/lock or a relock, ordinary messages do not reach the agent until you unlock.
Set it
~/.telekit/passcode.json (0600). It never stores the clear passcode. It never forwards unlock text to the agent or the fast lane.
Unlock
| You send | Result |
|---|---|
/pw | Prompt. Next plain text within 2 minutes is the passcode. |
/pw <code> | Verify now. |
| Bare passcode | Only in the 2-minute window after a lock prompt. |
/lock locks immediately and sends the prompt.
Five wrong guesses → lockout for 5 minutes.
Relock knobs
| Command | Default | Meaning |
|---|---|---|
telekit passcode relock-on-new | off | /new does not lock. |
telekit passcode relock-on-restart | on | Daemon bounce locks every lane. off restores unexpired unlocks. |
telekit passcode relock-on-node-switch | on | /node switch locks. off carries remaining TTL. |
telekit passcode relock-on-thread-switch | on | /thread switch locks. |
Deletion
The bridge tries todeleteMessage the Telegram message that contained the passcode. That is hygiene, not a guarantee. Notifications, other devices, exports, and screenshots may still have seen it. If delete fails, the reply says so.
Locked-safe commands
/pw /lock /new /stop /x /status /s /restart /help /ping /whoami /claim.
/skill is not locked-safe.