How a page reaches your phone
This page covers what Mast does between a script posting to a channel URL and you reading the card: how it tells you who sent it, what happens when your phone is off, what it records along the way, and the two settings that decide how often you get woken up.
Every page says who sent it
Each notification carries the name of the channel it came from and a short label for the key that sent it, like backups · mk_1a2b3c. The label is the first six characters of the key, which is enough to tell two keys apart and not enough to send with. Both are copied onto the message when it arrives, so renaming the channel or rotating the key later doesn't change what an old card says.
The same two fields are on every message the API returns:
{
"id": "mm_4f1c…",
"channel_name": "backups",
"key_label": "mk_1a2b3c",
"first_link": false,
"canary_url": "",
"sent_at": "2026-09-24T03:12:01.204Z",
"shown_at": "2026-09-24T03:12:02.918Z",
"acked_at": "2026-09-24T03:14:40.051Z"
}"This isn't mine"
A channel URL is a send credential. If a page arrives that you don't recognise, someone else has the URL. Tap This isn't mine on the card, or call:
curl -X POST https://api.tissue.systems/v1/mast/messages/mm_4f1c…/disown \
-H "Authorization: Bearer $TISSUE_TOKEN"Mast then does four things at once:
- Rotates the channel's key with no grace period. An ordinary rotation lets the old key keep working for seven days so a cron job you haven't updated yet doesn't drop pages; this one doesn't, because the old key is the one being used against you. Any older key still inside its grace period stops working too.
- Mutes the channel for 24 hours.
- Records a
disownedevent on the message. - Returns the channel id, the new key's label and the new URL, so you can hand the URL to the senders that should have it.
{
"channel_id": "mc_9b2e…",
"channel_name": "backups",
"key_id": "mk_7d0e44",
"rotated_from": "mk_1a2b3c",
"muted_until": "2026-09-25T03:20:00.000Z",
"url": "https://mast.tissue.dev/mk_7d0e44…"
}The first link from a channel is flagged
A channel that has only ever sent "backup finished" and then sends "reset your password at …" is worth a second look. The first message from a channel whose title, body or URL holds a web address or a phone number is marked first_link, the card says so, and the send gets a warning back:
{"ok": true, "id": "mm_…", "state": "queued", "first_link": true,
"warning": "first link or phone number from this channel"}After that, links from the channel go through unmarked. Rotating the key resets it, so the first link sent with the new key is flagged again. Version numbers, times, dates and IP addresses don't count as links.
If you'd like pages from a channel to carry a link you trust, set canary_url on the channel. It's an http or https address, it rides on every page from that channel, and the app shows it as the link to open. A page that points somewhere else stands out against it.
curl -X PATCH https://api.tissue.systems/v1/mast/channels/backups \
-H "Authorization: Bearer $TISSUE_TOKEN" \
-d '{"canary_url": "https://status.example.com/backups"}'A phone that was off gets the newest page, and the rest when it opens
Apple's push service keeps only one notification per app for a phone it can't reach: the newest one. If three pages go out while your phone is off, it will show the third when it comes back, and the app picks up the other two from the feed the next time it opens.
Mast chooses what is allowed to take that one slot. A page is kept until the message expires, or for an hour if it has no expiry. Acknowledgements, resolves and card updates are sent once and never kept, so they can't push a waiting page out of the slot. If you've been offline, open the app before you trust the lock screen.
Three timestamps on every page
| Field | Whose clock | What it means |
|---|---|---|
sent_at |
Mast's | Apple's push service accepted the page |
shown_at |
Mast's | The app reported the page on screen |
acked_at |
Mast's | Someone acknowledged it |
The app also sends its own clock reading when the notification arrived, stored as arrived_at. The gap between sent_at and shown_at is delivery time; arrived_at next to shown_at tells you whether the phone's clock is off. Each one is written once. The web app's feed shows all three.
When Mast stops sending to a phone
If Apple tells Mast a phone no longer accepts pushes, usually because the app was deleted or the phone was reset, Mast stops sending to it. It tells you once, by email to your account address and as a page on another of your phones:
Mast retired a phone: iPhone 15, it stopped accepting pushes; open the app to link it again
If that was the only phone, the email is the only notice. The web app's home screen shows how many phones are receiving pages, in red when the answer is none.
The weekly line
The web app's home screen shows how often you were paged over the last seven days:
14 pages this week, 6 between 23:00 and 07:00
It counts loud and critical pages, not quiet notices or silent checks, and reads the night in your phone's time zone. The same numbers, plus the median minutes from page to acknowledgement, are at:
curl https://api.tissue.systems/v1/mast/owners/me/budget \
-H "Authorization: Bearer $TISSUE_TOKEN"{"pages": 14, "night_pages": 6, "median_minutes_to_ack": 3.5,
"tz": "America/Los_Angeles", "since": "2026-09-18T12:00:00.000Z",
"line": "14 pages this week, 6 between 23:00 and 07:00"}Ack timeout
Acknowledging a page stops it repeating. It doesn't mean the problem is fixed. Set ack_timeout_min on a channel and an acknowledged page that still isn't resolved after that many minutes pages again, once. Acknowledge it a second time and it stays quiet until it's resolved or expires.
curl -X PATCH https://api.tissue.systems/v1/mast/channels/backups \
-H "Authorization: Bearer $TISSUE_TOKEN" \
-d '{"ack_timeout_min": 30}'0 turns it off, which is the default. The longest timeout is a week (10080 minutes). You can also set it in the web app's channel settings.