In short: a remote coding agent is a coding agent (Claude Code, Codex, GitHub Copilot, OpenCode…) that runs on a dedicated machine — server, VPS, Mac mini, container — rather than on your laptop. An open-source orchestrator like Paseo runs several agents in parallel, each in its own git worktree and branch, and lets you drive them from your desk, a browser, the command line or your phone. Code stays on your machines; remote access goes through SSH, a VPN or an end-to-end encrypted relay. The rule that doesn't change: the agent proposes, a human reviews, CI validates.
Why take coding agents off the laptop?
Coding agents changed scale in 2025-2026: they no longer complete a line, they take on a whole task — read the code, edit several files, run the tests, fix, repeat. A task can last from a few minutes to over an hour.
Running them on your workstation quickly raises three problems:
- The laptop becomes the agent's hostage. Closing the lid, switching networks or heading to a meeting interrupts the work.
- One task at a time, in practice. Two agents in the same folder step on each other: files edited simultaneously, tests breaking for no reason.
- Monitoring is a constraint. An agent waiting for approval ("may I run this command?") stays blocked until someone is at the screen.
Moving agents to a dedicated machine solves all three: the machine runs continuously, each task has its isolated space, and you answer approvals from anywhere.
Paseo at a glance
Paseo describes itself as an open-source agentic development environment (Apache-2.0 license, no telemetry, no required account). Its architecture resembles Docker's:
A daemon that runs the agents
It runs wherever you want agents to work: your computer, a Mac mini, a VPS or a Docker container. It manages agent lifecycles, workspaces and terminals.
Clients everywhere
Desktop app (macOS, Windows, Linux), native iOS and Android app, web client and CLI. They all connect to the same daemon: pick up on your phone what you started at your desk.
Your agents, your subscriptions
Claude Code, Codex, GitHub Copilot, OpenCode, Pi and other ACP-compatible agents. Paseo drives the tools you already use, with your credentials, configuration and MCP servers.
One branch per task
Each task can run in its own git worktree, on its own branch. Agents work in parallel without conflicts; you review each diff and decide what to merge.
On top of that come schedules (start an agent on a cron: morning ticket triage, dependency updates, build babysitting), orchestration tools that let an agent launch others and collect their results, and an optional service, Paseo Hub, that starts agents from GitHub, Slack or Discord events.
How it works: the architecture
The principle fits in one table: agents run on the daemon's machine; clients only drive them.
| Component | Where it runs | Role |
|---|---|---|
| Paseo daemon | Server, VPS, Mac mini, Docker container | Starts and supervises agents, manages worktrees, terminals and schedules |
| Coding agents | Same machine as the daemon | Read and edit code, run tests, call their provider's API |
| Clients | Computer, browser, phone, terminal | Start tasks, follow progress, review diffs, approve permissions |
| Transport | Encrypted relay, SSH, Tailscale/VPN, local network | Connects a remote client to the daemon |
For remote access, three documented options:
- SSH from the desktop app or the CLI, to a daemon listening locally on the server;
- Tailscale (or another VPN): the daemon listens on the VPN's private address, never on the internet;
- the Paseo relay, off by default: the daemon connects to it outbound (no port to open) and traffic is end-to-end encrypted after QR-code pairing. According to the documentation, the relay only sees metadata and can neither read nor forge messages.
What it changes in practice
Start a task and walk away. You describe the task ("add a date filter to the invoice list, with tests"), the agent works on the server, and you're notified when it's done or needs approval.
Parallelize. Three independent tasks, three worktrees, three agents — possibly from different providers. Or two agents on the same task to compare approaches before choosing.
Review from your phone. The mobile app gives access to agents, files, terminals and diffs. Approving a permission or restarting a stuck agent no longer requires being at your desk.
Automate maintenance. A schedule can start an agent every morning to go through open tickets, or every week to propose dependency updates on a dedicated branch.
Make agents collaborate. An agent can delegate a subtask to another, ask an agent from another provider for a review ("second opinion"), then consolidate.
Who is it for?
Good fit
- Teams and freelancers already using coding agents daily
- Well-scoped, testable tasks: fixes, small features, migrations, missing tests
- Recurring maintenance: dependencies, docs, cleanup
- Developers often on the move or in meetings
- Rapid prototyping (PoC) exploring several options in parallel
Less suited
- Projects without tests or CI: no quick way to verify what the agent produced
- Structural architecture decisions that need human judgment
- Code handling secrets or sensitive data without isolation
- Organizations with nobody able to review the code produced
The guardrails you need
A remote coding agent acts with the rights of the machine it runs on. That's what makes it useful, and it's what demands discipline.
- Dedicated machine or user. A VPS or container reserved for agents, with a non-admin user. Paseo's official Docker image runs the daemon and agents as a non-root user.
- Minimal network exposure. Daemon listening locally + SSH, VPN or encrypted relay. Never expose the daemon to the internet without a password; Paseo supports password authentication and a hostname allowlist.
- Graduated permissions. Most agents offer modes (plan only, approval for each command, accept file edits…). Keep no-approval modes for disposable environments.
- One branch per task, one review per merge. Worktrees isolate the work; the decision to merge stays human, backed by tests and CI.
- Distrust external input. If an agent is triggered by a ticket, a Slack message or a GitHub issue, that content may contain malicious instructions. Limit what those agents can do and read Paseo Hub's security documentation before enabling it.
- Personal data. Code sent to the agent's provider may contain test data or configuration: anonymize datasets and check the provider's terms (data reuse, hosting).
Limits to keep in mind
- An agent can be confidently wrong. Time saved is measured in merged tasks, not launched ones. Without automated tests, review eats much of the gain.
- Review becomes the bottleneck. Launching ten agents is easy; seriously reviewing ten diffs isn't. Start with two or three parallel tasks.
- Usage costs grow with parallelism. Several simultaneous agents burn through subscription quotas or API credits faster.
- The machine needs upkeep: system updates, backups, rotation of agent credentials.
Get started in a week
- Day 1 — Local. Install the desktop app on your workstation, run an agent on a small task in a worktree, review the diff.
- Day 2 — Mobile. Pair your phone and follow a task remotely.
- Days 3-4 — Server. Move the daemon to a dedicated VPS or Mac mini — that's what our tutorial Install Paseo on a server and drive your AI coding agents from your phone covers.
- Day 5 — Parallel. Run two or three independent tasks, and measure the time from launch to merge and the number of corrections requested.
Going further
To understand how agents plug into your tools, see our tutorial Build an MCP server with FastMCP. For a business-side AI agent rather than a coding one, read AI agent as a personal assistant: email triage, calendar and meetings.
And if you want to bring coding agents into your team with a method and guardrails, or have an application built by a team that uses them daily:
- Fractional CTO partnership — frame the use of AI agents in your tech team (tooling, security, review, metrics);
- Application development — your applications delivered by an agent-equipped team;
- Application PoC — test an idea in a few weeks, several options in parallel.
Sources: official Paseo documentation (architecture, security, connectivity, worktrees, schedules), getpaseo/paseo GitHub repository.