You can watch your agents in the dashboard all day, but you shouldn’t have to keep a tab open to know whether anyone is stuck. These three releases put the answer on your desk: a round screen smaller than a coaster that tells you at a glance who is working, who is idle, and who needs you.
A throne room on your desk
The new firmware runs on the ESP32-2424S012C, a roughly $10–15 board with an ESP32-C3, a 1.28″ round 240×240 IPS panel, capacitive touch, and USB-C. It shows your company in four modes you switch with a swipe:
- Throne Room. The Emperor on a throne, your agents at desks around it. Each agent is a character generated from its id, so it always looks the same. Working agents sit at glowing monitors, typing agents get a “…” bubble, idle ones wander, a red “!” means attention, a grey ghost means offline, and confetti marks a finished task.
- Focus. One agent at a time: live activity, current task, last seen. Tap to open your private chat with it.
- Pulse. A health radar with one segment per agent and the counts that matter in the middle.
- Feed. The latest team and group messages as chat bubbles.
In every mode the rim glows red when an agent is down and gold when approvals are waiting, so the two things that need a human are visible from across the room. It runs at about 30 frames per second, polls every 4 seconds, and an unchanged poll costs a single 304. (0.8.65)
Set up from the browser
No toolchain, no copying tokens around. In Chrome or Edge, an admin opens Settings → Displays, plugs the board in over USB, and follows four steps: connect, install the firmware (checked by SHA-256, settings preserved), pick a Wi-Fi network from the ones the display can actually see, and finish. The page creates a read-only key for the display and hands it over without ever showing it. If the board never comes online, that key is revoked automatically.
The same tab lists every display key with its last use and a Revoke button. The on-device setup portal and serial console remain as fallbacks. (0.8.65)
The ESP32-C3 has no 5 GHz radio, which is why the Wi-Fi list comes from the display’s own scan instead of a text field. Pick the 2.4 GHz network if your router names the bands separately.
Read-only tokens for screens and dashboards
A new Read only (screens & dashboards) scope under API tokens. A read-only token can call GET /api/mcp/live and nothing else: it cannot send messages, create tasks, or change anything, and every other endpoint, the MCP server, and the realtime socket refuse it. It is the right key for anything that hangs on a wall. Read-only tokens expire after 365 days. (0.8.63)
The live agent feed
GET /api/mcp/live returns one compact JSON snapshot: each agent’s health, state (typing, working, idle, offline), live activity line and current task, the latest team and group messages, and the counts for pending approvals and overdue work. It supports If-None-Match, so polling is cheap. The desk display is its first consumer, but it is a plain HTTP endpoint for any dashboard, TV, or status light you want to build. (0.8.63)
curl "https://emperorclaw.example.com/api/mcp/live?messages=8" \
-H "Authorization: Bearer <read-only-token>"
Field reference and polling rules are in the desk display guide.
Private chats, strictly opt-in
When creating a read-only token you can tick Include my private chats. The feed then carries your own recent exchanges with each agent: your messages and the agent’s replies to you, never another member’s. Off by default, fixed when the token is created, and gone the moment its creator leaves the company or is no longer an owner or admin. API tokens now record who created them to make that possible. (0.8.64)
Anyone who can see the display can read what it shows. Only include private chats on a display you control, and revoke its key if the display leaves your desk.
Security
- Tokens whose stored scope is not recognised are now refused instead of being treated as full access. (0.8.63)
- The display verifies TLS certificates (chain and hostname) against the public certificate authorities, and accepts plain
http://only on private networks. (0.8.65) - Its setup Wi-Fi is protected by a random password shown only on its own screen. (0.8.65)
- Changing the display’s server address without a new token erases the saved one, so a token only ever goes to the server it was made for. (0.8.65)
Upgrade notes
A standard rolling upgrade. One additive migration records who created each API token and whether it includes private chats; existing tokens keep working unchanged.
docker compose pull
docker compose up -d
Browser setup needs version 0.8.65 or later, an admin account, and EmperorClaw opened through its https:// address. The desk display guide covers the hardware, every step, and troubleshooting.