# Open Zuse in a local browser

> Enable local browser access, redeem a one-time link, verify the session, and revoke it safely.

Canonical URL: https://docs.zuse.sh/how-to/remote-local-browser



Authorize one browser on the Mac's local network without exposing an unauthenticated server or signing in to hosted access.

## Applicability [#applicability]

Use this guide when the browser can reach the Mac over the current network. Use [hosted remote access](/how-to/remote-hosted-access.md) when the browser is away from that network.

## Prerequisites [#prerequisites]

* Zuse is open on the Mac that owns the environment.
* The target browser is on a network that permits device-to-device traffic.
* You can restart Zuse if browser and device access is currently off.

## Steps [#steps]

1. In the desktop app, open **Settings → Devices**.

2. If **Browser and device access** is off, choose **Enable browser and device access**.

3. Confirm **Restart and turn on**.

   Enabling the listener restarts Zuse and stops running agents. Reopen **Settings → Devices** after the app returns.

4. Choose **Create web link**.

   Zuse displays a browser QR code, a one-time link, and a short pairing code. The link expires after five minutes.

5. Choose **Open web app**, copy the link into the target browser, or scan the browser QR code.

6. Let the browser finish authorization and load the environment.

   Do not send the link through an untrusted service or open it in a shared browser. Treat the unredeemed link like a temporary password.

## Verification [#verification]

Confirm that the browser shows the same projects and chats as the Mac. Then return to **Settings → Devices** on the Mac and verify the browser appears under **Connected devices**, with its label and last-connected time.

The one-time link may now expire without ending the authorized browser session. The browser's device credential remains valid until you revoke it or disable local access.

## Revoke the browser [#revoke-the-browser]

1. Open **Settings → Devices** on the Mac.
2. Find the browser under **Connected devices**.
3. Choose **Revoke**.
4. Reload the browser and confirm it shows **Pair this browser**.

Use **Revoke all** for the grouped **Older device access** credentials created by versions that cannot identify clients individually.

## Troubleshooting and recovery [#troubleshooting-and-recovery]

### The link expired [#the-link-expired]

Choose **Create web link** again. Old links are not renewable.

### The browser says the versions do not match [#the-browser-says-the-versions-do-not-match]

Update the environment, then reload the page. Incompatible clients are blocked instead of connecting with a partial protocol.

### The browser cannot reach Zuse [#the-browser-cannot-reach-zuse]

Confirm the Mac is awake, Zuse is open, and browser and device access shows **On**. Guest and corporate Wi-Fi often isolate clients; move both devices to a trusted network if necessary.

### Authorization expired after a working session [#authorization-expired-after-a-working-session]

Revoke any stale entry, create a new web link, and authorize the browser again. See [connection recovery](/how-to/remote-recover-connection.md) for the error-state decision tree.
