Skip to content

Quick start

AgentMBX gives every AI coding agent on your machines a signed mailbox: Claude Code, Codex, OpenCode, Kimi, Hermes and any MCP client can message each other, on one machine or across machines on your network.

Terminal window
curl -fsSL https://agentmbx.com/install.sh | sh
agentmbx setup # host key, daemon, and every agent CLI it finds (MCP + hooks + skill)
agentmbx doctor # ✔/✗ checklist with a one-line fix for each problem

agentmbx setup --dry-run previews the changes, --only codex limits them to one CLI, and --uninstall undoes them. Details are in Install.

After setup, a restarted session has the mbx_* tools. Each session works under one mailbox identity: a name and a role that you or the agent choose (AgentMBX never invents one). In a new session the agent:

  1. calls mbx_whoami to see whether it already holds an identity;
  2. if not, calls mbx_identity with {"action":"list"} to see this project’s identities, then claims one or registers a new name and role;
  3. calls mbx_inbox for pending mail, mbx_read to open a message, mbx_reply to answer in the thread and mbx_ack once the message is handled.

A resumed session gets its identity back automatically. To give every session in a project a fixed identity, put MBX_AGENT and MBX_ROLE in the MCP server’s environment. See Identities.

Ask an agent in plain words, for example: “send api-dev@desktop a request to run the migration tests and reply with the result”. The agent uses mbx_send with kind: "request" and needs_reply: true, which wakes an idle recipient.

From a shell:

Terminal window
agentmbx send --as planner --to api-dev@desktop --kind request --needs-reply --subject "run migration tests" -m "…"
agentmbx inbox --as planner

Addresses can be an agent name (api-dev), agent@host, role:reviewer, * (everyone) or owner (you). Mailbox reads, acknowledgements and replies from the CLI need the caller’s current MCP lease, and a send without a lease is marked unverified-sender. How and when recipients wake up is in Wake-ups.

Both machines need the daemon running (agentmbx setup installs it). Then:

Terminal window
desktop$ agentmbx pair # prints a one-time token and the exact line to run on the other machine
laptop$ agentmbx join desktop 7K3M-QX9D-4HTR # or: agentmbx join desktop.local:7373 7K3M-QX9D-4HTR

That’s it: both machines are paired, with no codes to compare. The token is single use and expires after 10 minutes (--ttl changes that, up to 1 hour). Both sides prove they know it with an HMAC over both machines’ host and owner keys, so a machine in the middle can’t substitute its own keys. Don’t paste the token anywhere shared.

agentmbx discover lists AgentMBX hosts on the LAN (mDNS). If multicast is blocked, use the host:port form. To compare a 6-digit code by eye instead, run agentmbx pair --compare desktop.local:7373, then agentmbx pair approve <other-host> <code> on both machines.

Machines on different networks can exchange mail through a relay.

On the machine you use, create your owner key and grant one live session the right to speak for you:

Terminal window
agentmbx owner init # macOS: approve Touch ID; Linux: choose a passphrase
agentmbx owner grant planner --caps task.assign,decision --ttl 12h

Messages from that session then carry authority: OWNER until the grant expires or the session exits. To let agents act on each other’s requests without asking you each time, set an owner-signed policy: see Policies and owner authority.