Codex Remote 0.2.0
Install
brew install --cask pandelisz/tap/codex-remotemacOS 15+, Apple silicon or Intel. Menu bar, no Dock icon.
New in 0.2.0
Bring your project with you. codex-remote push <machine> clones when your work is pushed and copies when it isn't — a dirty tree stops being cloneable rather than quietly arriving as last week's code. It sends the untracked .env files a clone cannot carry, which is the reason a clone alone always leaves you with a project that doesn't run, and skips node_modules rather than shipping macOS native modules to Linux. docs
An MCP server, so an agent can build its own machine. codex-remote mcp serve. Reading is always available; creating machines and running commands are off by default because they bill to your cloud account; destroying has its own switch, because creating the wrong machine costs pence and deleting the right one loses work. destroy_machine also requires the machine's name twice, so a name a model produced but didn't verify fails instead of deleting something real. docs
Clouds come from a registry, not a release. The provider catalogue is a JSON file fetched from codexremote.io/registry.json, so adding a cloud is a pull request. Point the app at your own registry — a homelab, your own baked-in packages — under Settings → Providers. HCL can live in its own .tf file, pinned to a SHA-256 so nobody can change what runs against your credentials after the registry was reviewed. format
The machine row says what the machine is doing. Live CPU, memory, and how many agent sessions are running, sampled over SSH. The indicator answers whether it's safe to stop: blue means up and idle, green means sessions are running. A machine that hasn't reported yet stays green rather than claiming idle.
Claude Code gets its own controls, and runs as a non-root claude account with its own login.
Fixes
Open Codex Remote Windowdid nothing — a SwiftUIWindowscene has noNSWindowuntil something opens it- Sourcing
shell.shdefined acodex-remote()function that shadowed the CLI of the same name - Per-machine launchers were named
codex-codex-remote-<name> - The CLI could edit the machine registry while the menu bar app held it in memory, so removals were silently undone
If you download the zip instead
This build is ad-hoc signed rather than notarised, so macOS calls a downloaded copy "damaged". That's the quarantine flag, not a corrupt download, and right-click → Open does not clear it:
xattr -dr com.apple.quarantine /Applications/CodexRemote.appHomebrew does that for you, which means trusting the tap and the checksum rather than Apple's notary. Notarisation is the real fix and isn't done yet.
Not affiliated with OpenAI or Anthropic.