agent-tether
v0.1.1
Published
Local daemon that lets a public web page drive Claude Code on your own machine
Maintainers
Readme
agent-tether
Local daemon that lets a web page drive Claude Code running on your own machine. Code execution and file access stay local; the browser is just the window.
npx agent-tether --root ~/my-project --model sonnetThe first time a web app connects, the daemon asks you in the terminal. Nothing happens until
you approve, and the session is confined to --root — unless you pass --allow-exec, which
hands over a shell and makes that confinement meaningless.
Pair it with agent-tether-client in the browser:
import { createTether } from 'agent-tether-client';
const t = await createTether({ app: 'My App', autoConnect: false });
await t.connect(); // call this from a user gesture
for await (const ev of t.prompt('summarize this folder')) {
if (ev.type === 'text') render(ev.delta);
}Options
-r, --root <path> Directory the daemon is allowed to touch (default: cwd)
-p, --port <n> Port (default: 5411)
-m, --model <name> Model, e.g. sonnet
--allow-exec Allow shell (Bash). Off by default — turning it on makes --root meaningless
--grant-days <n> Grant lifetime in days, default 7 (0 = never expires)
-y, --yes Auto-approve consent (development only — any site can attach)
--no-ask Don't relay permission prompts to the web UI
-v, --verbose Log SDK messages
tether grants List approved origins
tether grants rm <origin> RevokeAudit log: ~/.tether/audit.log
Security
This intentionally crosses the browser sandbox boundary. Give it a dedicated directory, leave
--allow-exec off, and stop the daemon when you're done — a shell voids --root by
construction. The repository lists what is
and isn't defended.
MIT © esc5221
