LockedIn Labs Agent Console v0.4.1 GitHub Install

See your AI coding work across every machine.

Claude Code and Codex sessions, token usage, cache activity and estimated costs, on this computer and every machine you connect. One local console, with no account or model API key required.

npx --yes https://github.com/LockedinLabs-AI/agent-console/releases/download/v0.4.1/lockedinlabs-agent-console-0.4.1.tgz --open

The console

recorded from v0.2.1 with --demo · watch the demoDEMO · every figure in this capture is generated
Agent Console in demo mode: console, team, and project views with generated token and cost figures.

Choose how to install

the package runs on Node 22 or newer; the standalone executable needs nothing
Try the published releaseFetches the packaged console from the v0.4.1 release, reads the Claude Code and Codex history already on this computer, and opens it signed in at 127.0.0.1:6787. Use the demo command to look around before reading your sessions.
npx --yes https://github.com/LockedinLabs-AI/agent-console/releases/download/v0.4.1/lockedinlabs-agent-console-0.4.1.tgz --open
npx --yes https://github.com/LockedinLabs-AI/agent-console/releases/download/v0.4.1/lockedinlabs-agent-console-0.4.1.tgz --demo --open
The second line looks around first: a synthetic team of five machines, stamped DEMO, reading nothing of yours.
Install with Claude Code or CodexGive your coding assistant the official repo link and ask it to follow INSTALL.md. The guide covers the source version, published downloads, version checks and opening the console. No model API key is required.
https://github.com/LockedinLabs-AI/agent-console
Install with npmKeep an agent-console command on this computer. Installs this exact release archive from GitHub; the npm registry name does not need to be published. Node.js 22 or newer is required.
npm install --global --ignore-scripts https://github.com/LockedinLabs-AI/agent-console/releases/download/v0.4.1/lockedinlabs-agent-console-0.4.1.tgz
agent-console --open
If npm reports a permission error, use the source option below. No administrator access is needed. Full installation guide
Download the Node.js packageDownload the archive, then run it without unpacking it. npx handles that for you. On Windows, use PowerShell.On a Mac, use Terminal.Use your terminal.
lockedinlabs-agent-console-0.4.1.tgz SHA-256 53e10604…98dd62 · verify it
npx --yes ~/Downloads/lockedinlabs-agent-console-0.4.1.tgz --open
npx --yes $HOME\Downloads\lockedinlabs-agent-console-0.4.1.tgz --open
Run the current sourceSource on main can include changes that are not in the published download. Clone into a new folder, or use Code → Download ZIP, then start with Node. No build step or dependency install. Run each line only after the previous one succeeds.
git clone https://github.com/LockedinLabs-AI/agent-console.git cd agent-console node bin/agent-console.mjs --open
Standalone executableone file with Node.js inside, for a computer without Node. The installer fetches the file for this computer and the release's SHA256SUMS, and installs nothing unless the SHA-256 matches. It installs to ~/.local/bin, and prints the line that puts that folder on your PATH if it is not there yet.It installs to AppData\Local\Programs\AgentConsole for your user only, and adds that folder to your PATH. On macOS it is signed with an Apple Developer ID and notarized by Apple; on Windows it is not code-signed, and this installer is the way to install it.
curl -fsSLO https://raw.githubusercontent.com/LockedinLabs-AI/agent-console/v0.4.1/install.sh && AGENT_CONSOLE_VERSION=v0.4.1 sh ./install.sh
& { $ErrorActionPreference = 'Stop'; $ProgressPreference = 'SilentlyContinue'; [Net.ServicePointManager]::SecurityProtocol = [Net.ServicePointManager]::SecurityProtocol -bor 3072; $f = Join-Path ([IO.Path]::GetTempPath()) ('agent-console-install-' + [Guid]::NewGuid().ToString('N') + '.ps1'); $v = $env:AGENT_CONSOLE_VERSION; try { Invoke-WebRequest -UseBasicParsing -Uri 'https://raw.githubusercontent.com/LockedinLabs-AI/agent-console/v0.4.1/install.ps1' -OutFile $f; if (-not (Test-Path -LiteralPath $f) -or (Get-Item -LiteralPath $f).Length -eq 0) { throw 'The installer did not download. Nothing was run.' }; $env:AGENT_CONSOLE_VERSION = 'v0.4.1'; powershell -NoProfile -ExecutionPolicy Bypass -File $f; if ($LASTEXITCODE -ne 0) { throw 'The installer stopped without installing.' } } finally { Remove-Item -LiteralPath $f -Force -ErrorAction SilentlyContinue; $env:AGENT_CONSOLE_VERSION = $v } }
Or use the Download button on the overview for the file itself, and verify it before you run it.
npm registry comingThe package name is not on the npm registry for this release yet. Use npm to install the verified GitHub archive above.
Homebrewthe standalone executable for macOS or Linux, checked by Homebrew against the release's SHA-256.
brew install LockedinLabs-AI/tap/agent-console

Then, a second machine

a teammate's laptop, your build box
  1. Start the console so other computers can reach itnode bin/agent-console.mjs --listen 0.0.0.0 --openThe console itself stays on this computer only. Other machines reach a separate port that serves nothing but joining and reporting.
  2. Press Add a machineSay whose machine it is, press Create join link, copy it, send it. The link works once, for at most an hour, and stays masked on screen.
  3. They paste one commandIt installs the console from the GitHub release, never from your computer, and reports over TLS pinned to your console's certificate. The machine appears within seconds; two machines with the same person roll into one row.

What works where

tested in CI on Node 22 and 24
macOSLinuxWindows
The console, reading this computeryesyesyes
Joining and reporting to another consoleyesyesyes
Projects view, with gityesyesexpected

Signed in, and only here

what --open does

The console shows its figures only to a browser that has signed in. --open opens it signed in; otherwise the terminal prints a one-time sign-in link when it starts. It listens on 127.0.0.1 and never on the network, whatever --listen says: other machines reach a separate port that serves joining and reporting and nothing else.

Leave the terminal open; closing it stops the console. The same command starts it again, and finds the console already running if it is.

In the first thirty seconds

hover a reading to find it on the screenDEMO capture

Six readings

what each one promises
Dollars are list-price estimates from a dated, offline tableDemo is never mixed with measured data

What a cache break costs you

your prefix, your model, list price from the console's dated tableprices checked 2026-09-20 · Opus 5.5 2026-09-22

A break is an idle gap longer than the cache lifetime, or a model switch inside a task. Either way the next turn writes the whole prefix again instead of reading it.

Extra cost per break$1.76366,000 × ($5.00 write − $0.20 read) per M
Per day$14.05
Per week, one person$98

An estimate at standard API list price, not a bill and not a subscription charge. Anthropic charges a 5-minute cache write at 1.25× the input rate; a read is a fifth of it.

At this prefix, per breakRewrite billed atA read would beExtra per breakPer day
usdPerMillion from lib/collector/prices.json, the table the console prices withAnthropic rows: 5-minute write; OpenAI rows: automatic cache, no write premium

Why this is the number

our own run, 22–23 September 2026, counted from the logs
Tokens in 24 hours, 122 agents, one machine6.97B
Of them, cache reads97.06%
List-price equivalent · cache reads' share of it$2,637 · 51%
Mean cached prefix handed back per message366,011 tokens · 18,485 messages

Half the bill was the agents re-reading what they already knew. That is what caching is for; the cost is in the breaks. On that run's mean prefix of 366,011 tokens, one break on Opus 5.5 writes $1.83 of cache that a read would have served for seven cents.

Anthropic's /usage shows cache misses for the current session. It does not show them across sessions, subagents or machines, or for Codex, and it does not price the week.

Today: the read/write split per machine and modelSince v0.3: each break flagged in its lane and priced

Nothing leaves a machine but counts.

No telemetry, no update check, no account. The console never fetches anything from us; a test proves what crosses the wire on every commit.

What a reporting machine sends, per usage event

the whole record; there are no other fields
FieldWhat it isExample
toolwhich agent wrote the transcriptclaude-code
modelthe model id, exactly as loggedclaude-opus-5-5
minutewhen, to the minute2026-09-24T14:26Z
tokensinput · cache read · cache write · output1,204 · 366,011 · 0 · 981
subagentwhether this was a child sessionfalse
session · parent · projectHMAC-SHA256 hashes, keyed by a salt the console shares only with machines that join it9f3c… · 41a0… · c77e…
machine namewhatever the console's owner typed when making the linkBuild box
One opt-in: --share-project-names also sends a folder's name, never its path. Off unless you pass it.

What never leaves

  • prompts, replies, thinking
  • tool input and output
  • file paths, file names, file contents
  • git branches, command lines
  • credentials

The proof

a test, not a sentence

test/hub-e2e.test.js pushes synthetic transcripts, in the tools' real formats, with a canary planted in every private field, through a real reporter process and a real hub process. A relay records every request whole, every answer the hub sends back and every read the console serves, and the test checks each byte for every canary. A new route the canary does not read fails the suite.

Check what you downloaded

the release page lists the SHA-256, and GitHub keeps a signed build attestation
1 · The hashmust print exactly the line below. PowerShell prints it in upper case; that is the same hash.
shasum -a 256 lockedinlabs-agent-console-0.4.1.tgz
Get-FileHash lockedinlabs-agent-console-0.4.1.tgz
expected · v0.4.153e10604a72066f6b7e220e432e5b6549e1d3109ec62e4f20c8012b03598dd62
2 · The attestationproves this exact file was built by this repository's release workflow, from the tag, on GitHub's runners. Needs the gh CLI.
gh attestation verify lockedinlabs-agent-console-0.4.1.tgz -R LockedinLabs-AI/agent-console
Verification succeededwhat the v0.4.1 attestation says, checked at build with --format json
subject
lockedinlabs-agent-console-0.4.1.tgz · sha256 53e10604…98dd62
built by
.github/workflows/release.yml @ refs/tags/v0.4.1
from commit
8e33889a4e1097f64e91fdb6fc9871d7301108f9
trigger · runner
release · github-hosted
predicate
https://slsa.dev/provenance/v1
logged
rekor.sigstore.dev · 2026-09-27 15:15:15 UTC
3 · Or read the sourcethe package is a plain npm pack of the tagged tree: bin/, lib/, public/, server.js. There is no compiled or minified file in it.
tar tzf lockedinlabs-agent-console-0.4.1.tgz

How a release is built

.github/workflows/release.yml
Tagv0.4.1
A release is published from the tag. Nothing is built on anyone's own machine.
Testnpm test · smoke:pack
The whole suite, including the multi-machine privacy canary, then a packed install started in --demo.
Packnpm pack
The version in package.json must equal the tag; SHA256SUMS is written beside the tarball.
Attestbuild provenance
A signed attestation records the workflow, the commit and the file's digest, in Sigstore's public log.
Attachgh release upload
The tarball and its sums land on the release page. The one-line install and every join command fetch exactly this file.
Actions pinned by commitgitleaks and a public-safety check on every push

A policy file that compiles into Claude Code's own controls

version 1, as policy init writes itsince v0.3
# agent-policy.yaml · platform team
version: 1
on_error: ask
model_allowlist: [haiku, sonnet, opus]
routing:
  roles:
    search:      { model: haiku }
    exploration: { model: haiku }
    log_reading: { model: haiku }
    code_edit:   { model: opus, with_verifying_test: sonnet }
escalation:
  after_failures: 2
  model: opus
budgets:
  per_run: { tokens: 200000, usd: 50 }
  per_day: { tokens: 1000000, usd: 200 }
cache:
  forbid_model_switch_in_task: true
  idle_gap_minutes: 5
gates:
  force_push: ask
  delete_outside_repo: block
  pipe_to_interpreter: ask
  credential_read: ask
  production_migration: block
Unknown fields fail validationAn organisation policy overrides a repository's, field by fieldJSON with the same fields works too

What it writes, and what it will not claim

agent-console policy initwrites the file above with the version 1 defaults
agent-console policy diffshows the .claude/settings.json, .claude/agents/*.md and .claude/hooks/ it would write; read-only
agent-console policy applywrites them, keeps restorable backups, prints the paths
agent-console policy removerestores exactly what it changed, and only that

Every setting key and hook it writes is one Claude Code documents: project settings, agent frontmatter with model and effort, PreToolUse and PreModelSwitch hooks. Nothing invented.

What a hook cannot see, the compiler says so. Hard token and dollar budgets, proof of a verifying test and a failed-attempt count are reported as not enforceable yet, because a tool-launch hook has no verified balance and no view of those facts. Budgets stay analysis thresholds the console watches.

Hooks fail safe and never touch the network. On a malformed input or a policy read error, on_error applies, defaulting to ask.

Since v0.3Details: docs/policy.md

When one console is not enough.

A team that outgrows one laptop gets the self-hosted hub for free, in this repository. An organisation that needs someone accountable for sign-on, enforcement and audit is what Agent Console Enterprise is for. Both read the same records and the same policy file.

In this repository, free, MIT

no CLA, no ee/ directory, no telemetry, no licence key anywhere
The console and everything it drawsthe local reader for Claude Code and Codex
The self-hosted hubjoin by link, TLS pinning, device tokens, team and machine roll-ups, 8 to 90 days of retention
The accounting spec and conformance suiteground-truth totals for streamed duplicates, subagent sidechains, resumed sessions, Codex counter resets, one person on two machines
The policy layerthe file, the parser, init | diff | apply | remove
Interop/metrics for Prometheus, OpenTelemetry ingest, LiteLLM and Kong gateway shapes

Agent Console Enterprise

by LockedIn Labsin build
Sign-onEntra ID, Okta, Google Workspace; groups to roles
Policy, distributedthe same agent-policy.yaml, versioned and signed per group, with a view of what each machine applied
Budgets that enforceper person, team and project, at a gateway; the repository only warns
Signed audit exportevery decision, block and refusal as evidence an auditor can verify
Historybeyond 90 days, across organisations for a consultancy
lockedinlabs.aiNothing in the repository phones home, and it never will