Skip to main content
MAG&Cie
Aller au contenu

§ IA·8 min read·

Remote AI coding agents: run agents on a server and drive them from your phone (Paseo)

A coding agent doesn't need your laptop. With an orchestrator like Paseo, agents (Claude Code, Codex, Copilot…) run on a dedicated machine, each on its own branch, and you drive them from your desk or your phone. How it works, architecture, security, use cases and limits.

By MAG&CieAI agentscoding agentPaseoClaude Code
§ Sommaire
  1. § 01Why take coding agents off the laptop?
  2. § 02Paseo at a glance
  3. § 03How it works: the architecture
  4. § 04What it changes in practice
  5. § 05Who is it for?
  6. § 06The guardrails you need
  7. § 07Limits to keep in mind
  8. § 08Get started in a week
  9. § 09Going further

In short: a remote coding agent is a coding agent (Claude Code, Codex, GitHub Copilot, OpenCode…) that runs on a dedicated machine — server, VPS, Mac mini, container — rather than on your laptop. An open-source orchestrator like Paseo runs several agents in parallel, each in its own git worktree and branch, and lets you drive them from your desk, a browser, the command line or your phone. Code stays on your machines; remote access goes through SSH, a VPN or an end-to-end encrypted relay. The rule that doesn't change: the agent proposes, a human reviews, CI validates.

Why take coding agents off the laptop?

Coding agents changed scale in 2025-2026: they no longer complete a line, they take on a whole task — read the code, edit several files, run the tests, fix, repeat. A task can last from a few minutes to over an hour.

Running them on your workstation quickly raises three problems:

  • The laptop becomes the agent's hostage. Closing the lid, switching networks or heading to a meeting interrupts the work.
  • One task at a time, in practice. Two agents in the same folder step on each other: files edited simultaneously, tests breaking for no reason.
  • Monitoring is a constraint. An agent waiting for approval ("may I run this command?") stays blocked until someone is at the screen.

Moving agents to a dedicated machine solves all three: the machine runs continuously, each task has its isolated space, and you answer approvals from anywhere.

Paseo at a glance

Paseo describes itself as an open-source agentic development environment (Apache-2.0 license, no telemetry, no required account). Its architecture resembles Docker's:

A daemon that runs the agents

It runs wherever you want agents to work: your computer, a Mac mini, a VPS or a Docker container. It manages agent lifecycles, workspaces and terminals.

Clients everywhere

Desktop app (macOS, Windows, Linux), native iOS and Android app, web client and CLI. They all connect to the same daemon: pick up on your phone what you started at your desk.

Your agents, your subscriptions

Claude Code, Codex, GitHub Copilot, OpenCode, Pi and other ACP-compatible agents. Paseo drives the tools you already use, with your credentials, configuration and MCP servers.

One branch per task

Each task can run in its own git worktree, on its own branch. Agents work in parallel without conflicts; you review each diff and decide what to merge.

On top of that come schedules (start an agent on a cron: morning ticket triage, dependency updates, build babysitting), orchestration tools that let an agent launch others and collect their results, and an optional service, Paseo Hub, that starts agents from GitHub, Slack or Discord events.

How it works: the architecture

The principle fits in one table: agents run on the daemon's machine; clients only drive them.

ComponentWhere it runsRole
Paseo daemonServer, VPS, Mac mini, Docker containerStarts and supervises agents, manages worktrees, terminals and schedules
Coding agentsSame machine as the daemonRead and edit code, run tests, call their provider's API
ClientsComputer, browser, phone, terminalStart tasks, follow progress, review diffs, approve permissions
TransportEncrypted relay, SSH, Tailscale/VPN, local networkConnects a remote client to the daemon

For remote access, three documented options:

  • SSH from the desktop app or the CLI, to a daemon listening locally on the server;
  • Tailscale (or another VPN): the daemon listens on the VPN's private address, never on the internet;
  • the Paseo relay, off by default: the daemon connects to it outbound (no port to open) and traffic is end-to-end encrypted after QR-code pairing. According to the documentation, the relay only sees metadata and can neither read nor forge messages.

What it changes in practice

Start a task and walk away. You describe the task ("add a date filter to the invoice list, with tests"), the agent works on the server, and you're notified when it's done or needs approval.

Parallelize. Three independent tasks, three worktrees, three agents — possibly from different providers. Or two agents on the same task to compare approaches before choosing.

Review from your phone. The mobile app gives access to agents, files, terminals and diffs. Approving a permission or restarting a stuck agent no longer requires being at your desk.

Automate maintenance. A schedule can start an agent every morning to go through open tickets, or every week to propose dependency updates on a dedicated branch.

Make agents collaborate. An agent can delegate a subtask to another, ask an agent from another provider for a review ("second opinion"), then consolidate.

Who is it for?

Good fit

  • Teams and freelancers already using coding agents daily
  • Well-scoped, testable tasks: fixes, small features, migrations, missing tests
  • Recurring maintenance: dependencies, docs, cleanup
  • Developers often on the move or in meetings
  • Rapid prototyping (PoC) exploring several options in parallel

Less suited

  • Projects without tests or CI: no quick way to verify what the agent produced
  • Structural architecture decisions that need human judgment
  • Code handling secrets or sensitive data without isolation
  • Organizations with nobody able to review the code produced

The guardrails you need

A remote coding agent acts with the rights of the machine it runs on. That's what makes it useful, and it's what demands discipline.

  1. Dedicated machine or user. A VPS or container reserved for agents, with a non-admin user. Paseo's official Docker image runs the daemon and agents as a non-root user.
  2. Minimal network exposure. Daemon listening locally + SSH, VPN or encrypted relay. Never expose the daemon to the internet without a password; Paseo supports password authentication and a hostname allowlist.
  3. Graduated permissions. Most agents offer modes (plan only, approval for each command, accept file edits…). Keep no-approval modes for disposable environments.
  4. One branch per task, one review per merge. Worktrees isolate the work; the decision to merge stays human, backed by tests and CI.
  5. Distrust external input. If an agent is triggered by a ticket, a Slack message or a GitHub issue, that content may contain malicious instructions. Limit what those agents can do and read Paseo Hub's security documentation before enabling it.
  6. Personal data. Code sent to the agent's provider may contain test data or configuration: anonymize datasets and check the provider's terms (data reuse, hosting).

Limits to keep in mind

  • An agent can be confidently wrong. Time saved is measured in merged tasks, not launched ones. Without automated tests, review eats much of the gain.
  • Review becomes the bottleneck. Launching ten agents is easy; seriously reviewing ten diffs isn't. Start with two or three parallel tasks.
  • Usage costs grow with parallelism. Several simultaneous agents burn through subscription quotas or API credits faster.
  • The machine needs upkeep: system updates, backups, rotation of agent credentials.

Get started in a week

  • Day 1 — Local. Install the desktop app on your workstation, run an agent on a small task in a worktree, review the diff.
  • Day 2 — Mobile. Pair your phone and follow a task remotely.
  • Days 3-4 — Server. Move the daemon to a dedicated VPS or Mac mini — that's what our tutorial Install Paseo on a server and drive your AI coding agents from your phone covers.
  • Day 5 — Parallel. Run two or three independent tasks, and measure the time from launch to merge and the number of corrections requested.

Going further

To understand how agents plug into your tools, see our tutorial Build an MCP server with FastMCP. For a business-side AI agent rather than a coding one, read AI agent as a personal assistant: email triage, calendar and meetings.

And if you want to bring coding agents into your team with a method and guardrails, or have an application built by a team that uses them daily:

Sources: official Paseo documentation (architecture, security, connectivity, worktrees, schedules), getpaseo/paseo GitHub repository.

§ Tags

AI agentscoding agentPaseoClaude CodeCodexsoftware developmentgit worktreeVPSagent orchestrationdeveloper productivitysecurity
Back to blog

§ FAQ

Questions frequentes

  • What is a remote AI coding agent?
    It's a coding agent (Claude Code, Codex, GitHub Copilot, OpenCode…) that runs on a machine other than the developer's — a server, a VPS, a Mac mini or a container — and is driven remotely from a computer, a browser or a phone. The agent keeps working when the laptop lid is closed.
  • What is Paseo?
    Paseo is an open-source agentic development environment (Apache-2.0 license). A daemon runs on the machine where agents execute; desktop (macOS, Windows, Linux), mobile (iOS, Android), web and command-line clients connect to it. It supports Claude Code, Codex, GitHub Copilot, OpenCode, Pi and other ACP-compatible agents, with no telemetry and no required Paseo account.
  • Is my code sent to Paseo's servers?
    No, according to Paseo's documentation: agents run on your machines and talk directly to their provider's API (Anthropic, OpenAI…). For remote access, the optional relay encrypts traffic end to end between the phone and the daemon; it only sees metadata (IP addresses, timing, message sizes). You can also skip it and use SSH or a VPN such as Tailscale.
  • Why run several agents in parallel?
    To handle independent tasks at the same time (a fix, a feature, a version upgrade), or to compare two implementations of the same feature. Paseo isolates each task in its own git worktree and branch: agents don't step on each other and you choose what to merge.
  • What are the risks of a coding agent running unattended?
    It acts with the machine's rights and credentials: it can modify or delete files, run commands, push code. Guardrails: a dedicated machine or user, no production secrets reachable, permission modes that require approval for sensitive actions, one branch per task, and human review + CI before any merge.
  • How much does Paseo cost?
    Paseo is free and open source. Costs are those of your agents (Claude, ChatGPT/Codex, Copilot subscriptions or API usage) and, if you move agents off your laptop, of the host machine (a VPS at a few dozen euros a month is often enough). Paseo Hub, which triggers agents from GitHub, Slack or Discord, is optional and can be self-hosted.
  • Is this suitable for a small business without a tech team?
    Not directly: a coding agent produces code that someone must be able to review, test and deploy. But a business having an application built can benefit indirectly — shorter lead times, more iterations — if its vendor or CTO frames these agents with a method and guardrails.

§ Related articles

Related articles