Holdfast
Partner
You are signed in. This page cannot pair or approve yet. The partner server address is empty. After the Cloudflare worker is deployed, set REMOTE_BASE in config.js and reload. Sign-in stays on this account.
This page is not a public partner link. Sign-in is not configured yet. Set the Firebase web key, the project id, and the server address in config.js, then reload. A person who only has this URL cannot approve an Unlock.
Sign in with the partner account. The same email works in any browser if this phone is lost. This page does not keep the signing key. The server signs Unlock, Lock, Unlock Indefinitely, and Allow Uninstall only for the account linked to the phone.
Use at least 8 characters. This is not a subscription. A later payment check can use this same account.
Locked
No Unlock is active on this phone's clock
Scanned/linked.
You are signed in. Scan the pairing code from Holdfast, or paste it below. It is a one-time invite, not a signing key. After Submit, this account is scanned/linked to that phone. Another browser with this same account can still approve later.
The code and the QR are the same pairing key. It pairs once. Delete the message after you link.
Partner change is allowed for 24 hours. Cancel it before a new partner submits the code.
Have them scan this or type the code in Holdfast. It works even if the phone is offline.
No backup code yet. Tap an action above first. Its code shows here.
How this works
Use Unlock for 1 hour or Unlock for 24 hours when they need a pause. A timed Unlock turns back on by itself and does not allow uninstall. Unlock Indefinitely stays off until they start protection again, and it does not allow uninstall either.
Each action is sent to the phone. It applies within a minute while Holdfast is running. If it does not respond, tap “Phone not responding? Show backup code”. The backup code is for the most recent action. It expires in 5 minutes and works once.
While an Unlock, Unlock Indefinitely, or Allow Uninstall is active, the phone is not protected. That button shows On (with time left for an Unlock), the status at the top shows a green Unlocked, and Relock shows up. A red Locked means protection is on. Allow Uninstall or a pending partner change, with no Unlock running, shows a green Unprotected. Relock ends the Unlock and turns protection back on.
Scan a request code (under “Phone not responding? Show backup code”): they can show a request code in Holdfast or text it to you. Scan it, or paste it on the scan screen. It expires in 5 minutes and works once. Submitting it creates a new Unlock or Unlock Indefinitely. It does not reuse an old code, and it does not pause the phone by itself.
If the status on this page looks wrong, tap “Phone not responding? Show backup code”, then “Phone status wrong? Scan status code”. Scan or paste the status code from Holdfast settings.
The Android Partner app is optional. This page does the same job.
Only the signed-in partner account can approve. A copied page link cannot. Protect this phone with a passcode. Do not keep a screenshot of the pairing code.
Sign out leaves the account link in place. Sign in again on any browser to keep controlling that phone.
Sync status
On the blocker, open Settings and show the status code. Scan it here, or paste it. That replaces the clock on this phone with the blocker's.