Device interface reference

Reviewed

Connect signed activity to its source.

This reference documents the development device interfaces for pairing, signed events, continuity and revocation. For the creator facing Mac app and tool setup, visit Integrations.

Integration note: The routes listed below document the legacy simulator contract, not a Premiere recording API. Other versioned device routes are not interchangeable with it. Keep simulator evidence identified by its source and use the supported Mac app for customer setup.

Interface overview

Device management, validation and creator setup.

Web device management

Authorised workspace administrators with current identity eligibility can create simulator pairing codes. Device listing and revocation follow their own access checks.

Signed simulator telemetry

The API validates canonical hashes, Ed25519 signatures, replay state and previous event continuity.

Creator setup guide

The Integrations page explains the Mac app and recording workflow for creators.

Pairing protocol

A short lived workspace handshake.

An eligible workspace administrator creates a code that expires after 10 minutes. Registration exchanges it for a device token shown once. The server stores a hash of that token and checks current account authority again when the device submits activity.
pairing sequence
1. POST /api/daemon/devices/pair-code
   Auth: account access token (Firebase ID token)

2. POST /api/daemon/devices/register
   Body: workspaceId, pairingCode, device metadata, public key

3. Store deviceToken in the local secure store
   The token is returned once and the server keeps only its hash

4. Use the paired token for simulator session routes
   Authorization: Bearer <deviceToken>

Development device contract

Device and session endpoints.

POST/api/daemon/devices/pair-code

Create pairing code

Creates a one time code with a 10 minute expiry.

Access: Eligible workspace administrator

POST/api/daemon/devices/register

Register simulator or development device

Consumes a pairing code and returns a one time device token.

Access: Workspace ID and pairing code

GET/api/daemon/devices

List safe device summaries

Returns redacted paired device and simulator validation summaries for the selected workspace.

Access: Authenticated workspace user

POST/api/daemon/proof-sessions/start

Start simulator session

Creates or reuses an active simulator proof session for an accessible asset.

Access: Paired device token

POST/api/daemon/proof-events/ingest

Validate simulator event

Checks payload fields, asset ownership, canonical hash, signature, replay state and chain continuity.

Access: Paired device token

POST/api/daemon/proof-sessions/close

Close simulator session

Closes the paired device session while keeping the asset explicitly unverified.

Access: Paired device token

GET/api/daemon/sync-status?workspaceId=<id>&deviceId=<id>

Read device sync status

Returns safe device status and sync metadata.

Access: Paired device token

POST/api/daemon/devices/revoke

Revoke device

Blocks future sessions and ingestion while preserving historical simulator events.

Access: Workspace user or the same paired device

Validation sequence

What an accepted simulator event means.

The ingest route accepts only supported event types and allow listed metric or fingerprint fields. It rejects forbidden telemetry keys before an event can be stored.
accepted event categories
session_started
active_work
idle_period
file_saved
export_created
hash_recorded
session_closed

Server side checks

  • Paired device token matches its stored hash
  • Asset and optional project belong to the workspace
  • Canonical event hash matches the payload
  • Ed25519 signature matches the paired public key
  • Duplicate accepted event hashes are rejected
  • Previous event continuity is enforced

Default off data

Metadata boundaries are enforced before storage.

Rejected telemetry fields include

Do not submit these categories as event data or hide them inside permitted fields. A connector must minimise the information it sends and honour the disclosed project scope and permissions.

  • Raw keystroke or private typed text
  • Passwords, lyrics, prompts or scripts
  • Raw audio, video, stems or masters
  • Creative project files and source file contents
  • Screenshots and screen recordings
  • Raw file, folder or absolute paths

Creative tool connections

Film production leads the next recording workflow.

Premiere Pro is the first film connection being prepared, followed by Resolve and a separate After Effects connection. These are not enabled by the simulator endpoints. Check Connections for the supported app and tool versions available to your account.

DigiBridge help

FAQs, support and sales

What can we help with?

Find a quick answer or leave a message for our team. Replies appear here.