Self-hosted · no inbound ports
Mission control for OpenCode
Chat with OpenCode sessions running on any Linux machine — streams, diffs, worktrees and permissions in your browser. The relay dials out, so nothing ever dials in.
- No inbound ports
- Existing sessions included
- One-command install
Relay
Nothing dials in.
Your machines open one outbound connection and keep it alive with a heartbeat every 15 seconds. No ports to open, no VPN, no exposure.
Your Linux box
opencode serve
supervised by the relay
CodePulse
teams · history · push
Your devices
browser or installed PWA
- HMAC-SHA256 signed batches
- ±5 minute replay window
- Rotatable and revocable secrets
Capabilities
Everything the terminal does, in the browser.
-
01
sse → ws
Streaming chat
Tokens, tool cards, markdown and highlighted code, rendered as they arrive.
-
02
git
Git worktrees
Create, work and merge in isolated branches. Every worktree starts from a fresh origin fetch.
-
03
interactive
Permissions & questions
OpenCode's permission prompts and questions are answered right in the transcript.
-
04
vapid
Push notifications
Know when a run finishes or needs input. Every notification deep-links into its session.
-
05
multi-host
Teams & relays
Invite teammates, run several hosts per team, rotate or revoke any relay.
-
06
full-text
Search & history
History is mirrored locally, so search keeps working while a relay sleeps.
Setup
One connection, three steps.
About two minutes on a box that already runs OpenCode. The relay installs as a hardened systemd service.
-
1
Install the relay
curl -fsSL https://codepulse.pro/install.sh | sh -
2
Enroll the host
relay enroll --url https://codepulse.pro --token <one-time-token> -
3
Open the dashboard
Projects, sessions and worktrees are waiting. If anything looks off,
relay doctorre-checks the whole chain.
Guardrails
Self-hosted by design.
-
Signed uplink
Every batch is HMAC-SHA256 signed, with a ±5 minute window and replay protection.
-
Secrets at rest
Relay secrets are encrypted in the app. Enrollment tokens are hashed, single-use and expire in 30 minutes.
-
Hardened service
The relay runs as a dedicated user under systemd with NoNewPrivileges, ProtectSystem and PrivateTmp.
-
Invite-only teams
No open registration. Access is granted through invitations and scoped per team.
Bring your agents into view.
Invite-only, self-hosted, and running in about two minutes.
Sign incodepulse.pro