Releases: PandelisZ/codex-remote
Release list
Codex Remote 0.5.2
Codex Remote 0.5.1
Codex Remote 0.5.1 — clearer first-machine setup with direct provider configuration and a copyable agent prompt; native Mac controls, a scrollable machine panel, and a simpler creation form. The app icon now appears in onboarding, and the website has fresh app captures.
Codex Remote 0.5.0
Codex Remote 0.5.0 — the first notarised build, and Amazon EC2 working end to end.
Signed with a Developer ID certificate and notarised by Apple, so a downloaded copy opens normally. Earlier builds were ad-hoc signed, which macOS reported as "damaged"; the Homebrew cask no longer has to strip the quarantine flag.
AWS: six bugs, each of which only ever appeared on EC2.
- A Mac named with a possessive ("Pandelis's MacBook Pro", with a curly apostrophe) put a non-ASCII character in the SSH key comment, and EC2's ImportKeyPair rejects the whole request. The security group description carried an em dash and failed the same way.
- AMI ids are region-scoped, so asking for one region while taking the recommended image from another failed with "collecting instance settings: couldn't find resource".
- A provision that failed before the instance existed never ran tofu destroy, orphaning the key pair and security group and making every retry fail with "already exists".
- Amazon's Ubuntu images log in as ubuntu rather than root, so the bootstrap could not write to /etc.
- set -euo pipefail plus a grep that matched nothing ended the script silently, reporting a connected machine as failed.
Also: a real app icon (and three bugs that meant it never shipped), a share card for codexremote.io, and a fix to the cask's zap list, which still named the pre-0.4 home.
Codex Remote 0.4.1
Fixes the packaging bug in 0.4.0.
Scripts/bundle.sh still installed OpenTofu to ~/.codex/codex-remote/tofu, the pre-0.4.0 location. On a machine that builds from source that recreated the directory 0.4.0 had just migrated away from, and put the bundled OpenTofu somewhere the app no longer looks.
Only affects building from source — installed copies fetch and verify OpenTofu themselves on first use — but it meant the 0.4.0 migration did not stay done.
Codex Remote 0.4.0
Codex Remote now keeps its state in ~/.codex-remote.
It used to live inside ~/.codex, which belongs to Codex. That meant codex could not clean up after itself without taking Codex Remote's state with it, and uninstalling Codex Remote could not remove its own directory without reaching into Codex's. Your machines, accounts, SSH keys and OpenTofu install move across on first launch — a move rather than a copy, so there is one directory afterwards and no question which is live. A shell profile that sourced the old shell.sh is repointed too.
Codex's own files — auth.json, config, the desktop app's state — are still read from ~/.codex, which is where they belong.
If you keep an older copy of Codex Remote running, it will recreate ~/.codex/codex-remote and write to it, and those writes are not picked up. Quit it before relying on this version.
The site no longer pins a version. The download button linked at a filename that 404s the moment a release ships; it and the version on the cover now resolve from latest.json, the same feed the app polls.
Codex Remote 0.3.0
Project detection, self-updating, and a redesigned site.
Codex Remote now finds the projects you already work on. Both agents keep that list — Codex records local-projects with names, roots and timestamps; Claude Code keys ~/.claude.json by path. Send one with Send a project on any machine row, codex-remote projects, or the list_local_projects MCP tool so an agent offers a choice rather than asking for a path.
It keeps itself up to date. Installed copies poll codexremote.io/latest.json, which you can curl yourself. The download is verified against the SHA-256 published there — this build is not notarised, so that checksum rather than Apple is what you are trusting. A Homebrew-installed copy refuses to update itself and offers brew upgrade instead, because replacing the bundle would leave brew's records pointing at a version that is no longer there.
A download button, for anyone not using Homebrew.
CONTRIBUTING.md, which leads with adding a cloud provider — the contribution that needs neither Swift nor a release.
The site is rebuilt as the operator's guide that used to ship in the box with a workstation, and HTTPS now works on codexremote.io.
Codex Remote 0.2.0
Install
brew install --cask pandelisz/tap/codex-remotemacOS 15+, Apple silicon or Intel. Menu bar, no Dock icon.
New in 0.2.0
Bring your project with you. codex-remote push <machine> clones when your work is pushed and copies when it isn't — a dirty tree stops being cloneable rather than quietly arriving as last week's code. It sends the untracked .env files a clone cannot carry, which is the reason a clone alone always leaves you with a project that doesn't run, and skips node_modules rather than shipping macOS native modules to Linux. docs
An MCP server, so an agent can build its own machine. codex-remote mcp serve. Reading is always available; creating machines and running commands are off by default because they bill to your cloud account; destroying has its own switch, because creating the wrong machine costs pence and deleting the right one loses work. destroy_machine also requires the machine's name twice, so a name a model produced but didn't verify fails instead of deleting something real. docs
Clouds come from a registry, not a release. The provider catalogue is a JSON file fetched from codexremote.io/registry.json, so adding a cloud is a pull request. Point the app at your own registry — a homelab, your own baked-in packages — under Settings → Providers. HCL can live in its own .tf file, pinned to a SHA-256 so nobody can change what runs against your credentials after the registry was reviewed. format
The machine row says what the machine is doing. Live CPU, memory, and how many agent sessions are running, sampled over SSH. The indicator answers whether it's safe to stop: blue means up and idle, green means sessions are running. A machine that hasn't reported yet stays green rather than claiming idle.
Claude Code gets its own controls, and runs as a non-root claude account with its own login.
Fixes
Open Codex Remote Windowdid nothing — a SwiftUIWindowscene has noNSWindowuntil something opens it- Sourcing
shell.shdefined acodex-remote()function that shadowed the CLI of the same name - Per-machine launchers were named
codex-codex-remote-<name> - The CLI could edit the machine registry while the menu bar app held it in memory, so removals were silently undone
If you download the zip instead
This build is ad-hoc signed rather than notarised, so macOS calls a downloaded copy "damaged". That's the quarantine flag, not a corrupt download, and right-click → Open does not clear it:
xattr -dr com.apple.quarantine /Applications/CodexRemote.appHomebrew does that for you, which means trusting the tap and the checksum rather than Apple's notary. Notarisation is the real fix and isn't done yet.
Not affiliated with OpenAI or Anthropic.
Codex Remote 0.1.0
First release.
A macOS menu bar app that provisions a cloud machine and wires it up as a remote Codex or Claude Code agent.
Install
brew install --cask pandelisz/tap/codex-remotemacOS 15 (Sequoia) or later, Apple silicon or Intel. It lives in the menu bar, not the Dock.
If you download the zip instead
This build is ad-hoc signed rather than notarised, so macOS refuses a downloaded copy with "CodexRemote is damaged and can't be opened". That is the quarantine flag rather than a corrupt download, and right-click → Open does not clear this particular error. Remove the flag:
xattr -dr com.apple.quarantine /Applications/CodexRemote.appThe Homebrew cask does this for you, which means trusting the tap and the checksum rather than Apple's notary. Proper notarisation is the real fix and is not done yet.
What it does
- Creates a server with OpenTofu on Hetzner, AWS, DigitalOcean, Linode, Vultr or Scaleway — you bring the account and pay them directly
- Installs Codex and/or Claude Code, with your MCP servers carried over
- Writes the host into
~/.ssh/config, which is how the Codex app finds a machine and startscodex app-serveron it over SSH - Claude Code signs in on the machine and appears in your account
- Everything it installs is a systemd unit enabled at boot, so a stop/start brings it back
The provider catalogue is fetched from codexremote.io/registry.json, so a new cloud is a pull request rather than a release. Format: docs/registry.md.
Not affiliated with OpenAI or Anthropic.