--- status: accepted --- # Onboarding runs on the phone through the TV's own pairing server Nobody should ever type on a TV. Instead of baking a server URL into the APK (rejected: publishes private infrastructure in a public artifact) or on-TV text entry (rejected: D-pad typing), first-run setup reuses the embedded remote-control server: the TV shows one QR, the phone opens the TV-served web app, and server URL plus IdP login (device-flow link opened directly on the phone) happen there. Requires phone and TV on the same LAN — acceptable, since the remote control has the same requirement by design.