CodePilot is a Mac menu bar app, local gateway, and iPhone companion for AI coding users who already run Codex CLI on a Mac they control.
The public beta focuses on Codex account switching, usage visibility, remote iPhone access through a user-owned Cloudflare Tunnel, file uploads, connector status, optional notifications, and gateway-backed conversation control. The current beta is Codex-focused; support for other coding agents is not part of the beta promise.
CodePilot is source-available under the PolyForm Noncommercial License 1.0.0. It is not open source under the OSI definition because commercial use is restricted.
Commercial use requires a separate written license. See LICENSE.md, COMMERCIAL-LICENSE.md, and NOTICE.md.
- CodePilot Mac: a macOS menu bar app that tracks usage, manages account profiles, and coordinates automatic account switching.
- CodePilot Gateway: a local Python gateway that exposes threads, jobs, files, usage, notifications, and account controls to trusted clients.
- CodePilot iOS: an iPhone app that connects to the gateway for remote chat, file uploads, usage status, steering, stopping turns, and notifications.
- Cloudflare Tunnel support: public-beta iPhone access to the gateway through a user-owned Cloudflare Tunnel.
CodePilot currently supports Codex by working with the local Codex home on the Mac:
~/.codex/auth.json~/.codex/state_5.sqlite~/.codex-account-switcher/accounts/~/.codex-account-switcher/usage.json
The public product name is provider-neutral, but the first implementation remains Codex-specific internally.
The Mac app currently builds from source on macOS 13 or later. The iPhone companion requires iOS 17 or later and access to an approved beta build; this repository does not yet promise a public TestFlight invitation or App Store download.
-
Install Codex on the Mac that will run CodePilot.
-
Clone this repository:
git clone https://github.com/codepilotios/codepilot.git cd codepilot -
Build the Mac app:
scripts/build-app.sh open "build/CodePilot.app" -
Use the menu bar app to add account profiles.
-
Install and start the gateway from the app setup screen or the helper script:
scripts/install-phone-gateway-agent.sh
-
Configure Cloudflare Tunnel for public-beta iPhone access.
-
If you have an approved iPhone beta build, install it and enter the gateway URL plus bearer token.
Keep the Mac awake and online, with the CodePilot gateway and Cloudflare Tunnel running, while using the iPhone companion. The current beta has no hosted relay that can reach an offline Mac.
See:
- Mac Installation
- iOS Installation
- Cloudflare Setup
- FAQ
- Beta Feedback Guide
- Privacy, beta data flow, and deletion
- Support
- Changelog
- App Store Metadata Draft
- Screenshot Plan
- Public Presence Checklist
- Security
- Architecture
- Troubleshooting
- Release Checklist
Remove gateway URLs, tokens, hostnames, localhost or local-web session URLs, local page contents, account names, local paths, private prompts, uploaded files, and unsanitized screenshots before submitting. For security-sensitive findings, read the security reporting guidance first and do not post sensitive evidence publicly.
- Manual account profile capture and switching.
- Automatic switching only after active turns are finished.
- 5-hour and weekly usage status, reset timing, and available reset credits per account.
- Global iOS credit progress indicator.
- iOS remote chat and file upload.
- Conversation steering and stop-turn controls where supported.
- In-app opening of
localhost,127.0.0.1, and::1web links through the authenticated Mac gateway. - Thread pinning, renaming, deletion, and project grouping.
- Connector/plugin status visibility.
- Turn-finished notifications when APNs is configured for the gateway.
- Gateway-backed auth refresh flows.
No public screenshots are committed yet. The beta screenshot checklist is tracked in docs/SCREENSHOTS.md so public images use demo data and avoid tokens, hostnames, local paths, private prompts, account names, or live desktop content.
CodePilot is being prepared for broader publishing through beta-first docs, sanitized screenshots, and maintainer-reviewed App Store metadata. Expect some internal names, bundle identifiers, LaunchAgent labels, and local state paths to still contain legacy Codex-specific names during the first migration phase.
Remote Desktop is not part of the supported public beta while its device-pairing and session-authorization enforcement is being completed and independently verified. Do not enable or promote it in beta builds yet.