VCode home

The security model

Agents: claude, codex, opencode · On: phone, desktop

Anything that can log in to VCode runs code as your user on that machine. The agents work without asking for approval, so a login is full trust. VCode's security is about who can log in, not about limiting what a logged-in session can do.

Why you would use it

Before you open VCode to the internet or pair a phone, you should know what a login is worth and what stands in front of it.

How to use it

  1. Keep the login token secret. Treat it like the password to a shell on the machine: if it leaks, change it and restart VCode, and every browser has to sign in again.
  2. Leave VCode listening on the machine itself, and reach it from outside through one gate you control: a private network or a tunnel with its own sign-in, or your VCode account.
  3. Pair only your own devices, and remove a device you no longer use from Settings.

What you see

Limits and known gaps