most recently;
- the one the agent used last.
- Connected computers show at the top of the conversation. Once connected, the agent keeps using that computer and never switches silently. If it goes offline, the agent finishes whatever can be done in the cloud and tells you which computer to turn on.
- It connects another computer only when you mention one, or when the job itself spans machines (say, copying a report from your home computer to your work one); it never replaces the one already connected. You can remove a computer at the top of the conversation or choose Add a computer at any time, and every result says which computer it came from.
What the agent can do on a computer
| Action |
How it's handled |
| List folders, read files, search by file name or content |
Done directly |
| Write, edit, move or rename files |
Done directly; the previous version is kept and you can undo for 7 days. A move never overwrites an existing file |
| Delete a file or folder |
Always asks first; once approved, it moves into waper's own trash on that computer (not the system Trash) and you can undo for 7 days |
| Run a command |
Asks first; choose "Don't ask again for this" on the approval card and it stops asking |
| Open a file, folder, app or web page for you to see |
Done directly |
| Save a local file (PDF, Word, Markdown, text, image) to your library |
Done directly, the same as a library upload: filed into a fitting space, with reading and summarizing charged at actual cost; the same file is only added once |
| Open and read pages in your browser |
Done directly; see Your browser |
| Click and type in your browser |
Asks first; choose "Don't ask again for this" and it stops asking |
Approvals
- When something needs your decision, an approval card appears in the conversation (for background tasks you also get a notification and an inbox item). You can approve from the web, your phone or the desktop app; a request with no answer for 7 days counts as declined.
- "Don't ask again for this" is saved to your account and applies to all your computers.
- Deleting is not affected by "Don't ask again for this": it always asks.
Undo
- Each time a file on your computer is written, edited, moved or deleted, the conversation shows a "Done · Undo" line. Use Undo while the undo window lasts to put the file back the way it was; a deleted file is moved back from waper's trash.
- If you or another program changed the file after that, undo won't overwrite it. Undo needs the computer to be online; if it's offline, try again once it's back.
- Files over 50 MB don't keep a previous version: the write still happens, but it can't be undone.
- After you undo something, the agent knows about it the next time you write, so it won't keep working on a file as if the change were still there.
Running commands
- A command runs for up to 2 minutes by default, and the agent can extend that to 30 minutes when needed. On timeout the command is stopped and the output so far comes back.
- Very long output keeps the beginning and the end.
- While a command runs, its latest line of output shows under that step in the conversation and goes away when it finishes.
- You can stop work at any time: stop the reply in the conversation, or stop one or all actions from the desktop app's menu bar icon.
Access scope
Access scope decides which files on a computer the agent can reach; approvals decide which actions ask you first. They are independent.
- The whole computer, by default: install, sign in, and it works. The desktop app's menu bar says "The agent can use all files on this computer".
- Only these folders: set per computer. In Settings → Computers, find the computer and change "Your agent can use" from "The whole computer" to "Only these folders", then add the allowed folders (full paths starting with
/ or ~/, up to 50). The command-line daemon can also set this at sign-in with --folders. Changes reach the computer immediately.
- Files outside the scope: when the agent hits a path outside the allowed folders, it shows a card in the conversation such as "Needs access to ~/Downloads". Choose Allow this folder and the folder is added and the agent carries on — no trip to Settings.
What "only these folders" guarantees
File actions:
- A path has
~ and relative parts expanded, then symlinks and .. resolved, and the result must be inside an allowed folder. A symlink inside an allowed folder that points outside counts as outside.
Commands:
- The working directory must be inside the scope, and the command itself runs in a system sandbox:
- macOS: it can only write to the allowed folders, temporary folders and common cache folders (such as
~/.cache, ~/Library/Caches, ~/.npm). Under your home folder and external disks (/Volumes) it can only read the allowed folders, common developer tool folders (such as ~/.nvm, ~/.cargo) and your git config; system folders stay readable. File metadata (whether a file exists, its size) isn't restricted, and neither are network access and inter-process communication.
- Linux: with bubblewrap (
bwrap) installed, system folders are read-only, your home folder only shows the allowed folders plus developer tool and cache folders, and /tmp is private; network access isn't restricted. Without bubblewrap only the working directory is checked and the command itself is not restricted, so install bubblewrap if you need the isolation (for example sudo apt install bubblewrap).
- In whole-computer mode, commands are not sandboxed.
In either mode:
- waper's own data on the computer (sign-in credentials, pending results, previous versions and the trash) is never open to the agent.
- Your home folder, the disk root and the allowed folders themselves can't be deleted or moved.
These limits keep the agent within bounds; they don't protect against malicious software already running on the computer.
Background and scheduled tasks
- Scheduled tasks can use computers too, under the same approval and scope rules.
- A scheduled task created in a conversation keeps using the computers that conversation was connected to; otherwise its first run picks one by the rules above and keeps using it.
- If a computer it needs is offline, the task checks every 5 minutes and continues once it's back, for up to 6 hours, then fails; a failure notifies you and shows up in your inbox.
Privacy and security
- The computer only makes outgoing connections to waper and opens no ports, so it works behind a router.
- The agent uses a computer only when it needs to, and the conversation shows which computer each action ran on.
- File contents the agent reads are processed by the model like anything else in the conversation.