DL-406
app.toml stays the native app’s only connection config and becomes writable from the app on first run. An absent app.toml with no --mode/$COMPASS_APP_MODE override opens a first-run chooser. “Run Compass on this computer” (primary) runs the embedded preflight in the window, writes mode="embedded", and asks the user to reopen the app. “Connect to a server” takes a URL, an optional CA file, and the bearer, probes in-process, then writes mode="client" with the normalized server_url and, when the user picks a CA file, ca_cert naming a new server-ca-<hex>.pem copy, and only then stores the bearer. The app writes app.toml only on a first-run choice, by exclusive create, so it never replaces an existing file; a configured client’s server_url stays a file edit, and the chooser never returns while app.toml exists. DL-320’s surviving clauses are restated: flag > env > file, else the chooser; mode="embedded" accepts no server_url/ca_cert; mode="client" requires an https origin server_url (no userinfo, path, query, or fragment; a trailing / is normalized away; one validator for file and UI) with optional ca_cert; embedded→client graduation stays a config edit. The bearer stays keychain-first per DL-109; this row partial-supersedes DL-109’s “(absent → embedded default)” clause by citation. Supersedes DL-320
Status: Active (Matt, 2026-10-05)
Record: ../../ui/compass-native-server-url-entry/design.md#a1–first-run-is-a-chooser