Open to workNew YorkGet in touch

Coding Agents

Offrun runs Claude Code and Codex side by side: worktrees, logins, limits

A free Mac app runs your own Claude Code, Codex, AGY and Grok Build CLIs in per-agent git worktrees, signed in as you. Here is what it isolates and what it leaves to you.

Published
October 4, 2026
Read
7 min
Author
Samir Sengupta
Offrun Mac app running Claude Code and Codex side by side in separate git worktrees
Note 082 / 082Daily note · Written from 2 sources

the short version

  • Offrun isolates parallel agents at the filesystem level by giving each agent in a project its own git worktree, and nothing merges on its own.
  • Credentials stay with the vendor CLIs: each agent signs in as you, and prompts go directly to Anthropic, OpenAI, Google or xAI with no Offrun server in that path.
  • The sources describe no process sandbox or network restriction for the agents, so the documented isolation is about files and branches, not execution.
  • The costs of the wrapper are a macOS 14 on Apple Silicon requirement, four supported harnesses with no custom-harness option yet, and rate-limit handling that acts only after a login runs out.

Offrun is a free macOS app that runs the coding-agent CLIs you already use from one workspace on your Mac. It currently supports four: Claude Code, Codex, AGY and Grok Build. Each agent in a project gets its own git worktree, and each CLI stays signed in under your own account. The app says prompts go straight from your Mac to the provider, with no server of its own in between. It requires an Apple Silicon Mac on macOS 14 Sonoma or later and costs $0.

The project launched as a Show HN on 2026-10-03. The landing page at offrun.dev describes it as a layer around existing harnesses, and its FAQ says it does not replace Claude Code or Codex but runs them. Pi and OpenCode are listed as coming soon. For an engineer deciding whether to put this between themselves and their agents, the questions are what gets isolated, where credentials live, and what you lose by not driving each CLI directly.

What Offrun isolates, and what it does not

The isolation unit is the git worktree. Every agent working in a project gets its own worktree, so two agents on the same repo do not touch the same files. The product example runs a refactor and a bug fix at once and leaves the merge to you. In the demo, a flaky-test fix reports that it changed only test/upload.test.js on its own branch and passed 50 runs in a row.

Workspace state is stored in the repository, not in a hosted service. Chats, memory and worktrees live under .offrun and .worktrees in the project folder, and the page says Offrun keeps no copy. Teams will need to decide whether those directories go into their ignore rules or get committed. The page invites you to version the memory files, but it says nothing about whether chat history is meant to be committed.

Execution isolation is not described. The page says the app runs the CLIs on your Mac, signed in as you. It does not mention containers, a VM, filesystem permissions beyond the worktree, or network egress controls. On what the sources describe, a worktree is a way to keep agents from editing the same files, not a security boundary.

Credentials stay with the vendor CLIs

Offrun requires no new account and no API key. You connect harness accounts under Settings, then Agents, and you can add a second account per harness. The demo shows Claude Code with a Default login at sam@studio.dev and a Work login at sam@acme.co. It also shows Codex signed in with ChatGPT, AGY signed in with Google, and Grok Build signed in with X. The page says each agent runs in its own folder and that Offrun never sees your password.

The data-flow claim is specific. Prompts and code go from the Mac to Anthropic, OpenAI, Google or xAI on your own login, and Offrun has no server in that path and never handles your keys. The sources do not explain how separate logins for the same CLI are kept apart on disk.

The pricing section also advertises free credits for 100+ connectors, which let agents find an email, file a GitHub issue or post to Slack. The no-server claim is made for the prompt path, and the connector path is not described. Check how connector traffic is routed before you enable connectors on a work machine.

Peer review and limits run on your own accounts

Peer review uses one of your own agent accounts as a reviewer, and you choose the model in the model picker. Findings appear in the chat while the work is still uncommitted. If you ask for fixes, they land in your message box for you to read before anything is sent. The FAQ says peer review cannot change your code, and the page says nothing merges on its own. In the demo, Codex reviews this retry-backoff change:

javascript
async function retry (req, n) {
  const wait = Math.min(2 ** n * 100, 30_000)
  const jitter = wait * 0.2 * Math.random()
  await sleep(wait + jitter)
}

The review is marked 'changes requested' and flags a warning at src/retry.js:2. The 30-second cap is longer than the gateway's 25-second timeout, so the last retry is cut off. The page says review runs on your own agent accounts, with no second subscription and no bot on your pull requests. It does not say how much usage a review consumes on the reviewing account.

Limit handling also runs across your accounts. When one login hits its usage limit, Offrun moves the chat to a login that still has room and tells you. You send your message again, and the new login picks up the whole conversation. When you are out of logins, it offers another agent. The demo has Codex continuing a chat after Claude Code hits its limit, with a note that Claude Code resets at 3am.

The sources do not say how a conversation built in one harness is replayed into another. They also do not say what tool state, if any, carries over.

Project memory lives as plain files in the repo

The workspace keeps repo-wide conventions in one place, and each agent's goal, plan and dead ends in another. The api-gateway example has three files: conventions.md, which every agent reads; plan.md, for one feature's approach; and dead-ends.md, which records what was tried and failed. Agents read that context at the start of each session and write back to it as they work, so the fourth session knows what the first one already tried.

Because these are plain files in the project folder, you can open, edit and commit them like any other file. The same property means anything an agent writes back will be read by later sessions unless someone reviews it. Diffing these files is the obvious control.

The remaining features are about convenience. A preview pane shows changed files, diffs with line numbers, rendered markdown and tables, images, PDFs and a small browser with an address bar. Dictation transcribes on-device and needs a network connection only for setup. It keeps identifiers spelled the way your code spells them, with a vocabulary list that maps 'retry backoff helper' to retryBackoffHelper, and optional voice samples.

What you give up versus each agent's own harness

  • Platform: the page specifies Apple Silicon (M1 or newer) on macOS 14 Sonoma or later. Linux and Windows builds do not exist yet, according to the Hacker News thread.
  • Harness coverage: four harnesses today. Pi and OpenCode are listed as coming soon, and per the thread, custom-harness support is still in progress.
  • Visibility before dispatch: limit handling acts after a login hits its limit. The sources describe no view of remaining headroom per account before you start work.
  • Execution boundary: you get filesystem separation through worktrees, but no described sandbox. The sources do not say whether each CLI's own permission or approval prompts are surfaced in the Offrun UI.
  • Handoff fidelity: moving a chat to another login or another agent is advertised, but the mechanism and what is lost in translation are not documented.

What Hacker News commenters pushed back on

The top question was how Offrun differs from Herdr. A reply written for the product said Herdr lets you run agents anywhere, Offrun helps you manage them, and Herdr integration is coming. Another commenter pointed out that Herdr runs on Linux, Windows and Intel Macs, and said it has reportedly raised $6 million.

A product-side reply said Offrun was released for Mac on both Apple Silicon and Intel, with Windows and Linux to follow. That conflicts with the landing page, which says Apple Silicon only. The same reply said integrations for Herdr, Pi and OpenCode, plus a way to add a custom harness, are being worked on.

One commenter asked to see per-account rate-limit headroom before dispatching, not after getting stuck mid-task. The reply did not address pre-dispatch visibility. It said users can switch to another account in one click and resume.

Others compared Offrun with Paseo, Orca, Goose, T3 Code, Conductor, JetBrains Air and more than half a dozen others. The product-side answer was a difference in design philosophy: other meta-harnesses focus on agent-in-the-loop, and Offrun focuses on human-in-the-loop. The reply said Offrun would be feature-complete in the next two months, with a cloud product and a mobile app launching soon. One commenter argued that tools with tighter single-harness integration may work better because ACP is fairly bare. The sources do not say whether Offrun uses ACP.

What the launch leaves undocumented

The launch leaves several engineering questions unanswered. On each one below, the landing page and the thread are either silent or contradict each other:

  • How cross-agent chat handoff carries a conversation from one harness to another.
  • How multiple logins for one CLI are kept apart on disk.
  • Whether the planned cloud product changes the claim that no Offrun server sits in the prompt path.
  • How the 100+ connectors route data.
  • Which hardware the app actually supports, given the conflict between the landing page and the thread.
  • Whether custom-harness support arrives, since that decides whether teams with their own agent loops can use Offrun at all.

Until these are documented, the safe reading is narrow. Offrun is a free local front end for four vendor CLIs that adds per-agent worktrees, a reviewer that cannot change your code, and file-based memory. Any security and execution guarantees still come from the harnesses underneath.

Questions this raises

Does Offrun sandbox coding agents?

No sandbox is described. Each agent gets its own git worktree so agents do not edit the same files, but the page mentions no containers, VM or network egress controls, so a worktree is not a security boundary.

Does Offrun need an API key or see my credentials?

Offrun requires no new account and no API key; each CLI stays signed in under your own vendor login. The page says prompts go from your Mac straight to Anthropic, OpenAI, Google or xAI, and Offrun never handles your keys or sees your password.

What happens in Offrun when Claude Code hits its usage limit?

Offrun moves the chat to another login that still has room and tells you, and the new login picks up the whole conversation after you resend your message. When you run out of logins it offers another agent, such as Codex continuing a chat after Claude Code hits its limit.

These daily notes are drafted by a model I run and operate myself - the same kind of pipeline this site is about - from sources published in the previous 24 hours, and every one lists what it read. The longer essays, the talks and the preprint are mine, written by hand.

More notes

Building something on this?

I ship production LLM, RAG and agentic systems for a living - the infrastructure behind the things these notes are about. Open to roles, contract work and research collaboration.