Docs

joinmyagent shares a live Claude Code or Codex session through a link. You keep running the agent in your terminal; the person you send the link to follows along in their browser and, when you allow it, sends prompts to your agent.

Getting started

You need Node.js 20 or newer and Claude Code (or Codex) installed and logged in. The person you're sharing with needs only a browser.

  1. In your project, start your agent through joinmyagent instead of directly:
    npx joinmyagent
    This runs claude exactly as usual in your terminal and prints a share link.
  2. Your owner page opens in the browser. That's where you approve requests and manage sharing. Keep it open.
  3. Send the share link (the one without #owner=) to whoever is helping you.
  4. When you're done, exit your agent as usual, or press End sharing on the owner page to stop sharing while your agent keeps running.

To use it often, install it once with npm install -g joinmyagent and run joinmyagent.

Commands and options

joinmyagent [options] [-- <agent> [agent args…]]

Everything after -- is the agent command. Without it, joinmyagent runs claude (or codex if Claude Code isn't installed).

ExampleWhat it does
joinmyagent -- claude --resumeShare a Claude Code session you started earlier, with its full history.
joinmyagent -- codexShare a Codex session (experimental).
--auto-approve [minutes|session]Give control to anyone who asks without asking you. Default length is 15 minutes. Paused while your agent runs without permission prompts.
--trusted-linkAlso print a trusted link. Whoever opens it gets control as soon as they ask.
--no-replayDelete the session from the relay when you exit. Without it, the encrypted replay is kept for 7 days.
--name <name>Your display name. Defaults to your computer's user name.
--relay <url>Use your own relay instead of joinmyagent.com. Same as JOINMYAGENT_RELAY.
--no-openDon't open the owner page in a browser.
joinmyagent config --relay <url> --name <name>Save defaults to ~/.joinmyagent/config.json.

The owner page

The owner page is the share link plus a secret key after #owner=. It shows the same live session your guests see, plus the controls only you have:

  • Requests: when someone asks for control, choose Allow 15 min, Allow for session, Allow & trust, or Reject.
  • Suggested prompts: guests without control can suggest a prompt. Send to agent delivers it as written.
  • Take back control at any time from the coloured bar at the top.
  • Sharing panel: copy the guest or trusted link and turn auto-approve on or off.
  • People panel: see who's watching, and trust or untrust a person.
  • Delete session: stop sharing and remove the replay from joinmyagent.

If the owner page isn't open when someone asks for control, joinmyagent opens it for you and rings the terminal bell.

Treat the owner link like a password. Anyone who has it can approve requests and send prompts to your agent until you exit or delete the session. Once it's open, the owner page removes the key from the address bar.

Control and trust

Everyone who opens the share link starts out watching. They see every prompt, reply, command (with output) and file change, plus a summary of the session so far, and can chat with you. Chat is between people only; the agent never sees it.

StateHow they get itWhat they can do
WatchingOpening the share linkWatch everything, chat, suggest prompts for you to approve
In controlYou approve their requestSend prompts straight to your agent and stop its current turn, until the time runs out or you take control back

There are three ways to skip approving each request:

  • Trust a person. Use Trust in the People panel, or Allow & trust on their request. Their later requests in this session are granted instantly. A person is recognised by a secret their browser keeps, so someone else can't claim to be them by copying their name.
  • Trusted link. Whoever opens it is trusted. Share it only with people you'd hand your keyboard to.
  • Auto-approve everyone. Anyone with the share link gets control when they ask.

Grants made this way still expire after the auto-approve length (15 minutes by default) and can be taken back at any time.

Security model

Giving someone control means letting them direct an AI agent on your computer. joinmyagent limits what they can do directly, but the agent itself can read files, run commands and use the network, within whatever permissions you've given it.

What guests can and can't do

  • Prompts from guests are delivered as plain text. Control characters are removed, so a guest can't press keys in your terminal (for example Shift+Tab to change Claude's permission mode, or Ctrl+C).
  • Guest prompts can't start with /, ! or #, so they can't run slash commands (such as /permissions), shell commands, or write to memory files. These checks run both on the relay and on your machine.
  • While your agent is waiting for you to answer a permission prompt, prompts from the browser are held back, so typed text can't answer it for you.
  • If your agent runs without permission prompts (for example --dangerously-skip-permissions or bypass mode), joinmyagent warns you in the terminal and on the owner page, and auto-approve-everyone is paused. Trusted people can still get control, so trust carefully.

What's shared

  • The conversation, commands with their output, and diffs of changed files. Files the agent only reads are shown by name, not content.
  • Common secret formats are masked before anything leaves your machine: API keys from major providers, tokens, JWTs, private keys, passwords in KEY=value form and database URLs. Output from commands that read .env or key files, or print the environment, is hidden entirely.
  • Masking is best-effort. It can't recognise every secret. Share a session the way you'd share your screen.

End-to-end encryption

Sessions started with joinmyagent 0.2 or later are end-to-end encrypted. When you start sharing, your terminal creates a 256-bit key and puts it in the links after #k=. Browsers never send that part of a link to a server, so the relay only ever stores and passes on ciphertext (AES-256-GCM).

The relay can't seeThe relay can see
Prompts and replies, commands and their output, diffs, file names, your project folder and branch, chat messages, suggested promptsYour display name and guests' names, which agent you use, when things happen and what kind of event they are, whether the agent is working or waiting for a permission decision, its permission mode, and who asked for or holds control
  • The relay sees just enough to referee control. It can't add or change prompts: your terminal only accepts prompts encrypted with the session key, and each one only once.
  • Anyone with a link has the key. Forwarding a link forwards access, so share links the way you'd share a password.
  • As with any end-to-end encrypted web app, the page itself comes from joinmyagent.com. Someone who took over the server could serve a page that reads the key from the link. Encryption protects you from stored data leaking and from anyone reading traffic or logs, not from a compromised server.
  • Sessions shared from joinmyagent 0.1 aren't encrypted. The owner page shows whether a session is.

Links and keys

  • Your computer only makes outbound connections (HTTPS and secure WebSockets). No ports are opened to the network; the CLI listens on localhost only, to hear from your agent's hooks.
  • Share links contain a random 96-bit token; owner keys are 192-bit. Keys are sent inside the encrypted connection, never in URLs, so they don't end up in server logs.
  • The relay stores only hashes of owner keys and trusted-link tokens.
  • When the owner page opens, it moves its keys into that browser tab and removes them from the address bar, so the owner link isn't left in your history or copied by accident. Reloading the tab keeps working; to open the owner page somewhere else, use the owner link from your terminal again.

Replays and deletion

  • After sharing ends, the link shows an encrypted replay for 7 days after the last activity.
  • Delete session on the owner page removes the session and its replay from the relay right away, for everyone. Start with --no-replay to delete it automatically when you exit.

Self-hosting

For now, all sessions go through the relay at joinmyagent.com. A self-hostable relay (a single Node.js process with no database) will be published together with the source.

The CLI is ready for it: --relay <url>, JOINMYAGENT_RELAY or joinmyagent config --relay <url> point it at another relay.

Troubleshooting

The guest page stays empty
The feed fills in from your agent's transcript, which starts after the first prompt. If it stays empty after that, check the agent isn't running inside another Claude Code session with transcripts turned off; joinmyagent clears those settings for the agent it starts, but not for agents you launch separately.
“Could not reach relay”
Check your internet connection. If you changed the relay with --relay, JOINMYAGENT_RELAY or joinmyagent config, check that address.
“This link is missing its key” or “Can’t decrypt this session”
The part of the link after # was cut off or changed, often by a chat app or by retyping it. Copy the full link again from your terminal or the owner page.
A guest's prompt was refused
They'll see why: they don't have control, the prompt started with /, ! or #, or your agent was waiting for a permission decision. Answer the permission prompt in your terminal and they can send it again.
Windows
Windows support is new. Run joinmyagent from Windows Terminal or PowerShell with Claude Code installed natively or through npm. Please report anything that doesn't work.
Codex
Codex support is experimental: watching works, but status updates are coarser than with Claude Code.