English · 简体中文
Try it free · Self-host · Features · Compare with Codex · Vision · Contribute · Security
Pick up your Codex work from any browser.
Follow conversations across your machines. Continue the same native session.
Keep execution in your own environment.
A self-hosted operations console for Codex CLI across Linux servers and personal computers.
Manage native sessions, send files and images, use installed plugin skills, and track usage from one English or Chinese web interface.
Actual interface with synthetic demo data. No production accounts, hosts, or conversations are shown.
Visit https://www.agentfleets.cn to try the hosted panel for free, without deploying your own server.
- Open the console from the website and sign in with your email verification code.
- Choose Add host, then run the installation command on a computer where you already use Codex.
- Once connected, choose a project and session to continue your work from a desktop or mobile browser.
Tasks execute on your connected host. Bring your own Codex account and available quota; the free panel experience does not include Codex credits. If you prefer to run the panel yourself, follow Self-host.
- Panel-wide voice control (experimental). The globe button in the top toolbar opens a separate call that stays connected as you navigate the panel. Choose the voice host, then name an authorized host, project and managed session. The coordinator searches for the target, dispatches and follows one task at a time, and reports verified results. Your existing per-session calls remain available. Hanging up does not cancel dispatched work; reconnect to query its status. Requires Agent 0.30.69 and Codex 0.159.2 on the voice host. Closing the page or backgrounding the browser ends the call.
- Talk to native Codex in realtime (experimental). In a managed, idle Codex session, choose Start voice, allow microphone access, then talk, mute, or end the connection. Requires a supported host runtime (currently validated with Agent 0.30.69 and Codex 0.159.2) and a modern HTTPS browser. Calls use Sol by default and renew control in the background. Closing the page or moving the browser to the background ends the call. Voice can start development tasks using the session’s permissions and approvals; ending voice closes the microphone without cancelling tasks already started. During calls, send text or images immediately when idle, or add them to the active task; queued messages wait until the call and active task finish. Voice tasks show the model and reasoning effort read from the native session.
- Schedule routine work. Search for a project or an existing managed session, choose the destination first, then set the prompt and schedule. Review each run in Scheduled tasks → History. For example, ask Codex to check a project every weekday morning.
- Give another task relevant conversation context. Paste a copied session link or use + → Reuse session. Send the reference card with your instructions; Codex consults the readable conversation snapshot as needed, without waiting for a separate AI summary.
- Send screenshots from your phone. Choose an image from the + menu or paste it on desktop. Improved browser compatibility for automatic resizing and compression reduces oversized-image failures on mobile.
- Use the panel on smaller screens. Mobile navigation uses compact labels; login forms fit narrow screens; scheduled-task cards follow the selected theme. Mobile usage dialogs show concise details first and provide a close button.
- Find one clear recovery entry. Switching between offline hosts no longer accumulates duplicate repair panels. Recovery guidance explains when local repair is needed; simply leaving the panel unused does not require repairing a host.
Running Codex on several machines creates a management task of its own: finding the right session, checking which jobs are still running, returning to finished results, and keeping track of settings and usage. AgentFleets brings those everyday operations into one graphical workspace.
Think of each enrolled host as a place where Codex executes work, and AgentFleets as the console you use to supervise it. This is particularly useful for headless Linux servers: the server runs Codex and the Agent, while you interact through a browser on another computer. No graphical desktop is required on the execution host. Once enrolled, hosts connect outward to your control plane; routine session management does not require opening an SSH terminal for each machine.
| Available today | What it makes easier |
|---|---|
| Graphical Codex session management | Browse hosts, projects, and conversations; continue native sessions; adjust model settings and execution permissions in the panel. |
| Reuse a session in another task | Copy a session link or choose one from the composer, then describe the task and send. AgentFleets validates access and stages a fixed, readable conversation snapshot on the target host; Codex searches it for relevant details. No panel AI summary is required. Reasoning and command output are excluded, and missing history is marked. Each reference is limited to 4 MB; up to two references may be sent together. |
| Files, folders, and images sent to a remote session | Use one attachment menu to paste images or upload bounded files and folders. AgentFleets safely stages files on the selected host and sends native Codex references. |
| Native goals, Plan mode, and plugin skills | Set a persistent session goal, switch the next turn to a host-advertised collaboration mode, and select skills from installed, enabled Codex plugins. |
| Host files in conversation results | Open or download files linked by Codex directly from the message. Bytes stream on demand from the bound host and remain limited to that session's registered project. |
| An overview across multiple hosts | Follow running work, return to completed-but-controlled sessions, queue follow-up messages, and inspect recorded tokens and reported account quota. |
| Scheduled work in a project | Run a prompt once, every N minutes, daily, on weekdays, or on chosen weekdays in a named time zone. Use a managed session or create a fresh one per run; inspect results in the Scheduled tasks History. |
| Switchable interface themes | Choose from 17 themes, with Castle in the Sky as the default for new browsers. Five Chinese classics join illustrated themes with coordinated messages, Markdown, code blocks and composers. |
For example, paste a screenshot of a broken page on your laptop, select the session on your Linux host, and ask Codex to investigate the project there. The current composer accepts pasted PNG, JPEG, and WebP images, up to four per message, with previews and automatic resizing/compression. Submission requires a host runtime and model that support image input.
Codex CLI already supports image and local-path inputs; AgentFleets makes those workflows accessible through a browser across enrolled hosts. See the official Codex CLI documentation. The + menu accepts images and up to 32 files, with a 4 MB per-file and 8 MB combined limit, or a folder while preserving its relative structure. Supported inputs include structurally checked PDF and macro-free XLSX files, UTF-8 text, common source code, configuration, and structured data. Validation runs in the browser, control plane, and host Agent; changing a binary file's extension does not bypass it. Other Office formats, archives, audio, video, and executables are rejected. Accepted files are staged under the selected project and passed to Codex as native path references. Files that Codex links in a reply can also be previewed or downloaded from the execution host on demand.
You should not have to know the exact technical term before asking for help. Writing assistance helps turn what you mean into a request you can review and send, without leaving the conversation.
- Find the words as you type. Chinese and English term suggestions cover programming, agents, office work, engineering, games, video editing, philosophy and cognition. Recall a name such as “ripple edit” or “metacognition” without interrupting your work to search for it.
- Start in everyday language. “Play the next shot audio before cutting to its picture” can surface a suggestion for an audio lead-in. “Am I only looking for evidence supporting my own view” can prompt a check for confirmation bias. Suggestions help frame the question; they do not decide the answer for you.
- Improve wording when you want to. Click Improve wording to request one concise rewrite that aims to preserve your intent and constraints. AI-assisted results are labeled, and you choose whether to apply, edit or ignore them.
- Keep familiar language close at hand. Suitable terms and explicit rewrites from synced conversations are added automatically, so you do not have to maintain a dictionary or approve entries one by one.
- Use it comfortably on a phone or desktop. Tap suggestions on mobile or use Tab for input completion on desktop. Longer wording suggestions show up to four lines on mobile, keeping the composer usable.
Choose your writing assistance defaults once in Settings, then adjust individual conversations when needed. Basic completion and local wording suggestions work without an external AI account; the optional Improve wording action uses the provider you configure.
The aim is fewer interruptions and clearer requests for both specialists and people working outside their expertise. Coverage continues to grow; a suggestion is an aid to expression, not a guarantee that every phrase is understood.
Type part of a term to find the name you need, then choose a suggestion without leaving the conversation.
Real interface with fictional conversations and simulated suggestions. No production account data or live model responses are shown.
Every computer. Any operating system. Codex as the interface. AgentFleets in control.
We want Codex to become the single entry point for operating every computer—from writing code and managing files to running applications and maintaining systems. AgentFleets would connect those computers into one workspace, where you can direct work, follow progress, and manage access without switching between machines or learning a different workflow for each operating system.
Codex acts on each computer. AgentFleets coordinates the fleet. You decide what they can do.
Today, AgentFleets manages native Codex sessions on supported Linux, macOS, and Windows hosts. The next horizon is broader operations through Codex:
- A consistent operations entry point: extend the workflow from individual coding sessions toward everyday application and system maintenance across operating systems.
- Coordinated work across hosts: move toward explicit multi-host workflows with task dependencies and progress tracking. Today's panel manages sessions on each host; it does not automatically schedule one job across the fleet or migrate its conversation and Git state.
- Richer remote inputs: expand beyond the current bounded file, folder, image, goal, Plan mode, and installed-plugin workflows while retaining host-side validation.
These are future directions, not shipped features or a delivery schedule. Universal operating-system support and a complete interface for every computer operation remain goals. AgentFleets currently provides Codex session operations, not a general server monitoring or operating-system patch management system. User workspaces are isolated; shared team permissions remain outside the current scope.
Scheduled tasks run through the same host and native-session controls as a manual send. If a host is offline or a project is busy, the latest due run waits; missed runs are coalesced, and anything more than 24 hours late expires. An uncertain result is recorded for review and is never sent again automatically. The History tab on the Scheduled tasks page keeps recent results; Pending remains for approvals and questions.
| Click Running, Controlled, or Online hosts, then jump straight to the session or machine you need. Skip browsing project trees across your fleet. | Take control, send a message, and release back to the host. Rename a session without changing its native identity. | Follow streaming output, add instructions to a running turn, or queue the next message. Choose execution permissions per session. |
| Unknown outcomes freeze writes. Verify the host and unfreeze manually, with no automatic replay of uncertain actions. | Inspect staged files by type and session. Preview supported cleanup before confirming it, with conversation text and native session identity preserved. | Inherit Codex model and reasoning-effort settings, set host defaults once, and override individual sessions when needed. Avoid configuring every conversation from scratch. |
| Show weekly and five-hour quota windows plus the current credit balance reported by Codex on the host. | Compare total and current-cycle usage by project and session, including per-turn and weekly cache hit rates. | Attach supported files, folders and images; select installed plugins with + or @; keep goals and Plan mode visible in the composer. |
The sidebar counts are shortcuts: click a category, then select a host or session to open it directly across your fleet. No need to remember which project contains a conversation or expand hosts and projects one by one.
| Shortcut | What you can reach |
|---|---|
| Running | Sessions with an active turn, including work waiting for your answer or approval |
| Controlled | Sessions still under AgentFleets control, including completed tasks whose results you want to review or follow up on |
| Online hosts | Connected hosts, with direct access to their workspace |
Use Running to follow progress and Controlled to return to results. When a turn finishes, its session leaves Running. As long as control has not been released, you can still find it under Controlled to review the output or send the next instruction without browsing hosts and projects again. Controlled also includes active sessions; it is not a completed-only filter.
Counts and open lists update as reported state changes. Controlled means currently controlled, not recently viewed or previously controlled; released sessions are not a takeover-history list. This workflow is especially useful when several tasks are spread across multiple hosts and projects.
The model shortcut above the composer shows saved model settings and reasoning effort. Draft changes and failed saves do not update the shortcut or send settings; running tasks retain their current configuration.
Keep using Codex's own configuration when no panel override is set. Or save host defaults once and make exceptions for a particular session. Existing project defaults participate in the same precedence:
Session settings → project settings → host defaults → Codex's own configuration (highest priority first).
For example, keep a host's everyday model and reasoning effort as its default, then give one demanding session a different supported model or deeper reasoning. Clear that session's override to return to the applicable defaults. Where the host runtime supports them, the panel also exposes plan/execution mode, service tier, and communication style.
The save button tracks the selected target scope. It is disabled when the form already matches the saved host, project, or session configuration; editing a value enables it, and a successful save or reverting to the saved values disables it again. This makes pending configuration changes visible before the next send.
- Fewer repeated choices: reuse saved settings across sessions instead of selecting the model and reasoning effort every time.
- Visible configuration: inspect the selected source, recently observed runtime values, and the settings last accepted by the host. A saved preference is not proof of the provider's final model choice.
- Controlled changes: saved defaults are used for subsequent sends; they do not rewrite the host's
config.tomlor change a turn already running. Choices are validated against the host's reported capabilities.
Together with direct access to running and completed-but-controlled sessions, native-session continuity, message queues, and explicit recovery, these are the workflows AgentFleets focuses on making easier. They are practical product strengths, not claims that other Codex clients lack similar features.
AgentFleets continues the same native Codex thread, including its history and identity. Codex performs its own automatic context management as a conversation grows. When you want explicit control, the session tools can request native context compaction without creating a replacement conversation. The panel labels the request and its result separately because acceptance does not mean compaction has already finished.
The composer keeps the active goal, Plan mode, installed plugin selection, model and reasoning effort close to the message. Plugins can be selected from the + menu or found by typing @; only capabilities advertised by the connected host are offered.
Choose from 17 themes, with Castle in the Sky as the default for new browsers. Five Chinese classics join Cyberpunk, The Matrix, Frozen and other illustrated themes. Each coordinates scene artwork, component borders, message bubbles, Markdown tables and quotations, code blocks and the composer.
On desktop, use the theme control below Controlled in the left sidebar. On narrow screens, open the navigation menu; the full theme selector is also available in Settings. The layout adapts to mobile widths, and the selected theme is remembered in the current browser.
All screenshots use fictional demo data. Browse all 17 desktop themes and 6 mobile previews.
Havoc in Heaven![]() |
A Thousand Li of Rivers and Mountains![]() |
|---|---|
Legend of the White Snake![]() |
The Matrix![]() |
Harry Potter![]() |
Peter Rabbit Garden![]() |
Open Usage or the summary on a host, project, or session to see three related views:
- Official account limits: weekly and five-hour quota windows, reset times, and the current credit balance, read from native Codex on the host. Hosts that report the same account are deduplicated instead of having their limits added together.
- Recorded token usage: total and current weekly-cycle tokens by machine, project, and session. Session timelines also show the tokens used by each completed turn when Codex reports them.
- Cache efficiency: per-turn and weekly cache hit rates, calculated as cached input tokens divided by input tokens. Rankings show which projects and sessions account for the recorded usage, with pagination for longer lists.
Quota and credits are shared by a Codex account; project and session figures are recorded observations, not an allocation of the account's official percentage or credit balance. Collection starts with managed-session notifications and does not reconstruct earlier history or standalone CLI work. Missing, partial, and stale data are labeled explicitly. Account limits update from native events, an initial connection query, and manual refresh; the browser reads the stored snapshot without polling every host each minute. See usage accounting for coverage and counting rules.
The dashboard above is the real interface populated only with fictional hosts, projects, sessions, quota and credit values.
AgentFleets adds a self-hosted management interface around Codex. The host's Codex runtime still executes the work; AgentFleets does not supply a model, a subscription, or extra usage quota.
Codex CLI is the terminal interface. The official desktop app provides a graphical workspace. AgentFleets focuses on administering enrolled hosts and their native sessions through your own browser-based panel.
| Area | Official desktop Remote Control | AgentFleets |
|---|---|---|
| Access | Supported desktop/mobile apps | Hosted or self-hosted web panel |
| Device identity | Same ChatGPT account and workspace, plus device authorization | Independent panel login and one-time host enrollment |
| Connection | Authorized devices connect through the official relay | Agent on each host connects outward to your control plane |
| Continue work | Continue chats and steer active work remotely | Continue native sessions with explicit take-control/release handling |
| Administration | Official app connection settings | Host/project/session overview, queues, manual unfreeze, retention and supported image cleanup |
| Operation | Official client setup | You operate HTTPS, storage, backups and updates |
How do accounts and authorization differ across these three connection methods?
- Official Remote Control pairs devices. To control your home computer from your laptop, both apps must use the same ChatGPT account and ChatGPT workspace—not a project folder. Enable remote access on the host and authorize the device pairing. Signing in alone does not grant control.
- Official SSH connects to projects on a server. To use a Linux development server, you need SSH login access and Codex installed and authenticated there, then add a remote project in the desktop app. This uses SSH login rather than device pairing; the official SSH setup does not list matching ChatGPT accounts and workspaces as a requirement. See the official remote connection guide.
- AgentFleets enrolls hosts in your own web panel. Install an Agent on each host and pair it using a one-time credential issued by the panel. The panel account manages hosts; each host's Codex account runs its tasks. Those Codex accounts can differ from each other and from the panel email, but every host needs valid Codex authentication and permissions.
AgentFleets supports multiple users through Django and Resend email verification. First sign-in creates a private workspace; machines, projects and sessions are isolated per user. Codex accounts and quotas remain on each host. Shared team permissions are not provided. The administrator-only Admin tab contains user management, managed upgrades and system information. Users retain control of their own hosts and sessions. See permissions and account administration.
Use the official app if its remote workflow meets your needs. Choose AgentFleets when you want to operate and customize your own multi-host web panel. Features overlap: remote continuation is not exclusive to AgentFleets. AgentFleets controls sessions where they live; it does not currently migrate a conversation and its Git state between hosts. Release its writer before opening that same native session in another client.
AgentFleets runs as a Docker Compose application. You need:
- A Linux server with Git, Docker, and Docker Compose
- A domain name with HTTPS for access from other devices
- At least one Linux, macOS, or Windows host signed in to Codex
Source builds download dependencies and platform runtime artifacts, so the deployment server needs internet access.
git clone https://github.com/JosephJagger/AgentFleet.git
cd AgentFleet
cp .env.example .envOpen .env and set these values:
ADMIN_EMAIL=you@example.com
AUTH_MODE=email
DJANGO_AUTH_URL=http://identity:8000
DJANGO_AUTH_SERVICE_TOKEN=generate-a-unique-secret-of-at-least-32-characters
DJANGO_SECRET_KEY=generate-another-unique-secret-of-at-least-32-characters
RESEND_API_KEY=your-resend-api-key
RESEND_FROM_EMAIL=login@your-verified-domain.example
RESEND_FROM_NAME=AgentFleets
PUBLIC_ORIGIN=https://panel.example.com
ALLOWED_ORIGINS=https://panel.example.com
COOKIE_SECURE=true
PUBLISH_HOST=127.0.0.1Replace the email, sender and example domain with your own values. Generate the two Django secrets independently with openssl rand -hex 48. Resend sends a six-digit code; no password is required. The sender must use a verified Resend domain. Keep the existing ADMIN_EMAIL on upgrades so its workspace is retained. Do not add a path or trailing slash to either origin. .env is excluded from Git. See the Django identity service for limits, local development and backup requirements.
If the reverse proxy passes client-address headers, add only its verified direct address to TRUSTED_PROXIES. Leave that setting unset when you do not need forwarded client addresses.
The host usage dialog can show a tentative temporary Codex quota reset forecast based on explicit public announcements. To enable its hourly check, set AGENTFLEET_X_BEARER_TOKEN in the private .env to an X API bearer token and restart the control plane. Without a usable source it shows No forecast yet. The forecast is unofficial; normal weekly resets are shown separately, and reset-card grants cannot be predicted. Available reset cards, when reported by the native Codex account API, appear in the same dialog. The public-signal approach is inspired by Codex Reset Radar.
docker compose up -d --build
curl --fail http://127.0.0.1:3215/readyA successful health check returns JSON with "status":"ok". View service status and logs with:
docker compose ps
docker compose logs -f control-planePoint your HTTPS reverse proxy at http://127.0.0.1:3215. WebSocket proxying must be enabled. For example, Caddy needs only:
panel.example.com {
reverse_proxy 127.0.0.1:3215
}Open the address configured in PUBLIC_ORIGIN and sign in with the verification code sent to your email. The account configured by ADMIN_EMAIL has access to the Admin tab; other verified emails receive their own private workspaces.
For a same-machine trial without a domain, set both origins to http://127.0.0.1:3215, set COOKIE_SECURE=false, and open that address locally. Do not expose this HTTP configuration to a network or the internet.
- Sign in to Codex on the Linux, macOS, or Windows host using the operating-system account whose projects and native sessions you want to manage.
- In AgentFleets, click Add host and select the host operating system.
- Copy the generated one-time installation command and run it on that host under the same operating-system account.
- Return to the panel. When the host is online, add or select a project and open an existing session or create a new one.
The enrollment ticket is single-use and short-lived; do not share it. The Agent connects outward to the control plane, so routine use does not require an inbound port on the Codex host. Write capability is enabled only after the host passes its operating-system, credential-protection, and Codex protocol checks.
When a setup problem has been fixed in GitHub, update the existing installation instead of cloning it again:
cd AgentFleet
git status --short
git rev-parse --short HEAD
git pull --ff-only
docker compose up -d --build
curl --fail http://127.0.0.1:3215/readygit pull updates the tracked project files. It does not replace the ignored .env file or erase the Docker named volumes. docker compose up -d --build rebuilds the application from the newly downloaded source and recreates only the containers that need changing.
If git pull --ff-only reports local tracked changes, preserve them before updating:
git stash push -u -m "before AgentFleets update"
git pull --ff-only
docker compose up -d --buildUse git stash list and git stash show -p to review the saved changes. Apply them later with git stash pop only if they are still needed; old source changes may conflict with the new version. The ignored .env file is not included by this command.
After an update, check the running revision and logs:
git rev-parse --short HEAD
docker compose ps
docker compose logs --tail=200 control-planeIf the health check still fails, include those outputs when reporting the problem, after removing passwords, enrollment tickets, tokens, private hostnames, and conversation content.
Panel source updates and host Agent updates are separate. The commands above update the control plane and web interface. For interface-only changes, users just refresh the panel; no host Agent upgrade or repair is needed. When a release also requires an Agent update, use the host update action. If a host stays unreachable after it is powered on, connected to the network, and signed in to the OS account used for installation, run the platform-specific repair command shown on its host page. Repair is a troubleshooting step, not a routine step after time away.
Compose keeps control-plane data and validated runtimes in the agentfleet-data and agentfleet-runtime-releases named volumes. Back up .env and these volumes before an upgrade. Do not run docker compose down -v unless you intend to erase the stored data.
See release guidance for deployments that must preserve an existing set of Agent downloads.
Session ownership, recovery, and image cleanup
A native session has one writer. While the panel controls a session, do not open that same session with codex resume on the host. Release control in the panel and wait for the host to acknowledge it before resuming locally. To return to the panel, stop the local writer first, then take control again. Renaming changes the title, not the native session ID.
A disconnect or restart can leave an operation's outcome unknown even if a reply is already visible. The panel freezes writes rather than automatically replaying an action. Check the host and native session first, then use the manual unfreeze button. Unfreezing does not prove that the previous operation failed and does not undo it; avoid sending the same action again until you know its outcome.
The control plane stores account and host enrollment data, synchronized conversation content, operation records, and uploaded images. Codex execution and model credentials remain on the host. Protect both the control-plane volumes and host data; this is not a storage-free relay.
The default image quota is 50 MB per host. The host page combines image and uploaded-file cleanup by session. Before deletion, the Agent verifies every staged path, size, content hash, directory member, and symlink boundary. Cleanup removes verified staged files on Linux, macOS, and Windows while preserving text and native session identity. Native-history image cleanup is currently restricted to the validated Linux/Codex adapter and requires Python 3; unsupported or ambiguous data is rejected. Cleanup does not delete provider-side data or independent backups. Native history files may retain their byte length after image removal. Storage size is not a token-usage estimate. See attachment cleanup.
Development and project structure
Use Node.js 24 and npm:
npm ci --prefix apps/control-plane
npm ci --prefix apps/local-agent
npm ci --prefix apps/web
npm run check
npm test
npm run build| Directory | Purpose |
|---|---|
apps/control-plane |
Fastify API, authentication, SQLite state, host connections |
apps/local-agent |
Host discovery, native session control, execution and recovery |
apps/web |
React browser workspace |
packaging |
Installers, runtime artifacts and container builds |
experiments |
Isolated native-history compatibility tools and tests |
See contributing, security reporting, and packaging. Changes to session ownership, replay, or native history require focused recovery tests; passing UI tests alone is insufficient.
Built for people who run Codex on their own machines.
MIT licensed · Third-party notices · Contributions welcome
Independent project, not an official OpenAI product. Deploy your own instance and use your own Codex credentials. No shared service or default login is provided.
Unreachable hosts show a Restore host connection card with a repair command matched to Windows, macOS or Linux. Run it on that host using the original installation account. Repair retains pairing and session data; copying a command does not run it remotely. Power, network or operating-system failures still require local attention.










