Remote Control vs Cloud Agents
Your agent needs you. You are not at your desk.
Claude Code, Codex and Antigravity away from your desk
Chapters
- Intro
- Two questions, four boxes
- Claude Code Remote Control
- Claude Code in the cloud
- Codex: Remote and Cloud
- Antigravity: agy and Managed Agents
- Side by side
- Pitfalls and checklist
Who it's for
Developers who already use Claude Code, OpenAI Codex or Google Antigravity and want to leave long tasks running while they're away from the desk, and team leads deciding which of those modes to allow. Chapters 1–2 are plain language; the rest is technical.
Context
By autumn 2026 all three major coding agents ship both modes:
- Claude Code — Remote Control (
claude remote-control,claude --remote-control/--rc,/remote-control//rc) lets claude.ai/code or the Claude mobile app drive a session that keeps running on your machine. Cloud sessions (Claude Code on the web,claude --cloud, the mobile and Desktop apps, routines) run Claude Code in an isolated Anthropic-managed VM configured by a cloud environment. - OpenAI Codex — Codex Remote (preview in the ChatGPT mobile app 14 May 2026, GA 25–26 June 2026) pairs the ChatGPT app with the Codex desktop app on a Mac or Windows PC (or an SSH devbox) by QR code, through an OpenAI relay. Codex Cloud (
codex cloud, chatgpt.com/codex,@codexon GitHub) runs tasks in containers; at DevDay on 29 Sep 2026 those environments became reusable and shareable, and the older per-task experience is now labelled "Codex Cloud (Legacy)". - Google Antigravity 2.0 (I/O, 19 May 2026) — a desktop Agent Manager, the
agyCLI, an SDK and Managed Agents in the Gemini API. Remote Control (21 Aug 2026, rolling out from Google AI Ultra to all users) drives sessions on your own machines from any browser or phone, with push notifications when an agent needs input.
Architecture
| Component | Role | Notes |
|---|---|---|
| Local agent process | Runs the loop, tools and MCP servers on your machine | Claude Code CLI / Desktop / VS Code; Codex desktop app; Antigravity desktop or agy |
| Relay (vendor API) | Routes messages between the local process and remote clients | Claude: the local session makes outbound HTTPS requests only, registers with the Anthropic API and polls for work; no inbound ports. Codex: an OpenAI relay "keeps trusted machines reachable across devices without exposing them to the public internet" |
| Remote client | Phone app or browser that steers the session | Claude app / claude.ai/code; ChatGPT app; any browser for Antigravity |
| Device trust | Ties steering rights to a known device | Claude Trusted Devices (off by default); Codex QR pairing plus ChatGPT account MFA/SSO |
| Cloud VM / container | Runs the agent away from your machine | One isolated VM per Claude cloud session; one container per Codex task; a Linux sandbox per Managed Agents environment |
| Cloud environment | Saved config for cloud runs | Claude: network level, env vars, setup script (cached if it finishes in ≈5 min), API credentials; Codex: setup + maintenance scripts, internet settings, env vars, secrets |
| Egress policy | What the agent may reach | Claude levels None / Trusted / Full / Custom (Trusted = package registries, GitHub, cloud SDKs); Codex agent internet off by default, setup has access; Managed Agents allow/block lists |
| Credential proxy | Keeps secrets outside the sandbox | Claude GitHub proxy attaches the token server-side; Codex secrets are removed before the agent phase; Managed Agents credential injection by network rule |
| Handoff | Moves work between cloud and local | claude --teleport (cloud → terminal, one-way from the CLI); Codex apply diff / PR; Managed Agents reuse an environment ID |
Request flow
Remote Control (Claude Code):
claude remote-control(server mode) registers with the Anthropic API over outbound HTTPS and polls for work; press space for a QR code.- The phone scans it (or opens the session at claude.ai/code); the session list shows it.
- A message typed on the phone goes to the API, which routes it down a streaming connection to the local process.
- Tools run locally with local files, MCP servers and config; results, permission prompts and
AskUserQuestiondialogs go back to every connected device. - Short-lived, single-purpose credentials expire independently; if the laptop sleeps or the network drops, the session reconnects when the machine is back.
Cloud session (Claude Code):
claude --cloud "task"creates a session; the VM clones the GitHub remote at the current branch (not the local checkout) or uploads a bundle when there is no usable remote.- The environment's setup script runs (cached for later sessions when it finishes in ≈5 min); network access follows the environment's level.
- The agent works; git operations go through the GitHub proxy, which attaches credentials outside the VM.
- You steer from any device (
claude -p "…" --cloud <session-id>queues a follow-up), review the diff, create a PR, orclaude --teleportthe branch and conversation into a terminal. - Idle sessions pause; a paused VM can be reclaimed. Reopening restores the conversation on a fresh VM, but not background jobs.
The failure modes
- The mixed-up mode. A developer starts a long job with Remote Control, closes the laptop and expects it to finish overnight; the host sleeps and nothing runs. Or they send a job that needs a local database or VPN to a cloud VM that can't reach it. The two modes look alike on the phone but run in completely different places.
- The account is the new SSH key. Anyone signed into the account can steer a paired machine with its files and credentials. Without MFA and device verification, a phished session is remote code execution on your laptop.
- Leaky sandboxes. A cloud agent with full network and a token inside the VM can be prompt-injected into sending that token elsewhere.
- Vanishing work and runaway bills. Background jobs die when an idle VM is reclaimed; always-on cloud hosts (for example a Droplet made for Codex Remote) bill by the hour until deleted; auto-fix can reply on GitHub as you and trigger comment-driven automation.
Why it happens
Remote steering and remote execution are separate axes, but the UI for both is the same chat on a phone. And the thing that authorises steering is a consumer account login, not a network boundary.
The fix
- Pick the mode per task: Remote Control when the job needs your local files, tools, VPN or MCP servers and you'll keep the host awake; cloud sessions for long, parallel or overnight jobs on code that's pushed.
- Outbound-only relay: all three vendors reach the host without inbound ports; don't expose the machine yourself.
- Harden the account: MFA, Claude Trusted Devices, revoke paired devices you don't use.
- Least-privilege egress: start at Claude's Trusted (or None), Codex's default (agent internet off); add domains per task with Custom.
- Credentials outside the sandbox: Claude's GitHub proxy and API credentials, Codex secrets that only exist during setup, Managed Agents credential injection.
- Commit and push often in cloud sessions; use
--teleport/ apply diff to bring work home; review auto-fix on repos with comment-triggered automation.
Trade-offs
- Remote Control: full local context and zero setup, but it depends on the host being awake and online, and each phone becomes a way into your machine.
- Cloud sessions: survive a closed laptop and run in parallel, but only see what's pushed and what the setup script installs, and can't reach private networks unless you use a self-hosted environment.
- Tighter egress blocks legitimate installs; a slow setup script (>≈5 min) isn't cached, so every session pays for it.
- Reusable/persistent environments (Codex DevDay 2026, Managed Agents environment IDs) start faster but carry state between tasks.
Numbers worth knowing
- Claude Code Remote Control server mode:
--capacitydefault 32 concurrent sessions; server mode gives up after ≈10 min without the network; resume sessions for ≈4 hours after stopping; forwarded dialogs (other than permission prompts and questions) expire after 5 min by default. - Claude cloud setup script cached only if it finishes in ≈5 min; bundled uploads must be under 100 MB.
- Codex Cloud container cache up to 12 hours; secrets are available only to setup scripts.
- Codex Remote: mobile preview 14 May 2026, GA 25–26 June 2026; DevDay reusable environments 29 Sep 2026.
- Antigravity 2.0 19 May 2026; Remote Control 21 Aug 2026.
- Illustrative only: every repository, session name, command output, diff, plan and notification shown on the phone and terminal screens, and the "142 tests".
The code
# three cloud sessions, from your repo
claude --cloud "Fix the flaky test in auth.spec.ts"
claude --cloud "Update the API docs"
claude --cloud "Refactor the logger"
# queue a follow-up from any machine
claude -p "also add tests" --cloud session_01Di...
# pull finished work into your terminal
claude --teleport
# watch a PR: fix failing checks and review comments
/autofix-pr
Checklist
Guard the account
Anyone in your account can steer. Use MFA and Trusted Devices.
Keep hosts awake
Remote Control needs the host awake. Use the cloud overnight.
Idle VMs vanish
Background jobs die with the VM. Commit and push often.
Start with Trusted
Or no network. Add domains only when a task needs them.
Watch auto-fix
It replies on GitHub as you, which can trigger comment bots.
Kill idle boxes
Always-on cloud hosts bill by the hour until you delete them.
Sources
Claude Code docs: Remote Control, Use Claude Code in the cloud, Configure cloud environments.
OpenAI: Codex Cloud, Codex cloud environments, Codex internet access; coverage of Codex in the ChatGPT mobile app (The New Stack) and Codex Remote GA (AI Weekly); TechCrunch, 29 Sep 2026: reusable Codex cloud environments.
Google: Antigravity Anywhere with Remote Control, Introducing Google Antigravity 2.0, Gemini API: Antigravity agent, Introducing Managed Agents in the Gemini API, Antigravity CLI.
Logos: LobeHub Icons (MIT); marks belong to their owners, used only to name the products.
Coming next in the series: Agent sandboxing: how isolation really works