Skip to main content
MAG&Cie
Back to tutorials
FreeIntermediateIA

Install Paseo on a server and drive your AI coding agents from your phone — 2026 guide

Step-by-step guide to move your coding agents (Claude Code, Codex…) to a VPS or Mac mini with Paseo: installation, phone pairing (encrypted relay, Tailscale or SSH), worktrees, parallel tasks, schedules and a security checklist.

October 8, 202645 min

What you'll learn

  • Install the Paseo daemon on a server, natively or with Docker
  • Install and authenticate a coding agent on that server
  • Connect your phone and computer to the daemon via encrypted relay, Tailscale or SSH
  • Run tasks in parallel, each in its own git worktree and branch
  • Schedule recurring agents (morning triage, dependency updates)
  • Apply a security checklist before daily use

Prerequisites

  • A Linux server (VPS) or a Mac mini running 24/7, with key-based SSH access
  • Node.js and npm, git
  • A subscription or API key for at least one coding agent (Claude Code, Codex, Copilot…)
  • A git repository with automated tests (strongly recommended)
On this page10

What you'll build: a server that keeps your coding agents (Claude Code, Codex, Copilot…) working continuously, one isolated branch per task, that you drive from your computer or your phone, without opening any port to the internet. Tool: Paseo, open source (Apache-2.0). Time: 45 minutes. To understand the benefits and limits first, read Remote AI coding agents: how it works.

Key vocabulary

  • Daemon: the Paseo service running on the server that starts and supervises agents. It listens on 127.0.0.1:6767 by default.
  • Client: the desktop, mobile or web app, or the CLI, that connects to the daemon.
  • Provider: the coding agent Paseo drives (Claude Code, Codex, Copilot, OpenCode…).
  • Workspace / worktree: a task's working space. With worktree isolation, Paseo creates a dedicated folder and git branch.
  • Relay: an optional intermediate server that lets your phone reach the daemon without a VPN; traffic through it is end-to-end encrypted.

Step 1 — Prepare the machine

Linux VPS

The default choice. A few cores and 8 to 16 GB of RAM for two or three parallel agents on a web project; more if your builds or tests are heavy.

Mac mini

Relevant for iOS development (Xcode) or if you prefer a physical machine at the office.

Docker container

Official image ghcr.io/getpaseo/paseo, daemon and agents running as a non-root user. Ideal for isolation.

Your workstation

To try things locally first with the desktop app, which starts its own daemon.

On a VPS, create a dedicated user without admin rights, allow key-based SSH authentication only, then install Node.js, npm and git.

Bash
# on the server, as root
adduser agents
# copy your public key to /home/agents/.ssh/authorized_keys,
# then disable PasswordAuthentication in /etc/ssh/sshd_config

Step 2 — Install and authenticate a coding agent

Paseo drives the agents you install; it doesn't ship them. Logged in as the agents user:

Bash
npm install -g @anthropic-ai/claude-code   # Claude Code
npm install -g @openai/codex               # Codex (optional)
claude   # first run: sign in to your account, then quit

Use your subscription or a development API key, never an account with access to your production environments.

Step 3 — Install Paseo and start the daemon

Bash
npm install -g @getpaseo/cli
paseo

The command starts the daemon and offers to enable the encrypted relay and print a pairing QR code (next step). Then check:

Bash
paseo daemon status   # is the daemon running, on which address?
paseo provider ls     # which agents are detected and available?

If an agent shows as "unavailable" although it's installed, it's almost always a PATH mismatch between your shell and the daemon: Paseo's Troubleshooting page walks through the fix.

Step 4 — Connect your phone and computer

Three documented methods, depending on your context:

MethodFor whomSetup
Paseo relaySimplest for the phone, no network to configurepaseo daemon pair, confirm, scan the QR code with the mobile app
Tailscale (VPN)Teams already on a VPN, no third party involveddaemon.listen on the Tailscale IP + password, then "Direct connection" in the app
SSHComputer and CLIDesktop app: Settings → Add host → Remote SSH; CLI: paseo --host ssh://agents@server ls -a

Relay. It's off by default. The daemon connects to it outbound, no port is opened, and traffic is end-to-end encrypted after pairing:

Bash
paseo daemon pair

The QR code and pairing link contain the daemon's public key: treat them like a password.

Tailscale. Get the server's address with tailscale ip -4, then in ~/.paseo/config.json:

JSON
{
  "daemon": {
    "listen": "100.101.102.103:6767"
  }
}

Protect the daemon with a password, then restart:

Bash
paseo daemon set-password
paseo daemon restart

In the mobile app: Settings → Add host → Direct connection, the Tailscale IP, port 6767 and the password.

Step 5 — Prepare the repository with paseo.json

Clone your repository on the server. Each worktree Paseo creates starts from a clean folder: no installed dependencies, no .env file. A paseo.json at the repository root describes what to prepare:

JSON
{
  "worktree": {
    "setup": "npm ci\ncp \"$PASEO_SOURCE_CHECKOUT_PATH/.env.development\" .env",
    "teardown": "rm -rf .cache"
  },
  "scripts": {
    "test": { "command": "npm test" },
    "web": { "type": "service", "command": "npm run dev -- --port $PASEO_PORT" }
  }
}
  • setup runs when the worktree is created, teardown when it's archived;
  • a service script gets a distinct port per worktree through $PASEO_PORT: several copies of the app run without conflict.

Paseo reads this file from the committed version of the base branch: commit it.

Step 6 — Run tasks in parallel

From the app (New workspace → Isolation: New worktree) or the CLI:

Bash
cd ~/projects/my-app
paseo run -d --provider claude \
  --new-workspace worktree --new-branch feature/invoice-filter --base origin/main \
  "Add a date filter to the invoice list. Add the tests and run them."

paseo run -d --provider claude \
  --new-workspace worktree --new-branch fix/csv-export --base origin/main \
  "Fix accented-character encoding in the CSV export. Add a regression test."

Branch off origin/main rather than main: Paseo fetches remote refs in the background, while your local main may be behind.

To follow along:

Bash
paseo ls                 # agents and status
paseo logs <id>          # what an agent is doing
paseo permit ls          # pending approvals
paseo permit allow <id>  # accept a request

On your phone you see the same agents, their files, terminals and diffs. For a second opinion, start another agent in the same workspace and ask it to review without editing.

Step 7 — Schedule recurring agents

A schedule starts a new agent on a cron. Example: ticket triage every weekday morning.

Bash
paseo schedule create --name "morning-triage" \
  --cron "0 8 * * 1-5" --timezone Europe/Paris \
  --provider claude --cwd ~/projects/my-app \
  "List issues opened since yesterday, rank them by priority and propose an action plan. Do not modify any file."

Manage them with paseo schedule ls, pause, resume, run-once and delete. Start with read-only tasks (triage, reports) before scheduling tasks that change code.

Step 8 — Security checklist before daily use

1

No production secrets

No production cloud keys, no access to real databases — only development credentials and anonymized test data.

2

Minimal exposure

Daemon listening locally or on the VPN IP. Never bound to 0.0.0.0 on a public IP without a firewall, password and HTTPS.

3

Graduated permissions

Approval modes for sensitive commands. No-approval modes only in a disposable container.

4

Protected branches

Agents only push to their own branches; the main branch requires a pull request, review and CI.

5

Upkeep

System and Paseo updates, backups of ~/.paseo and agent credentials, key rotation if a paired device is lost.

If you later enable Paseo Hub to trigger agents from GitHub, Slack or Discord, read its security page: a message or an issue can contain malicious instructions, and the agent must not have more rights than needed.

What next?

Want to frame the use of coding agents in your team (tooling, security, review, metrics)? That's the role of our Fractional CTO partnership. To have an application delivered by an agent-equipped team, see Application development.