See your AI coding work across every machine.
Claude Code and Codex sessions, token usage, cache activity and estimated costs, on this computer and every machine you connect. One local console, with no account or model API key required.
npx --yes https://github.com/LockedinLabs-AI/agent-console/releases/download/v0.4.1/lockedinlabs-agent-console-0.4.1.tgz --open
The console
recorded from v0.2.1 with--demo · watch the demoDEMO · every figure in this capture is generatedChoose how to install
the package runs on Node 22 or newer; the standalone executable needs nothing127.0.0.1:6787. Use the demo command to look around before reading your sessions.npx --yes https://github.com/LockedinLabs-AI/agent-console/releases/download/v0.4.1/lockedinlabs-agent-console-0.4.1.tgz --opennpx --yes https://github.com/LockedinLabs-AI/agent-console/releases/download/v0.4.1/lockedinlabs-agent-console-0.4.1.tgz --demo --openhttps://github.com/LockedinLabs-AI/agent-consoleagent-console command on this computer. Installs this exact release archive from GitHub; the npm registry name does not need to be published. Node.js 22 or newer is required.npm install --global --ignore-scripts https://github.com/LockedinLabs-AI/agent-console/releases/download/v0.4.1/lockedinlabs-agent-console-0.4.1.tgzagent-console --opennpx handles that for you. On Windows, use PowerShell.On a Mac, use Terminal.Use your terminal.npx --yes ~/Downloads/lockedinlabs-agent-console-0.4.1.tgz --opennpx --yes $HOME\Downloads\lockedinlabs-agent-console-0.4.1.tgz --openmain can include changes that are not in the published download. Clone into a new folder, or use Code → Download ZIP, then start with Node. No build step or dependency install. Run each line only after the previous one succeeds.git clone https://github.com/LockedinLabs-AI/agent-console.git
cd agent-console
node bin/agent-console.mjs --openSHA256SUMS, and installs nothing unless the SHA-256 matches. It installs to ~/.local/bin, and prints the line that puts that folder on your PATH if it is not there yet.It installs to AppData\Local\Programs\AgentConsole for your user only, and adds that folder to your PATH. On macOS it is signed with an Apple Developer ID and notarized by Apple; on Windows it is not code-signed, and this installer is the way to install it.curl -fsSLO https://raw.githubusercontent.com/LockedinLabs-AI/agent-console/v0.4.1/install.sh && AGENT_CONSOLE_VERSION=v0.4.1 sh ./install.sh& { $ErrorActionPreference = 'Stop'; $ProgressPreference = 'SilentlyContinue'; [Net.ServicePointManager]::SecurityProtocol = [Net.ServicePointManager]::SecurityProtocol -bor 3072; $f = Join-Path ([IO.Path]::GetTempPath()) ('agent-console-install-' + [Guid]::NewGuid().ToString('N') + '.ps1'); $v = $env:AGENT_CONSOLE_VERSION; try { Invoke-WebRequest -UseBasicParsing -Uri 'https://raw.githubusercontent.com/LockedinLabs-AI/agent-console/v0.4.1/install.ps1' -OutFile $f; if (-not (Test-Path -LiteralPath $f) -or (Get-Item -LiteralPath $f).Length -eq 0) { throw 'The installer did not download. Nothing was run.' }; $env:AGENT_CONSOLE_VERSION = 'v0.4.1'; powershell -NoProfile -ExecutionPolicy Bypass -File $f; if ($LASTEXITCODE -ne 0) { throw 'The installer stopped without installing.' } } finally { Remove-Item -LiteralPath $f -Force -ErrorAction SilentlyContinue; $env:AGENT_CONSOLE_VERSION = $v } }brew install LockedinLabs-AI/tap/agent-consoleThen, a second machine
a teammate's laptop, your build box- Start the console so other computers can reach it
node bin/agent-console.mjs --listen 0.0.0.0 --openThe console itself stays on this computer only. Other machines reach a separate port that serves nothing but joining and reporting. - Press Add a machineSay whose machine it is, press Create join link, copy it, send it. The link works once, for at most an hour, and stays masked on screen.
- They paste one commandIt installs the console from the GitHub release, never from your computer, and reports over TLS pinned to your console's certificate. The machine appears within seconds; two machines with the same person roll into one row.
What works where
tested in CI on Node 22 and 24| macOS | Linux | Windows | |
|---|---|---|---|
| The console, reading this computer | yes | yes | yes |
| Joining and reporting to another console | yes | yes | yes |
Projects view, with git | yes | yes | expected |
Signed in, and only here
what--open doesThe console shows its figures only to a browser that has signed in. --open opens it signed in; otherwise the terminal prints a one-time sign-in link when it starts. It listens on 127.0.0.1 and never on the network, whatever --listen says: other machines reach a separate port that serves joining and reporting and nothing else.
Leave the terminal open; closing it stops the console. The same command starts it again, and finds the console already running if it is.
In the first thirty seconds
hover a reading to find it on the screenDEMO captureSix readings
what each one promisesWhat a cache break costs you
your prefix, your model, list price from the console's dated tableprices checked 2026-09-20 · Opus 5.5 2026-09-22A break is an idle gap longer than the cache lifetime, or a model switch inside a task. Either way the next turn writes the whole prefix again instead of reading it.
An estimate at standard API list price, not a bill and not a subscription charge. Anthropic charges a 5-minute cache write at 1.25× the input rate; a read is a fifth of it.
| At this prefix, per break | Rewrite billed at | A read would be | Extra per break | Per day |
|---|
lib/collector/prices.json, the table the console prices withAnthropic rows: 5-minute write; OpenAI rows: automatic cache, no write premiumWhy this is the number
our own run, 22–23 September 2026, counted from the logsHalf the bill was the agents re-reading what they already knew. That is what caching is for; the cost is in the breaks. On that run's mean prefix of 366,011 tokens, one break on Opus 5.5 writes $1.83 of cache that a read would have served for seven cents.
Anthropic's /usage shows cache misses for the current session. It does not show them across sessions, subagents or machines, or for Codex, and it does not price the week.
Nothing leaves a machine but counts.
No telemetry, no update check, no account. The console never fetches anything from us; a test proves what crosses the wire on every commit.
What a reporting machine sends, per usage event
the whole record; there are no other fields| Field | What it is | Example |
|---|---|---|
| tool | which agent wrote the transcript | claude-code |
| model | the model id, exactly as logged | claude-opus-5-5 |
| minute | when, to the minute | 2026-09-24T14:26Z |
| tokens | input · cache read · cache write · output | 1,204 · 366,011 · 0 · 981 |
| subagent | whether this was a child session | false |
| session · parent · project | HMAC-SHA256 hashes, keyed by a salt the console shares only with machines that join it | 9f3c… · 41a0… · c77e… |
| machine name | whatever the console's owner typed when making the link | Build box |
--share-project-names also sends a folder's name, never its path. Off unless you pass it.What never leaves
- prompts, replies, thinking
- tool input and output
- file paths, file names, file contents
- git branches, command lines
- credentials
The proof
a test, not a sentencetest/hub-e2e.test.js pushes synthetic transcripts, in the tools' real formats, with a canary planted in every private field, through a real reporter process and a real hub process. A relay records every request whole, every answer the hub sends back and every read the console serves, and the test checks each byte for every canary. A new route the canary does not read fails the suite.
Check what you downloaded
the release page lists the SHA-256, and GitHub keeps a signed build attestationshasum -a 256 lockedinlabs-agent-console-0.4.1.tgzGet-FileHash lockedinlabs-agent-console-0.4.1.tgz53e10604a72066f6b7e220e432e5b6549e1d3109ec62e4f20c8012b03598dd62gh CLI.gh attestation verify lockedinlabs-agent-console-0.4.1.tgz -R LockedinLabs-AI/agent-console--format json- subject
- lockedinlabs-agent-console-0.4.1.tgz · sha256 53e10604…98dd62
- built by
- .github/workflows/release.yml @ refs/tags/v0.4.1
- from commit
- 8e33889a4e1097f64e91fdb6fc9871d7301108f9
- trigger · runner
- release · github-hosted
- predicate
- https://slsa.dev/provenance/v1
- logged
- rekor.sigstore.dev · 2026-09-27 15:15:15 UTC
npm pack of the tagged tree: bin/, lib/, public/, server.js. There is no compiled or minified file in it.tar tzf lockedinlabs-agent-console-0.4.1.tgzHow a release is built
.github/workflows/release.yml--demo.package.json must equal the tag; SHA256SUMS is written beside the tarball.A policy file that compiles into Claude Code's own controls
version 1, aspolicy init writes itsince v0.3# agent-policy.yaml · platform team
version: 1
on_error: ask
model_allowlist: [haiku, sonnet, opus]
routing:
roles:
search: { model: haiku }
exploration: { model: haiku }
log_reading: { model: haiku }
code_edit: { model: opus, with_verifying_test: sonnet }
escalation:
after_failures: 2
model: opus
budgets:
per_run: { tokens: 200000, usd: 50 }
per_day: { tokens: 1000000, usd: 200 }
cache:
forbid_model_switch_in_task: true
idle_gap_minutes: 5
gates:
force_push: ask
delete_outside_repo: block
pipe_to_interpreter: ask
credential_read: ask
production_migration: block
What it writes, and what it will not claim
agent-console policy initwrites the file above with the version 1 defaultsagent-console policy diffshows the .claude/settings.json, .claude/agents/*.md and .claude/hooks/ it would write; read-onlyagent-console policy applywrites them, keeps restorable backups, prints the pathsagent-console policy removerestores exactly what it changed, and only thatEvery setting key and hook it writes is one Claude Code documents: project settings, agent frontmatter with model and effort, PreToolUse and PreModelSwitch hooks. Nothing invented.
What a hook cannot see, the compiler says so. Hard token and dollar budgets, proof of a verifying test and a failed-attempt count are reported as not enforceable yet, because a tool-launch hook has no verified balance and no view of those facts. Budgets stay analysis thresholds the console watches.
Hooks fail safe and never touch the network. On a malformed input or a policy read error, on_error applies, defaulting to ask.
When one console is not enough.
A team that outgrows one laptop gets the self-hosted hub for free, in this repository. An organisation that needs someone accountable for sign-on, enforcement and audit is what Agent Console Enterprise is for. Both read the same records and the same policy file.
In this repository, free, MIT
no CLA, noee/ directory, no telemetry, no licence key anywhereinit | diff | apply | remove/metrics for Prometheus, OpenTelemetry ingest, LiteLLM and Kong gateway shapesAgent Console Enterprise
by LockedIn Labsin buildagent-policy.yaml, versioned and signed per group, with a view of what each machine applied