Docs/NOME Code/Trusted workers

Trusted workers

The single worker contract for a Mac today and additional hosts later.

Worker identity

Every worker is bound to a WorkOS user and tenant, device identity, worker key, capability set, allowed workspace roots, execution policy, and heartbeat.

Current scope

Early access proves one canonical Mac seat worker first. Linux, Windows, private VM, and managed cloud workers must implement the same protocol instead of introducing parallel host systems.

Interruption and resume

The server preserves jobs, events, artifacts, and checkpoints. A different worker may resume only when it has the workspace, provider authorization, required capabilities, and explicit policy.

Ready to try it?

Open NOME