You just scanned a robot's face.
If you got here from a small square glowing on a panel the size of a large coin, that was an ESP32-C6 on our bench showing you its own pairing code.
That board is groundwork. It runs the MCU host work for OpenCastor, the part that has to be true before a six dollar class robot can be adopted the way a robot should be: you point a phone at its face, and it is yours. On boot it inventories every chip on its own I2C bus, brings up a 368 by 448 AMOLED over QSPI, and paints a QR of the address you just visited. It has no Wi-Fi credentials and no network.
The code you scanned is a demo payload. It is a link to this page and nothing else. It carries no identity, no token, no address and no key, and it cannot pair anything to anything. What it proves is the gesture: a robot that shows its own code needs no companion app, no captive portal and no serial console to be adopted.
display init ok 368x448 (SH8601 over QSPI, RGB565, no backlight -- AMOLED) QR painted, version 3, modules 29x29, 9 px/module, quiet zone 36 px QR payload : https://opencastor.com/pair?demo=esp32c6 QR caption : OpenCastor ยท scan to pair (demo)
What a real pairing QR carries.
A real one is not a link. It is a small payload your phone reads once and keeps: where the robot's gateway answers, a bearer token scoped to a tier rather than a password, the robot's registration number, the URL that stops it, the key its receipts are signed with, and the list of everything it can actually be asked to do. Scanning is the whole of pairing. There is no account, nothing is uploaded, and from then on your phone can sign plans for that robot while the robot's receipts stay checkable against the key that arrived in the same scan.
- gateway_url where the robot answers
- bearer a token scoped to a tier, not a password
- rrn its registration number
- estop_url the address that stops it
- attest_kid which key signs its receipts
- attest_pub that key, so you can check them offline
- capability_surface everything it can actually be asked to do
What is not built yet.
The C6 cannot pair. Generating its own signed identity, issuing a bearer, publishing the attestation key its receipts would be checked against: none of that runs on the board today, and the QR on its panel is a demo payload precisely because pretending otherwise would be the one thing this project refuses to do. The Raspberry Pi side of that loop is real and shipping, which is the difference between the two halves of this page.
The work is tracked in the open, and the app that will do the scanning is in public beta.
Version 1.0, free. It is the robot's face, and on a vehicle its eye.