No SSH, no exposed ports, no router changes — your laptop makes an outbound-only connection to Jarvis and stays connected. Jarvis can never dial in on its own.
Download agent_client.py from the backend repo onto the laptop.
Install its one dependency:
pip install aiohttp
Get a connection token from whoever runs the backend (it lives in the server's .env, never in this page or any repo).
Run it, and leave the window open — closing it instantly cuts Jarvis's access: