Product manual

Connect, share, and stop with every decision visible.

A complete browser guide for passwordless access, device enrollment, direct-first sessions, screen mirroring, group limits, consent, recovery, and support.

Before you begin

Two enrolled browsers and a host who can approve the request.

Use the production app on a secure origin in a current browser with WebRTC and screen-capture support, plus access to the verified-email inbox. The host remains involved: account ownership never starts capture, grants control, or accepts content automatically.

Create or access a passwordless account

Verified-email magic links provide standard passwordless signup and sign-in. Passkey or TOTP enrollment is optional hardening for a standard account.

  1. Enter your email from Create Free account or Sign in, then open the short-lived, one-use verification link intended for that request.
  2. A standard user can finish signup or sign-in with that verified-email magic link and may optionally add a passkey or TOTP authenticator from account security settings. No password is created.
  3. Every administrator must complete a recent passkey ceremony or provide a live TOTP for admin access and actions. Recovery alone is insufficient; never send links, authenticator codes, recovery material, or tokens to anyone.

Enroll and identify each device

Every browser profile is a separate account device with its own locally held, non-exportable signing key.

  1. Open the app separately on the host and viewer, authenticate, and give each browser identity a recognizable device name.
  2. Confirm the target name before requesting a session. Sharing an account makes enrolled devices selectable; it does not pair them silently or bypass host approval.
  3. Revoke a lost, replaced, or unfamiliar device from the account. A revoked identity cannot obtain new session authority.

Connect direct-first, with encrypted TURN fallback

The service authorizes the named peers and bounded signaling; WebRTC carries screen, control, clipboard, and file data between endpoints.

  1. After the host accepts, WebRTC tries direct ICE candidates first to favor the lowest practical latency between the two devices.
  2. When the networks cannot establish a direct path, the session may use short-lived authenticated TURN credentials. TURN forwards encrypted packets and does not receive endpoint session keys.
  3. Direct and TURN paths authorize only the selected product session. Neither creates an account-wide VPN, default route, remote shell, or arbitrary network proxy.

Start one-to-one or plan-bounded group sessions

Select only the hosts you need. Every target is a separate peer connection with its own visible consent and lifecycle.

  1. Choose one enrolled host for a one-to-one session, or select several hosts up to the account's simultaneous-session limit shown below.
  2. Each target sees the requester and requested permissions, then accepts, narrows, or rejects independently. One acceptance never authorizes another target.
  3. Ending or recovering one peer does not grant or keep another peer alive. Device and concurrency limits remain enforced by the account plan.

Mirror a screen and use the viewer as a display

The host chooses an existing display, window, or tab; the accepted viewer can present that stream as a focused browser display.

  1. On the host, start sharing from the visible action and choose the exact source in the browser's native screen picker. Share no more than the viewer needs.
  2. On the viewer, choose Use as display, then select Fit, Fill, or 1:1 and rotate 0°, 90°, 180°, or 270°. Fullscreen and Wake Lock are optional enhancements.
  3. Use as display is encrypted screen mirroring. It does not add an operating-system monitor, extend a desktop, or change the host's resolution or refresh rate.

Grant control, clipboard, and files deliberately

View, pointer, keyboard, clipboard, and file permissions are separate, short-lived choices; grant only what the task requires.

  1. Keep the request view-only unless another permission is necessary. The host can reduce, pause, or revoke granted pointer and keyboard control during the session.
  2. Clipboard text and files travel over the authorized peer data channel only after an offer and explicit acceptance. Check the sender, name, type, and size before accepting.
  3. The browser release does not execute operating-system-wide input. That requires a separately published trusted native component with its own signing and visible-consent gate.

Exit, stop, revoke, and recover safely

Exit changes the viewer presentation; Stop ends that peer. The host can stop capture locally at any time.

  1. Choose Exit display to leave the immersive receiver while preserving only the already authorized session. Choose Stop to close that peer's tracks and channels.
  2. If connectivity drops, the viewer makes at most three bounded ICE-restart attempts. An answered restart receives fresh fingerprint-bound authorization.
  3. Expired authority, revocation, identity change, or exhausted recovery ends the peer. Start a new named request and make a new host-approved screen choice.

Apply the security checklist

Trust the named person, exact device, requested scope, and visible host state—not account membership or a link alone.

  1. Before accepting, verify the viewer name, requested permissions, selected source, and why the session is needed. Reject unexpected requests.
  2. Keep browser capture indicators and RealLexi Stop controls visible. Stop immediately for an identity mismatch, unexpected permission change, or unknown file offer.
  3. Revoke devices after loss or replacement. The service stores authorization metadata, not screen, clipboard, file content, input content, or endpoint private keys.

Troubleshoot the browser session

Start with the visible account, device, capture, connection, and permission state before changing network or browser settings.

  1. For sign-in trouble, confirm the exact production origin, device clock, delivery inbox, and unexpired magic link. If optional MFA is enabled—or the account is an admin—confirm the current passkey or live TOTP step.
  2. For a blank viewer, confirm host acceptance, an active browser-selected source, media permission, and the displayed connecting or recovery state. Re-request after capture ends.
  3. For transfer or control trouble, confirm both endpoints granted the exact direction and that the peer data channel is ready. Record whether the session reports direct or TURN.

Contact support without exposing secrets

Useful diagnostics identify the product state while excluding credentials and customer session content.

  1. Provide the time, browser and operating-system versions, device roles, visible device names, session-state label, direct or TURN path, and bounded error code.
  2. Do not send screen captures containing sensitive work, private keys, email links, passkeys, recovery codes, access or refresh tokens, clipboard text, or transferred files.
  3. Use the support address for account or connection help and the security address for a suspected vulnerability. Stop and revoke first when unauthorized access is suspected.

Group capacity

Concurrent targets follow the active plan.

The same identity, encryption, consent, and Stop model applies at every tier. A group consumes one simultaneous session for each independently authorized target.

Maximum active devices and simultaneous peer sessions per account plan.
Plan detailActive devicesConcurrent sessions
Free21
Silver31
Gold72
Organization1005

Browser release boundary

Know what this manual does—and does not—authorize.

These boundaries keep setup instructions aligned with the public browser product and prevent an unsigned or unsupported component from being mistaken for a released capability.

  • Use as display mirrors an accepted source inside the browser; it is not an operating-system Extend or Duplicate monitor.
  • The public unsigned Windows EXE demo is for download inspection only; this manual does not authorize installing or using it, and no native installer, driver, or mobile host package is offered.
  • Gamepad execution and virtual-HID control are not presented as browser capabilities.
  • RealLexi sessions are not a general VPN, VLAN/VWAN replacement, proxy, remote shell, network scanner, or unrestricted port forward.

Ready to connect

Open the app, enroll both browsers, and keep the host in control.

Start with view-only access, confirm the named peer and selected screen, then add only the permissions the session actually needs.