NEW Android app and iPad support have landed→

A Desktop Control Plane
for AI Coding Agents

Operate Claude Code, Codex, Gemini CLI, Grok CLI, Aider, and more — on build servers, GPU boxes, staging hosts, and this computer. Every agent runs inside a tmux session on its host: close the client, suspend the laptop, lose the network — work continues. Now from a tablet or a phone, too.

fleet overview
PROJECTS
▾orbit-api2 agents
 ├claude-codegpu-01
 └codexdev-box
▾novel-reader3 agents
 ├aiderlocal
 ├gemini-clistaging
 └opencodeidle
SERVERS
gpu-01cpu 34% · gpu 81%
dev-boxcpu 12% · mem 7.2G
this computertmux · no sshd
agentmux — activity
SSHgpu-01 connected · host key pinned
TMUXclaude-code reattached · scrollback intact
RECVbroadcast 5/5 delivered · receipts confirmed
HOLDorchestrator proposes restart agent · awaiting approval
MEM3 memory hits · embeddings computed locally
OKfleet ready · 3 hosts · 7 agents running
[agentmux/0:fleet*]3 hosts · 20:10 · ⌃K
7agent CLIs supported out of the box
1binary: desktop · headless server · Android app
3×3terminal wall, several hosts on one screen
MIT100% open source
Ecosystem

Works with the agents and infrastructure you already run

Capabilities

Everything you need to operate a fleet of agents

AgentMux never owns the agent process — it attaches to a tmux session on the host. Persistence is guaranteed by construction, not by the client staying online.

Session persistence

Close the client, suspend the laptop, lose the network — agents keep running. Reopen and you're back in the same pane with scrollback intact. A four-hour migration no longer depends on one SSH connection staying up.

Direct terminal access

Every agent's pane is a full terminal — colour, mouse reporting, selection, search — not a transcript view. Step in mid-task, correct the agent, and hand control back without restarting the run.

A wall of terminals

Split the terminal area into up to nine panes — a 3×3 wall across hosts, each independently interactive. Drag the seams, double-click a tab to zoom, and the layout reflows with the window and is restored on next start.

Broadcast with receipts

Send one instruction to any selection of agents; each returns a receipt confirming delivery. Fan-out to a fleet is auditable rather than assumed.

Orchestration under approval

A local model served by Ollama can take an objective — say, working out why an agent stalled — one tool call at a time. Every mutating operation is held for your explicit approval; scheduled patrols are strictly read-only.

Retrieval memory, kept local

Project facts, preferences, and agent activity are indexed for retrieval by wording or by meaning. Embeddings are computed locally; nothing leaves the machine. Credentials matching known patterns are redacted before storage.

Tablet and phone, wherever you areNEW

The same binary runs headless, so a tablet browser is a complete AgentMux — terminals, agents, the toolkit, file browsing, all of it. Android goes further with a standalone app that carries the whole core: SSH runs from the device, and no always-on machine is needed.

It raises a hand when it needs youNEW

An agent asking a question, one that finished with results to review and one idle at its prompt all read as “running” before. The poll now reads each pane and classifies it, marks the transitions a person needs to see, and takes the mark down when somebody actually looks.

One-click upgrades, and a portable installNEW

It checks for new releases shortly after launch and every six hours: download, verify the published sha256, swap in place, relaunch — and roll back if the swap fails. The whole configuration also travels to another computer as one encrypted file, and an import never overwrites what is already there.

Product Tour

Real screens, real workflows

Everything below is an actual application screenshot — no concept renders.

AgentMux demo
Terminal

Attach, and it's a real terminal

Attach to any agent's tmux pane: full colour, mouse reporting, search and selection. The side panel shows process state, recent output, and lifecycle controls.

  • Start / Stop / Restart / Attach — one row of buttons for the whole lifecycle
  • An exiting agent leaves a usable shell instead of destroying the session
  • Ten terminals against one host is still one SSH connection, one authentication
Terminal attached to an agent
Coordination

Tell the whole fleet — and know who heard you

Send the same instruction to any selection of agents, across projects and hosts. Each agent returns a delivery receipt, turning fan-out from "assumed" into "confirmed, one by one."

  • Target by project, by host, or by manual selection
  • Per-agent delivery status at a glance
  • Failed deliveries stand out and can be retried individually
Broadcast with delivery receipts
Provisioning & Ops

A new host, working in minutes

The install panel inspects a host first and offers only the agent CLIs and runtimes it can actually support, stating why others are unavailable. Installation runs inside tmux, so a dropped connection can't leave a partial package tree.

  • CPU by mode and core, memory, disk, network, NVIDIA GPU telemetry
  • SFTP browser and editor with atomic writes and conflict checks
  • This computer managed with zero setup: no sshd, no credentials
Host install panel
Interface

Comfortable for an all-day watch

Apple's system palette by default, with six alternative themes including Nord, Solarized, and a light theme. Information density tuned for long supervision sessions.

  • Ctrl/⌘ K command palette reaches everything
  • Per-agent status and last output in the fleet tree
  • Seven themes, dark and light
Themes
New · tablet & phone

The same AgentMux, in your hands

Two paths beyond the desktop: headless serve mode turns any browser into a complete client, and Android has a standalone app carrying its own core. Both run the same frontend on the same core — neither is a cut-down view.

Headless serve mode

Releases ship a dedicated server build, agentmux-server-linux-{amd64,arm64} — fully static, with no GTK, no webview and no display needed. Copy it to any Linux server and run it. The desktop build enters the same mode with --serve. The first start generates an access token and prints it in the log (kept as serve-token in the data directory; AGENTMUX_TOKEN overrides it).

# server build: serves on :8642 by default
./agentmux
# desktop build, same thing
agentmux --serve --addr 0.0.0.0:8642

iPad and Android tablets: just open a browser

Point the tablet at http://host:8642, enter the token once, and everything works — terminals, agents, the toolkit, file browsing. “Add to Home Screen” (Safari on iPad, Chrome on Android) installs it as a standalone app. Closing the browser stops nothing, exactly like closing the desktop window: the agents live in remote tmux.

The native Android app needs no always-on machine

Every release attaches agentmux-android.apk (Android 8.0+ · arm64) with the same core the server build ships, embedded and started by a foreground service — foreground because Android freezes background processes at screen lock, and the core holds the SSH connections. The layout was reworked for small screens too: under 768px the side panels become overlay drawers, and a bottom navigation bar puts the tree, the command palette, the detail panel and settings where a thumb actually reaches, safe-area inset respected.

agentmux · tablet:8642
PROJECTS ▾ orbit-api
 ├ claude
 └ codex SERVERS gpu-01
dev-box
$ claude --resume
✓ reattached · scrollback intact
› reindexing…
⏸ waiting for you
$
APKarm64
$ codex
✓ ssh gpu-01
› patch applied
$
Tree ⌘K Panel Settings
Security note: serve mode authenticates with the token alone. On a LAN or over a VPN that is enough; for use over the public internet, put an HTTPS reverse proxy in front of it.
What's new

And this round also brought

Beyond tablets and phones, the August round landed the following.

01Reconnects on its own

A terminal that lost its transport is not over — the tmux session on the far side is still running. The pipe is rebuilt with the same shell id, the same scrollback and the same pane, backing off from one second to fifteen and leaving the manual button after about five minutes. Two keepalives, TCP and SSH, answer different questions; one-shot command terminals are exempt, because re-running an install is a side effect nobody asked for.

02Remote desktop over the connection it already has

Some work is a screen. Right-click a host and 3389 or 5900 is dialled through the SSH connection that host already has, forwarded to a port here and handed to whichever viewer this computer has — Remote Desktop Connection, Screen Sharing, Remmina. A desktop listening on its own loopback needs nothing opened to the network.

03One-click upgrades

The app checks the release feed shortly after launch and every six hours after. A newer version raises a one-line banner under the title bar: upgrade and restart, release notes, or later. Upgrading downloads with a progress bar, verifies the published sha256, swaps the running executable, and rolls back to the build that was running if the swap fails.

04Carry an installation, encrypted

Hosts, folders, projects, workspaces and agent definitions go into a single passphrase-encrypted file (Argon2id + AES-256-GCM) and open on the other side. An import never overwrites: a host at the same address, a project with the same name, a path on the same machine — each is left exactly as it is, so importing twice adds nothing.

05What a host is, not just what it is doing

The metrics panel now reports CPU model, DIMM specs, physical drives and graphics adapters alongside utilisation. Those are static, so they ride a one-shot read cached for the session rather than the three-second ticker.

06More toolkit, more languages

One-click install now covers Grok CLI, Docker (six methods, retrying against a mirror where the network needs one, then starting the daemon and adding the user to the group) and Ollama. The interface adds Traditional Chinese — a full catalogue in Taiwan terminology, not a character-for-character conversion.

Security Model

Permissions, credentials, and audit — built into the structure

These aren't settings. They're design decisions, and most of them cannot be switched off.

Encrypted credentials

Passwords and key passphrases are encrypted with AES-256-GCM before storage; the key lives in the OS keychain (Keychain, Credential Manager, Secret Service). If the keychain is unavailable, a 0600-file fallback is reported in the status bar.

Host keys pinned

Host keys are pinned on first connection. Any subsequent mismatch aborts the connection with an explanation — a man-in-the-middle swap cannot pass silently.

Secrets never reach the UI

No secret crosses into the UI process. The interface learns only whether a secret is set — never its value.

Tool gate with risk tiers

The orchestrator can only call a fixed whitelist of tools, each carrying a risk tier fixed at declaration. Execution passes through a single gate combining tier, host trust level, and the run's trigger.

Unattended = read-only

Scheduled patrols are refused every non-read tool unconditionally — and that restriction is not configurable. A patrol can report a stalled agent, but has no authority to act on it.

Fully auditable

Every step of every run is recorded — including proposals that were refused, rejected, or left unanswered. Remote output enters the model marked as data; instruction-shaped text raises a flag on the approval card.

Operating Scenarios

Built for these ways of working

01Long-running workloads

Migrations, refactors, and test campaigns that outlast a working session or a network link.

02Multi-host fleets

Three to fifty hosts with concurrent agent activity, presented as one tree with per-agent status.

03Coordinated changes

Instruct an entire fleet in one action, with confirmation of what was delivered.

04Provisioning

Bring a new host to a working state without assembling install commands by hand.

05Unattended monitoring

Scheduled read-only patrols that report stalled agents — without authority to act on them.

06Restricted environments

Planning, embeddings, and memory run locally. No proxying of agent model traffic, no reading of API keys.

Get Started

Four steps to your first managed agent

Unix-like remote hosts need only tmux and an SSH account — AgentMux can install tmux where it's missing; a remote Windows host just needs OpenSSH Server. This computer is even simpler: no credentials at all.

Read the full docs→
  1. 1

    Add a host

    Remote: address, user, and one of ssh-agent / key / password, with jump hosts supported. Local: nothing but a name.

  2. 2

    Add a project and workspace

    A working directory on that host. Or browse the host's files and add the directory in place — its name, path, and host are already known.

  3. 3

    Add an agent and start it

    A name and the command that starts it. Hit Start and it's running inside tmux on the host.

    claude --dangerously-skip-permissions
  4. 4

    ⌃K opens the command palette

    Attaching to an agent, opening a shell, installing a CLI, changing theme — the fastest route to all of it.

    Ctrl / ⌘ + K
Ctrl/⌘KCommand palette
Ctrl/⌘BShow or hide the tree
Ctrl/⌘\Add a pane — instantly with the next open tab, otherwise asking what to attach
Ctrl/⌘⇧\Close the pane, leaving the tab and its shell open
Ctrl/⌘⇧↵Fill the area with the focused pane, and back again
Ctrl/⌘⌥←→Move between panes — zoomed, this reads them one at a time
Download

Desktop, server and Android — one build per platform

All produced by GitHub Actions from a tagged commit, each file with a .sha256 alongside.

macOS

macOS 11+ · Universal for Intel & Apple Silicon

agentmux-macos-universal.zip

Download ↓

Windows

Windows 10+ · WSL and native PowerShell local hosts

agentmux-windows-amd64.zip

Download ↓

Linux

GTK3 & WebKitGTK 4.1 required · amd64

agentmux-linux-amd64.tar.gz

Download ↓

Tablet / server (headless)NEW

Any Linux · amd64 and arm64 · no GTK, no webview, no display

agentmux-server-linux-amd64.tar.gz
agentmux-server-linux-arm64.tar.gz

Download ↓

AndroidNEW

Android 8.0+ · arm64 · embeds the full core, runs standalone

agentmux-android.apk

Download ↓
Note: builds are not yet code-signed or notarized. On macOS, choose Open Anyway in Privacy & Security on first launch (or xattr -dr com.apple.quarantine); on Windows, "More info → Run anyway". Downloading with curl -L -O avoids the macOS quarantine attribute.
FAQ

Questions you might have

Does AgentMux decide what my agents do?+

No. Objectives, prompts, and repository conventions remain yours. The orchestrator investigates and proposes; any action that modifies a host executes only after your explicit approval.

What do hosts need?+

Remote Unix-like hosts (Linux / macOS) need a POSIX shell, tmux, and SSH (AgentMux can install tmux where it's missing); a remote Windows host just needs OpenSSH Server enabled — sessions are hosted by AgentMux's own session daemon, deployed over SFTP on first use. This computer qualifies directly on Linux and macOS; on Windows the same machine offers two local hosts — the WSL distribution (where tmux lives) and native Windows (PowerShell, persisted by the same daemon, so closing the window does not stop native work either).

Is Ollama required?+

No. Only local orchestration and semantic memory search need Ollama (one chat model plus one embedding model). Without it, everything else is fully functional.

Can it report or cap my agents' model spend?+

No — deliberately. Agent traffic goes straight from the host to whichever provider the agent CLI is configured for. AgentMux does not proxy it and does not read the keys, so it can neither report cost nor enforce a budget.

Is it built for teams?+

One operator per installation. State, credentials, and the decision log live on the workstation — no shared server, no team account, no central audit sink. Two people working the same fleet see the same tmux sessions but keep separate histories.

Does deleting something in AgentMux stop remote work?+

Never. Removing a workspace or agent record only removes the local record — the tmux session keeps running. The one control that destroys a running session is named Kill, and it confirms first, stating what is lost.

How do I use it on a tablet or a phone?+

Two ways. Run the headless server on any Linux machine — the dedicated agentmux-server-linux-{amd64,arm64} build, or the desktop build with --serve — then open http://host:8642 on the tablet, enter the token once and “Add to Home Screen” for a standalone app. That is the iPad route. On Android you can instead install agentmux-android.apk, which embeds the full core and needs no server at all.

What is the difference between the Android APK and serve mode?+

In serve mode the core runs on one of your machines and the tablet is a client, so phone, tablet and desktop see the same state. The APK puts the core on the device itself: SSH runs from the phone, configuration and keys stay local, and no always-on machine is involved. The foreground service is deliberate — without it Android freezes the process at screen lock and cuts every SSH connection.

Is serve mode safe to expose to the internet?+

It authenticates with an access token alone, generated on first start and kept as serve-token in the data directory. That is enough on a LAN or over a VPN; for public access, put an HTTPS reverse proxy in front rather than exposing plain HTTP.

Let the agents run. Go get some rest.

One binary, one SQLite file, zero servers. Download and go — MIT licensed.