Self-hosted · no inbound ports

Mission control for OpenCode

Chat with OpenCode sessions running on any Linux machine — streams, diffs, worktrees and permissions in your browser. The relay dials out, so nothing ever dials in.

  • No inbound ports
  • Existing sessions included
  • One-command install
build-box relay · online seq 8,412
Run finished billing-webhook · 6 passed

Relay

Nothing dials in.

Your machines open one outbound connection and keep it alive with a heartbeat every 15 seconds. No ports to open, no VPN, no exposure.

Your Linux box

opencode serve
supervised by the relay

CodePulse

teams · history · push

Your devices

browser or installed PWA

  • HMAC-SHA256 signed batches
  • ±5 minute replay window
  • Rotatable and revocable secrets

Capabilities

Everything the terminal does, in the browser.

  1. 01

    Streaming chat

    Tokens, tool cards, markdown and highlighted code, rendered as they arrive.

    sse → ws
  2. 02

    Git worktrees

    Create, work and merge in isolated branches. Every worktree starts from a fresh origin fetch.

    git
  3. 03

    Permissions & questions

    OpenCode's permission prompts and questions are answered right in the transcript.

    interactive
  4. 04

    Push notifications

    Know when a run finishes or needs input. Every notification deep-links into its session.

    vapid
  5. 05

    Teams & relays

    Invite teammates, run several hosts per team, rotate or revoke any relay.

    multi-host
  6. 06

    Search & history

    History is mirrored locally, so search keeps working while a relay sleeps.

    full-text

Setup

One connection, three steps.

About two minutes on a box that already runs OpenCode. The relay installs as a hardened systemd service.

  1. 1

    Install the relay

    curl -fsSL https://codepulse.pro/install.sh | sh
  2. 2

    Enroll the host

    relay enroll --url https://codepulse.pro --token <one-time-token>
  3. 3

    Open the dashboard

    Projects, sessions and worktrees are waiting. If anything looks off, relay doctor re-checks the whole chain.

relay · build-box ubuntu 24.04

Guardrails

Self-hosted by design.

  • Signed uplink

    Every batch is HMAC-SHA256 signed, with a ±5 minute window and replay protection.

  • Secrets at rest

    Relay secrets are encrypted in the app. Enrollment tokens are hashed, single-use and expire in 30 minutes.

  • Hardened service

    The relay runs as a dedicated user under systemd with NoNewPrivileges, ProtectSystem and PrivateTmp.

  • Invite-only teams

    No open registration. Access is granted through invitations and scoped per team.

Bring your agents into view.

Invite-only, self-hosted, and running in about two minutes.

Sign in

codepulse.pro