Codex Cloud reaches your tailnet.
AI Commander runs Codex on your machines.
OpenAI’s Codex Cloud now supports Tailscale as a VPN provider, so Codex Cloud tasks can reach resources on your tailnet (Tailscale blog, OpenAI docs: cloud environments). It is easy to read that as “reach my local Codex from anywhere”. It is the reverse: an OpenAI-managed cloud VM joins your tailnet and calls HTTP or HTTPS services in your network. AI Commander covers the other direction: Codex, Claude Code, and any shell command or detached job run on your own machines, driven from the AI client you already use.
Sibling harness pages: Codex · Claude Code · ChatGPT · Grok — and every client on Connect your AI client.
Codex Cloud + Tailscale and AI Commander: two directions
| Codex Cloud + Tailscale | AI Commander | |
|---|---|---|
| Where the agent runs | Codex Cloud, on OpenAI-managed computers | Your machines: laptop, workstation, home VM, VPS — whatever CLI or command you start runs there |
| Direction | The cloud VM joins your tailnet and calls into your network; inbound connections to it are not supported | The host agent on your machine dials out to the relay; your AI client sends commands through it |
| What it reaches | HTTP and HTTPS services and private IPv4 subnet routes on your tailnet — internal APIs, package registries | The shell, files, and detached jobs on each machine running the host agent |
| UI | Codex Cloud in ChatGPT (rolling out to paid ChatGPT plans) | Your existing client — Claude, Codex, Grok, ChatGPT — over MCP; no AI Commander app |
| What you install | A Tailscale VPN setting in the Codex Cloud environment (see the linked docs) | The host agent on each machine, plus the AI Commander MCP server or plugin in your client |
| Network requirement | A tailnet, with destinations allowed in both the VPN access rules and the environment’s internet-access settings | Outbound HTTPS to aicommander.dev; no inbound ports, no tailnet required |
Use them together: Codex Cloud reaches the services on your tailnet, and AI Commander runs jobs on your tailnet machines. For Codex Cloud setup, follow the Tailscale blog and the OpenAI docs.
How it works on a tailnet-only machine
- Install the host agent on the box — macOS, Windows, or Linux (x86_64 and arm64); see Install the host agent and the
signed Linux installer. It opens one outbound
wss://connection to aicommander.dev on port 443 and accepts no inbound connections, so the box needs no public IP and no port forwarding — but it does need direct outbound internet access to aicommander.dev. - Attach AI Commander in your client. Terminal:
codex mcp add aicommander --url https://aicommander.dev/mcporclaude mcp add --transport http aicommander https://aicommander.dev/mcp. Desktop and mobile: add the connector in Claude, ChatGPT, or Grok where that client supports one. Terminal, desktop, and mobile are just different clients for the same MCP server. - Ask for the work as a detached job. Your client calls
remote_job_startto run an installed Codex or Claude Code CLI, a build, or a test suite on that box, thenremote_job_statusandremote_job_logsto check on it. The job keeps running on the machine after the chat ends.
Commands and output pass through the aicommander.dev relay, not over your tailnet. They are encrypted in transit; the path is not end-to-end encrypted —
see Security. The agent does not use HTTP_PROXY / HTTPS_PROXY, so a machine whose only way out is a proxy cannot reach the relay.
More on agent-to-agent runs: Remote coding agents.
FAQ
Next steps
Install the host agent on a machine you own, attach https://aicommander.dev/mcp in Claude, Codex, or Grok, then ask for a real job on that box.
Tailscale is a trademark of Tailscale Inc.; Codex and ChatGPT are trademarks of OpenAI. AI Commander is an independent product and is not affiliated with, endorsed by, or sponsored by either company.