Codex Cloud reaches your tailnet.
AI Commander runs Codex on your machines.

OpenAI’s Codex Cloud now supports Tailscale as a VPN provider, so Codex Cloud tasks can reach resources on your tailnet (Tailscale blog, OpenAI docs: cloud environments). It is easy to read that as “reach my local Codex from anywhere”. It is the reverse: an OpenAI-managed cloud VM joins your tailnet and calls HTTP or HTTPS services in your network. AI Commander covers the other direction: Codex, Claude Code, and any shell command or detached job run on your own machines, driven from the AI client you already use.

Positioning in one line: AI Commander is complementary to Tailscale and Codex Cloud, not an alternative to either — and there is no additional AI Commander app: Claude, Codex, Grok, or ChatGPT is the UI, and only a host agent runs on each machine.

Sibling harness pages: Codex · Claude Code · ChatGPT · Grok — and every client on Connect your AI client.

Codex Cloud + Tailscale and AI Commander: two directions

Codex Cloud + TailscaleAI Commander
Where the agent runsCodex Cloud, on OpenAI-managed computersYour machines: laptop, workstation, home VM, VPS — whatever CLI or command you start runs there
DirectionThe cloud VM joins your tailnet and calls into your network; inbound connections to it are not supportedThe host agent on your machine dials out to the relay; your AI client sends commands through it
What it reachesHTTP and HTTPS services and private IPv4 subnet routes on your tailnet — internal APIs, package registriesThe shell, files, and detached jobs on each machine running the host agent
UICodex Cloud in ChatGPT (rolling out to paid ChatGPT plans)Your existing client — Claude, Codex, Grok, ChatGPT — over MCP; no AI Commander app
What you installA Tailscale VPN setting in the Codex Cloud environment (see the linked docs)The host agent on each machine, plus the AI Commander MCP server or plugin in your client
Network requirementA tailnet, with destinations allowed in both the VPN access rules and the environment’s internet-access settingsOutbound HTTPS to aicommander.dev; no inbound ports, no tailnet required

Use them together: Codex Cloud reaches the services on your tailnet, and AI Commander runs jobs on your tailnet machines. For Codex Cloud setup, follow the Tailscale blog and the OpenAI docs.

How it works on a tailnet-only machine

  1. Install the host agent on the box — macOS, Windows, or Linux (x86_64 and arm64); see Install the host agent and the signed Linux installer. It opens one outbound wss:// connection to aicommander.dev on port 443 and accepts no inbound connections, so the box needs no public IP and no port forwarding — but it does need direct outbound internet access to aicommander.dev.
  2. Attach AI Commander in your client. Terminal: codex mcp add aicommander --url https://aicommander.dev/mcp or claude mcp add --transport http aicommander https://aicommander.dev/mcp. Desktop and mobile: add the connector in Claude, ChatGPT, or Grok where that client supports one. Terminal, desktop, and mobile are just different clients for the same MCP server.
  3. Ask for the work as a detached job. Your client calls remote_job_start to run an installed Codex or Claude Code CLI, a build, or a test suite on that box, then remote_job_status and remote_job_logs to check on it. The job keeps running on the machine after the chat ends.
Prompt — Codex on your homelab box
On homelab, start a job in /home/me/src/api named codex-fix, running: codex exec --sandbox workspace-write "Fix the failing tests in tests/billing and run make test. Leave the changes uncommitted." Give me the jobId, then use remote_job_status and remote_job_logs to tail the last 50 lines.

Commands and output pass through the aicommander.dev relay, not over your tailnet. They are encrypted in transit; the path is not end-to-end encrypted — see Security. The agent does not use HTTP_PROXY / HTTPS_PROXY, so a machine whose only way out is a proxy cannot reach the relay. More on agent-to-agent runs: Remote coding agents.

FAQ

Is AI Commander an alternative to Tailscale?
No. AI Commander is not an alternative to Tailscale, and it does not integrate with it. Tailscale connects your devices into a private network; AI Commander lets your AI client run commands and detached jobs on machines you own. The host agent only needs outbound internet access to aicommander.dev, so it works the same on a machine that is on a tailnet, behind NAT, or on a public IP. It is also not an alternative to Codex, Claude Code, or Grok; it works with them.
Does Codex Cloud with Tailscale let me reach my local Codex from my phone?
No. It works the other way round. Codex Cloud runs tasks on OpenAI-managed computers, and with Tailscale configured, that cloud VM joins your tailnet so its tasks can call HTTP or HTTPS services on your private network. It does not run Codex on your laptop or server, and inbound connections to the Codex Cloud node are not supported. To start work on your own machines from your phone, open the Claude, ChatGPT, or Grok app, attach the AI Commander connector where that client supports one, and ask it to start a detached job on the machine.
Do I need to open ports, and does it work on a machine that is only reachable on my tailnet?
You open no ports. The host agent makes one outbound WebSocket connection over TLS (wss://) to the aicommander.dev relay on port 443 and accepts no inbound connections, so a machine with no public IP and no port forwarding, that you otherwise reach only over your tailnet, can still be driven. It still needs direct outbound internet access to aicommander.dev: commands travel through the relay, not over your tailnet, and the agent does not use HTTP_PROXY or HTTPS_PROXY settings. A machine with no internet egress cannot connect.
Can I use Codex Cloud with Tailscale and AI Commander together?
Yes. They cover different directions. Codex Cloud with Tailscale lets cloud tasks reach internal APIs, package registries, and other HTTP or HTTPS services on your tailnet. AI Commander lets Claude, Codex, Grok, or another MCP client run shell commands and detached jobs on your own machines, including an installed Codex or Claude Code CLI, and including machines that sit on the same tailnet.
Is AI Commander affiliated with Tailscale or OpenAI?
No. AI Commander is an independent product. It is not affiliated with, endorsed by, or sponsored by Tailscale Inc. or OpenAI, and there is no partnership or integration with either. Tailscale is a trademark of Tailscale Inc.; Codex and ChatGPT are trademarks of OpenAI.
Do I need a separate AI Commander app?
No. There is no additional AI Commander app. Your AI client is the UI: Claude, Codex, Grok, or ChatGPT in the terminal, on the desktop, or on your phone, with the AI Commander MCP server or plugin attached. The only thing you install is the host agent, on each machine you want to drive.

Next steps

Install the host agent on a machine you own, attach https://aicommander.dev/mcp in Claude, Codex, or Grok, then ask for a real job on that box.

Tailscale is a trademark of Tailscale Inc.; Codex and ChatGPT are trademarks of OpenAI. AI Commander is an independent product and is not affiliated with, endorsed by, or sponsored by either company.