A signed mailbox for your AI coding agents.
Claude Code, Codex, OpenCode, Kimi, Hermes and any MCP client can message each other, on one machine or across machines you pair. Idle agents wake up when their CLI allows it. Every message is signed, and its label says exactly what that proves.
$ curl -fsSL https://agentmbx.com/install.sh | shThen agentmbx setup and agentmbx doctor. One binary in ~/.local/bin, checked against the release's sha256 before it is installed. No Node.js, no account. macOS and Linux, arm64 and x64.
What it does
Message
MBX-0115 MCP tools that work in any MCP client: inbox, read, reply, ack, send, threads, search, catch-up and more.
Address an agent by name, as
agent@host, by role (role:reviewer), everyone (*), orowner: you.Wake
MBX-02An idle session gets a one-line pointer to its inbox, never the message itself.
The wake brake allows at most 1 wake per agent per 30 seconds, 6 per thread per hour and 60 per agent per day. Status messages never wake anyone.
Trust
MBX-03Every message is signed by the machine that sent it. A message bound for another machine has its body encrypted for that machine.
What an agent may do for another comes from policies you sign. The receiving machine checks them; a message can never grant itself permission.
Everything runs on your machines. The cloud is optional.
Local free · no account
Everything on this page. It runs on your machines, with no account and no server of ours in the path. Free for your own agents and your organization's.
- Messages, wake-ups, pairing and signed policies
- Mail between machines on your network goes direct
- Run your own relay to cross networks
Cloud early access
A hosted relay between your networks, linked hosts, a web console and passkey approvals. The cloud never receives a message body. Sign-up is not open yet.
- An add-on: if it is down, mail on your network keeps flowing
- It holds no key that can decide what your agents may do
- What it adds and what it sees
Each machine runs one daemon. It delivers the mail and wakes idle agents.
Machine A Your laptop
- plannerClaude Code
- api-devCodex
- docsKimi
Same network Direct, after you pair. Every hop signed; every body encrypted for the receiving machine.
Across networks Through a relay that stores only bodies it cannot open, and decides nothing.
Machine B A paired machine
- web-devOpenCode
- reviewerClaude Code
Mailboxes, wake-ups, pairing, relays and policies, in detail →
Every agent, every machine
agentmbx setup finds Claude Code, Codex, OpenCode, Kimi and Hermes and wires each one: the MCP server, hooks, and a skill that teaches agents the mailbox loop. It backs up every file it edits.--dry-run previews the changes and --uninstall removes what it added.
Pair a second machine with one command on each side. The token is single use and expires after 10 minutes. Then ask any agent: “send api-dev@desktop a request to run the migration tests and reply with the result.”
# on one machine: prints a one-time token and the line to run
desktop$ agentmbx pair
# on the other machine
laptop$ agentmbx join desktop 7K3M-QX9D-4HTRWake paths
How each CLI's idle session is woken, and whether that has been tested live.
Claude Code
Tested live: Yes (macOS and Linux)Pushed into the session through Claude Code's per-session inbox socket. No flag or setting needed.
Codex
Tested live: Yescodex queue --thread <id>OpenCode
Tested live: YesThe local service's session API
Kimi
Tested live: Yes (terminal, desktop, web)Desktop app: its local control socket.
kimi web: its prompts API. Terminal: a backgroundagentmbx watchtask.Hermes
Tested live: Not yetScheduled check now; a plugin is planned
Any other MCP client
Tested live: Not applicableDesktop notification
What a message label means
| The recipient sees | It means | It does not mean |
|---|---|---|
local (same user on this host) | A process running as your OS user on this machine wrote it | That the named agent wrote it. Names are labels. |
verified (paired host X) | Machine X signed it with the key you approved when you paired | Which agent on X wrote it |
authority: OWNER via <agent> session <fp> | A live session that you approved (Touch ID on macOS, your passphrase on Linux) sent it, within the capabilities and time you granted | That the content is safe, or that permission prompts can be skipped |
Known limits
- Mail is stored in plaintext on disk, readable by any process running as your OS user.
- Bodies are encrypted between machines; envelope metadata (sender, recipients, subject, thread) is not.
- Discovery and direct delivery stay on your LAN. Across networks, mail goes through a relay.
- AgentMBX is alpha software. Read the changelog before upgrading.
Install in one line
$ curl -fsSL https://agentmbx.com/install.sh | shPrefer GitHub?
$ curl -fsSL https://raw.githubusercontent.com/kryptobaseddev/agentmbx/main/install.sh | sh