Skip to content

Releases: PandelisZ/codex-remote

Codex Remote 0.5.2

Choose a tag to compare

@PandelisZ PandelisZ released this 28 Sep 08:51
e7f28d1

Codex Remote 0.5.2 — the standalone window now uses its native title bar and toolbar, with a cleaner first-run layout. Updated website captures show the new window.

Codex Remote 0.5.1

Choose a tag to compare

@PandelisZ PandelisZ released this 28 Sep 08:38
842aef6

Codex Remote 0.5.1 — clearer first-machine setup with direct provider configuration and a copyable agent prompt; native Mac controls, a scrollable machine panel, and a simpler creation form. The app icon now appears in onboarding, and the website has fresh app captures.

Codex Remote 0.5.0

Choose a tag to compare

@PandelisZ PandelisZ released this 28 Sep 04:03
9675264

Codex Remote 0.5.0 — the first notarised build, and Amazon EC2 working end to end.

Signed with a Developer ID certificate and notarised by Apple, so a downloaded copy opens normally. Earlier builds were ad-hoc signed, which macOS reported as "damaged"; the Homebrew cask no longer has to strip the quarantine flag.

AWS: six bugs, each of which only ever appeared on EC2.

  • A Mac named with a possessive ("Pandelis's MacBook Pro", with a curly apostrophe) put a non-ASCII character in the SSH key comment, and EC2's ImportKeyPair rejects the whole request. The security group description carried an em dash and failed the same way.
  • AMI ids are region-scoped, so asking for one region while taking the recommended image from another failed with "collecting instance settings: couldn't find resource".
  • A provision that failed before the instance existed never ran tofu destroy, orphaning the key pair and security group and making every retry fail with "already exists".
  • Amazon's Ubuntu images log in as ubuntu rather than root, so the bootstrap could not write to /etc.
  • set -euo pipefail plus a grep that matched nothing ended the script silently, reporting a connected machine as failed.

Also: a real app icon (and three bugs that meant it never shipped), a share card for codexremote.io, and a fix to the cask's zap list, which still named the pre-0.4 home.

Codex Remote 0.4.1

Choose a tag to compare

@PandelisZ PandelisZ released this 27 Sep 23:48
7ebf684

Fixes the packaging bug in 0.4.0.

Scripts/bundle.sh still installed OpenTofu to ~/.codex/codex-remote/tofu, the pre-0.4.0 location. On a machine that builds from source that recreated the directory 0.4.0 had just migrated away from, and put the bundled OpenTofu somewhere the app no longer looks.

Only affects building from source — installed copies fetch and verify OpenTofu themselves on first use — but it meant the 0.4.0 migration did not stay done.

Codex Remote 0.4.0

Choose a tag to compare

@PandelisZ PandelisZ released this 27 Sep 23:44
0371c15

Codex Remote now keeps its state in ~/.codex-remote.

It used to live inside ~/.codex, which belongs to Codex. That meant codex could not clean up after itself without taking Codex Remote's state with it, and uninstalling Codex Remote could not remove its own directory without reaching into Codex's. Your machines, accounts, SSH keys and OpenTofu install move across on first launch — a move rather than a copy, so there is one directory afterwards and no question which is live. A shell profile that sourced the old shell.sh is repointed too.

Codex's own files — auth.json, config, the desktop app's state — are still read from ~/.codex, which is where they belong.

If you keep an older copy of Codex Remote running, it will recreate ~/.codex/codex-remote and write to it, and those writes are not picked up. Quit it before relying on this version.

The site no longer pins a version. The download button linked at a filename that 404s the moment a release ships; it and the version on the cover now resolve from latest.json, the same feed the app polls.

Codex Remote 0.3.0

Choose a tag to compare

@PandelisZ PandelisZ released this 27 Sep 23:12
0991d92

Project detection, self-updating, and a redesigned site.

Codex Remote now finds the projects you already work on. Both agents keep that list — Codex records local-projects with names, roots and timestamps; Claude Code keys ~/.claude.json by path. Send one with Send a project on any machine row, codex-remote projects, or the list_local_projects MCP tool so an agent offers a choice rather than asking for a path.

It keeps itself up to date. Installed copies poll codexremote.io/latest.json, which you can curl yourself. The download is verified against the SHA-256 published there — this build is not notarised, so that checksum rather than Apple is what you are trusting. A Homebrew-installed copy refuses to update itself and offers brew upgrade instead, because replacing the bundle would leave brew's records pointing at a version that is no longer there.

A download button, for anyone not using Homebrew.

CONTRIBUTING.md, which leads with adding a cloud provider — the contribution that needs neither Swift nor a release.

The site is rebuilt as the operator's guide that used to ship in the box with a workstation, and HTTPS now works on codexremote.io.

Codex Remote 0.2.0

Choose a tag to compare

@PandelisZ PandelisZ released this 27 Sep 21:54
134c440

Install

brew install --cask pandelisz/tap/codex-remote

macOS 15+, Apple silicon or Intel. Menu bar, no Dock icon.

New in 0.2.0

Bring your project with you. codex-remote push <machine> clones when your work is pushed and copies when it isn't — a dirty tree stops being cloneable rather than quietly arriving as last week's code. It sends the untracked .env files a clone cannot carry, which is the reason a clone alone always leaves you with a project that doesn't run, and skips node_modules rather than shipping macOS native modules to Linux. docs

An MCP server, so an agent can build its own machine. codex-remote mcp serve. Reading is always available; creating machines and running commands are off by default because they bill to your cloud account; destroying has its own switch, because creating the wrong machine costs pence and deleting the right one loses work. destroy_machine also requires the machine's name twice, so a name a model produced but didn't verify fails instead of deleting something real. docs

Clouds come from a registry, not a release. The provider catalogue is a JSON file fetched from codexremote.io/registry.json, so adding a cloud is a pull request. Point the app at your own registry — a homelab, your own baked-in packages — under Settings → Providers. HCL can live in its own .tf file, pinned to a SHA-256 so nobody can change what runs against your credentials after the registry was reviewed. format

The machine row says what the machine is doing. Live CPU, memory, and how many agent sessions are running, sampled over SSH. The indicator answers whether it's safe to stop: blue means up and idle, green means sessions are running. A machine that hasn't reported yet stays green rather than claiming idle.

Claude Code gets its own controls, and runs as a non-root claude account with its own login.

Fixes

  • Open Codex Remote Window did nothing — a SwiftUI Window scene has no NSWindow until something opens it
  • Sourcing shell.sh defined a codex-remote() function that shadowed the CLI of the same name
  • Per-machine launchers were named codex-codex-remote-<name>
  • The CLI could edit the machine registry while the menu bar app held it in memory, so removals were silently undone

If you download the zip instead

This build is ad-hoc signed rather than notarised, so macOS calls a downloaded copy "damaged". That's the quarantine flag, not a corrupt download, and right-click → Open does not clear it:

xattr -dr com.apple.quarantine /Applications/CodexRemote.app

Homebrew does that for you, which means trusting the tap and the checksum rather than Apple's notary. Notarisation is the real fix and isn't done yet.

Not affiliated with OpenAI or Anthropic.

Codex Remote 0.1.0

Choose a tag to compare

@PandelisZ PandelisZ released this 27 Sep 21:27
30ed2bb

First release.

A macOS menu bar app that provisions a cloud machine and wires it up as a remote Codex or Claude Code agent.

Install

brew install --cask pandelisz/tap/codex-remote

macOS 15 (Sequoia) or later, Apple silicon or Intel. It lives in the menu bar, not the Dock.

If you download the zip instead

This build is ad-hoc signed rather than notarised, so macOS refuses a downloaded copy with "CodexRemote is damaged and can't be opened". That is the quarantine flag rather than a corrupt download, and right-click → Open does not clear this particular error. Remove the flag:

xattr -dr com.apple.quarantine /Applications/CodexRemote.app

The Homebrew cask does this for you, which means trusting the tap and the checksum rather than Apple's notary. Proper notarisation is the real fix and is not done yet.

What it does

  • Creates a server with OpenTofu on Hetzner, AWS, DigitalOcean, Linode, Vultr or Scaleway — you bring the account and pay them directly
  • Installs Codex and/or Claude Code, with your MCP servers carried over
  • Writes the host into ~/.ssh/config, which is how the Codex app finds a machine and starts codex app-server on it over SSH
  • Claude Code signs in on the machine and appears in your account
  • Everything it installs is a systemd unit enabled at boot, so a stop/start brings it back

The provider catalogue is fetched from codexremote.io/registry.json, so a new cloud is a pull request rather than a release. Format: docs/registry.md.

Not affiliated with OpenAI or Anthropic.