Skip to content

Commit 0ff3ebb

Browse files
authored
Merge pull request #6 from dazer1234/codex/ios-app
Release Codex Deck 0.7.0
2 parents f3b6190 + c58b008 commit 0ff3ebb

89 files changed

Lines changed: 12752 additions & 189 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

.gitignore

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,3 +15,6 @@ codex-deck-launcher-*.zip
1515
!.env.example
1616
*.tmp
1717
.DS_Store
18+
ios/**/xcuserdata/
19+
ios/DerivedData/
20+
ios/Configuration/Local.xcconfig

CHANGELOG.md

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,20 @@
11
# Changelog
22

3+
## 0.7.0 - 2026-07-21
4+
5+
- Added a source-distributed native SwiftUI iPhone companion that merges authenticated Mac and Windows snapshots while leaving the Stream Deck plugin independent.
6+
- Added pinned-TLS Nearby Wi-Fi pairing and private Tailscale HTTPS profiles without exposing Chrome DevTools or accepting wildcard/public relay listeners.
7+
- Added native task details, command receipts, Attention Center, optional notifications, one-task Live Activity follow mode, five WidgetKit experiences, and app-local key layouts.
8+
- Added circular 5-hour/weekly usage, a two-window overview, optional context rings, and a centered reset-credit action with a deliberate 1.2-second hold.
9+
- Added portable local iOS signing configuration; personal team, bundle, App Group, relay tokens, and official OpenAI keycap artwork remain outside public artifacts.
10+
- Fixed empty iPhone agent keys drawing two misaligned plus symbols.
11+
- Fixed the iPhone dashboard in landscape with a bounded two-column layout instead of stretching the square Micro device across the full screen width.
12+
- Fixed completed, selected, and mirrored tasks retaining stale working/unread colors across Mac and Windows while preserving fresh approval and active-work signals.
13+
- Fixed long-running iPhone relays retaining stale Codex version metadata after an app update; host identity remains stable and no Codex restart is required.
14+
- Updated renderer discovery and active-task detection for Codex macOS `26.715.70719` and Windows `26.715.8383.0` without hardcoding renderer hashes.
15+
- Added physical-iPhone Swift tests, macOS launcher/watcher self-tests, release privacy audits, and expanded relay, renderer, usage, and project regression coverage.
16+
- Added beginner installation, same-Wi-Fi verification, and release documentation plus explicit inspiration credit for the mobile companion concept.
17+
318
## 0.6.3 - 2026-07-19
419

520
- Fix completed tasks remaining stuck in the green finished state after they are opened.

README.md

Lines changed: 35 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,7 @@ The same Stream Deck plugin package works in all three modes. Install only the l
1616
| Windows only | Windows | Local Windows Codex | [Windows setup](docs/WINDOWS.md) |
1717
| Mac only | macOS | Local Mac Codex | [macOS setup](docs/MACOS.md) |
1818
| Windows + Mac | Windows | Both apps; six agents are merged | [Multi-host setup](docs/MULTI_HOST.md) |
19+
| iPhone companion | iOS 17+ | Private Mac and/or Windows nodes | [iPhone app](docs/IOS.md) · [Install from source](docs/IOS_INSTALL.md) |
1920

2021
Windows-only and Mac-only mode have no relay, no second computer dependency, and no host badges. Multi-host mode is optional and can be disabled without changing the local bridge on either machine.
2122

@@ -27,11 +28,14 @@ Windows-only and Mac-only mode have no relay, no second computer dependency, and
2728
- Native key-down/key-up handling for Micro slots `ACT06` through `ACT12`.
2829
- Native joystick up, right, down, left, and encoder click.
2930
- Dedicated reasoning-effort up/down buttons with press-and-hold repeat.
31+
- Live usage controls: a configurable circular 5-hour/weekly limit key and a two-window overview.
32+
- A centered reset-credit counter with a deliberate 1.2-second hold before an applicable credit can be consumed.
3033
- A local `codex://threads/new` action for a new task.
3134
- Standalone actions for all official single-size keycaps, resolved from the installed Codex build at runtime.
3235
- Optional local loading of official keycap SVGs; those protected files are never included in this repository or its releases.
3336
- Optional authenticated SSH/Tailscale relay for one Stream Deck controlling Windows and Mac Codex together.
3437
- Per-host health on the Windows/Mac target key, with last-known agent tiles visibly marked when native desktop signals are uncertain or the relay is offline.
38+
- Native SwiftUI iPhone companion with dual-host agents, usage, reset credits, and authenticated Micro controls over pinned-TLS Nearby Wi-Fi or private Tailscale HTTPS.
3539

3640
## Requirements
3741

@@ -53,6 +57,15 @@ Other Stream Deck models may work, but the included layout and physical-device t
5357
4. In **Codex Settings > Codex Micro**, choose the agent source, action assignments, joystick actions, and encoder behavior.
5458
5. Build the two Stream Deck pages below.
5559

60+
The iPhone companion is currently source-only: **a Mac with Xcode is required
61+
to build, sign, and install it**, even when the phone will control only a
62+
Windows Codex node. There is no App Store, TestFlight, or pre-signed IPA build
63+
yet. After installation, the Mac does not need to stay online unless it is one
64+
of the computers being controlled. Nearby pairing works on the same private
65+
Wi-Fi without Tailscale; add Tailscale for private control away from home. See
66+
the [beginner installation guide](docs/IOS_INSTALL.md) and the
67+
[local Wi-Fi test](docs/IOS_LOCAL_WIFI.md).
68+
5669
In Windows + Mac mode, choose the same agent-source mode in both Codex apps when you want both native Pinned lists or both sets of Individual assignments to contribute. Pinned tasks are interleaved fairly. For Individual assignments, the Stream Deck computer wins when both apps assign different tasks to one button, while the other computer fills empty slots. Mirrored copies of the same task are shown only once. See [Multi-host behavior](docs/MULTI_HOST.md#agent-source-modes).
5770

5871
## Recommended 15-key layout
@@ -81,6 +94,16 @@ The action names describe the default Codex Micro setup. The keys always follow
8194

8295
The page-navigation and profile-switch keys are built-in Stream Deck actions. All other named controls come from Codex Deck. Every official Codex Micro keycap is also exposed as a standalone action, so extra pages can be customized without changing the six synchronized Micro action slots.
8396

97+
### Usage and reset controls
98+
99+
![Usage limit, overview, and reset-credit controls](docs/assets/usage-controls-preview.svg)
100+
101+
Add **Usage Limit** for the existing circular capacity display. Its Stream Deck property inspector can pin the key to **5 hours** or **Weekly**, while **Automatic** prefers 5 hours and falls back to weekly whenever Codex temporarily omits the shorter window. **Usage Overview** shows both windows as separate horizontal bars; a missing window stays visible as unavailable instead of being mistaken for zero capacity.
102+
103+
**Rate Limit Reset** shows the number of credits Codex currently reports. The count remains centered inside the reset arrow and the action is dimmed only when no credit is available. Consuming a credit requires holding the key for 1.2 seconds; a short tap does nothing, and Codex's current applicability check still has to pass. This action uses Codex's current native usage client and is therefore subject to the same undocumented compatibility boundary as the Micro bridge.
104+
105+
Usage and reset credits are account-scoped. In Windows + Mac mode these three keys therefore do not follow the Windows/Mac function-key target: they prefer the healthy local account snapshot and fall back to the paired host only when local usage data is unavailable.
106+
84107
## Official keycap SVGs are not included
85108

86109
The public source and release intentionally exclude OpenAI's Codex Micro keycap SVG files. The original agent tiles, status marks, glow system, animations, fallback labels, and plugin artwork are included.
@@ -117,7 +140,7 @@ No virtual HID driver is installed and no Codex application file is patched. See
117140
- The Codex debug endpoint remains loopback-only and is never the multi-host relay endpoint.
118141
- CDP is privileged: another untrusted process running as the same local user could try to access it.
119142
- Codex Deck has no telemetry, cloud service, or update service.
120-
- Single-host mode reads no rollout data. Multi-host mode reads only exact local rollout **filenames**, never their contents, to distinguish a task's owning desktop from a cloud/SSH mirror.
143+
- Codex Deck reads exact local rollout filenames for ownership and a bounded recent tail for structural status tags plus numeric `token_count` fields. It does not parse or relay prompts, responses, project names, or other conversation content.
121144
- Optional SVGs stay in the user-local icons directory and are never uploaded.
122145
- Multi-host mode accepts only authenticated, typed Codex Deck commands over SSH or Tailscale; wildcard and arbitrary public-IP listeners are rejected.
123146
- Private relay tokens, local host state, logs, and personal paths are excluded by the release audit.
@@ -128,11 +151,12 @@ Do not use the launcher while running untrusted local software. See [SECURITY.md
128151

129152
The current build was locally validated against:
130153

131-
- Codex for Windows `26.715.4045.0`
132-
- Codex for macOS `26.715.31925`
154+
- Codex for Windows `26.715.8383.0`
155+
- Codex for macOS `26.715.70719` (`5650`)
133156
- Stream Deck `7.4.2.22730`
134157
- Windows `10.0.26220.0`
135158
- Node.js `24.13.0`
159+
- iPhone `iOS 27.0` (physical-device build and tests)
136160
- Standard 15-key Stream Deck MK.2
137161

138162
The Windows physical-device path and the Windows+Mac relay were exercised on the real setup. The macOS launcher, watcher, native bridge, and plugin package are validated; a Stream Deck physically attached to the Mac has not yet been hardware-tested. These are tested versions, not strict maximums.
@@ -156,6 +180,14 @@ npm run audit:release
156180

157181
Nothing is published automatically. See [CONTRIBUTING.md](CONTRIBUTING.md).
158182

183+
## Acknowledgements
184+
185+
The idea to explore a phone-native Codex Micro companion was inspired in part
186+
by the public mobile concept shared by [Shikhar (@xikhar)](https://x.com/xikhar).
187+
Codex Deck Mobile is an independent implementation built on this project's own
188+
authenticated bridge, native controls, and visual system; no source code or
189+
artwork from that concept is included.
190+
159191
## License and trademarks
160192

161193
Code and original artwork are licensed under [MIT](LICENSE). OpenAI, Codex, ChatGPT, Elgato, Stream Deck, and their marks/assets belong to their respective owners; third-party and user-supplied assets are not relicensed.

docs/ARCHITECTURE.md

Lines changed: 39 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -53,10 +53,15 @@ The same plugin runs on Windows and macOS. It discovers the local loopback port
5353
3. read the native six-slot state, layout, agent source, and lighting preference;
5454
4. dispatch Micro HID and joystick events;
5555
5. emulate native encoder-rotation HID events for reasoning-effort changes;
56-
6. resolve standalone keycap actions from Codex's live Micro keycap registry and current official command runner.
56+
6. resolve standalone keycap actions from Codex's live Micro keycap registry and current official command runner;
57+
7. read Codex's renderer-owned `rate-limit-status` query and normalize its current 5-hour, weekly, and reset-credit state.
5758

5859
The bridge does not emulate a USB HID device and installs no driver.
5960

61+
Usage data remains part of the same typed host snapshot, but usage and reset credits are account-scoped and therefore do not follow the Mac/Windows function-key target. The controller prefers a healthy local account snapshot and falls back to the paired host only when local usage is unavailable. Window identity is derived from the duration returned by Codex rather than from primary/secondary ordering. A missing 5-hour window is represented as unavailable, and Automatic mode falls back to weekly. The bridge refreshes a stale renderer-owned usage query at most once every 15 seconds, so background-window values do not depend on Codex receiving focus.
62+
63+
Reset consumption is the only mutating usage operation. It is a narrow typed relay command and calls Codex's current native reset-credit client only after the Stream Deck key has been held for 1.2 seconds. The bridge verifies both availability and applicability, selects an available plan-supported credit, uses a unique redemption request ID, and then refreshes the renderer query. No credential, raw endpoint access, or arbitrary request surface is exposed to the relay.
64+
6065
### Optional multi-host relay
6166

6267
The Mac watcher can host an authenticated WebSocket relay on loopback behind an
@@ -68,15 +73,39 @@ target the host selected by the Windows/Mac toggle.
6873
Host ownership is resolved from exact local rollout filenames, not from a
6974
renderer's mirrored recent list. This distinguishes a task's owning desktop
7075
from a stale cloud or remote-SSH mirror. A bounded rollout tail is searched only
71-
for structural activity/completion event tags; prompts, responses, project
72-
names, and other content are neither parsed nor relayed. The relay never reads
73-
or proxies the remote CLI app-server stream.
76+
for structural activity/completion event tags and the latest numeric
77+
`token_count` record. The latter provides optional context-window percentage
78+
metadata for the small agent-key ring. Prompts, responses, project names, and
79+
other content are neither parsed nor relayed. The relay never reads or proxies
80+
the remote CLI app-server stream.
7481

7582
The relay protocol has no arbitrary-evaluation, filesystem, shell, or raw-CDP
7683
operation. Payloads are capped at 64 KiB, authentication is required before a
7784
snapshot or command is accepted, and command results use request IDs with
7885
bounded timeouts.
7986

87+
### Optional iPhone transports
88+
89+
The iPhone consumes the same authenticated protocol through two independent
90+
transport profiles. Remote mode keeps the relay on loopback and uses private
91+
Tailscale Serve TLS. Nearby mode binds only the typed relay to one discovered
92+
RFC 1918 address; Chrome DevTools remains on `127.0.0.1`. Nearby creates a
93+
per-host P-256 certificate and random token, pins the certificate fingerprint
94+
in the iPhone profile, and stores the token in Keychain.
95+
96+
Bonjour `_codexdeck._tcp` announces protocol version, stable `hostId`, display
97+
name, platform, private address, relay port, and certificate fingerprint. It
98+
never announces the token. The QR deep link carries the initial private
99+
endpoint, token, and fingerprint. Later Bonjour address changes are accepted
100+
only for the already-paired `hostId` with the same pinned fingerprint. Config
101+
and QR files are written atomically with user-only permissions and are excluded
102+
by the release-state audit.
103+
104+
The nearby and Tailscale listeners are separate, so enabling local discovery
105+
does not replace or weaken remote access. No public relay is bundled: a
106+
reliable internet alternative would require operated identity, TURN/push, rate
107+
limiting, and abuse controls rather than exposing a desktop listener.
108+
80109
An authenticated client may remain connected while the Mac app or its native
81110
Micro signals are unavailable. Snapshot failures are caught and rate-limited;
82111
they do not terminate the relay server or watcher. Normal snapshots resume
@@ -104,6 +133,12 @@ Agent keys are original deterministic SVGs generated in memory from task title a
104133
| `approval` | orange pause/input |
105134
| `error` | red error |
106135

136+
When Codex exposes token usage for a task, an optional top-left ring shows the
137+
latest context-window percentage. Orange begins at 80% and red at 92%. Select
138+
any Agent key in Stream Deck's property inspector to show or hide this ring
139+
globally for all six agent keys on that computer. The setting is independent on
140+
Windows and macOS and does not stop context metadata from syncing.
141+
107142
The renderer derives the active Codex appearance from explicit theme tokens when available and falls back to the computed renderer surface luminance. Dark mode uses layered charcoal surfaces rather than pure black, with off-white text and slightly lifted status colors for the Stream Deck display.
108143

109144
Official Codex Micro keycap SVG contents are not part of the source or release. Optional user-local files are loaded from `%LOCALAPPDATA%\CodexDeck\icons` on Windows or `~/Library/Application Support/CodexDeck/icons` on macOS and wrapped in the project's neutral key surface at runtime.

0 commit comments

Comments
 (0)