Handoff

Preview, consent, transfer, then continue.

Handoff keeps recipient authorization and encrypted project transfer explicit.

Choose the recipient boundary

  • People: an accepted relationship provides ongoing collaboration consent
  • Quick Handoff: a short-lived code provides temporary, scoped consent without creating a Friend

Preview before accept

Opening a public Handoff link does not claim it. The recipient sees a safe preview, then explicitly accepts before temporary capability visibility is granted.

Prepare and transfer

Meloft rechecks recipient Capability and current authorization, then prepares the selected project package. Project bytes are encrypted on the sender device before cloud transfer; the server stores opaque ciphertext and minimum orchestration metadata.

Open and continue

The recipient explicitly materializes the received package in Received Workspace and opens it. A later contribution is an explicit child Revision, not a silent overwrite of the sender's project.

Security boundary

Use only canonical meloft.app/handoff links. Raw Handoff codes are short-lived secrets and should not be placed in screenshots, logs, or diagnostics.