Development previews
Preview a hosted app and explicitly consent to temporary real project access.
Start octonodes app dev --workspace user:<id> after signing in. Studio shows the full hosted page, with optional contribution previews. The development session belongs to its publisher and starts with no project grants.
The generated React app shows its workspace page only after the backend verifies the preview session. With no project grants, the Projects route shows an empty state. Direct visits to its public host show no workspace content.
Real project access
Declare the required actions, then choose Review development access in Studio. The consent dialog identifies the host and selected projects. The signed-in publisher must also be a workspace administrator. Review the destination: the live developer server receives these selected data, and code edits take effect immediately.
Consent expires after one hour. The session expires after ten minutes without a heartbeat. Heartbeats keep the session alive but cannot extend the consent deadline. Revoke development access removes access immediately. Changing the app origin or requested scopes clears consent. Stopping the CLI closes its session; a disconnected process expires automatically.
Production installation needs its own consent. Never publish a temporary tunnel URL as the release host.
Session renewal
The hosted SDK receives session updates from Studio without reloading the app. A normal heartbeat retains the development bearer. Installed sessions are replaced before expiry. The SDK keeps bearers in memory and removes launch credentials from the URL fragment.
Open the app from Studio to receive and renew its session. See routing for integrating the bridge with your app.