Remote development console for enterprise developersOn-premises installDesktop · Phone

Your developers' Claude Code,
anywhere, via your company server.

SSemBridge is a remote development console for Claude Code, built for enterprise developers. Once your company hosts the relay server on its own infrastructure, developers can view and control the Claude Code sessions they run in tmux on their own Macs from a desktop browser or a phone, through that server — sending prompts, approving permissions, answering questions, and interrupting.

On-premises install · each Mac runs macOS + tmux · verified with Claude Code 2.1.x · desktop browsers and phones (home screen app)

SSemBridgeconnected Needs response 2Tasks 1UsageManageSettingsNew session
Sessions4 sessions · 2 hosts
api-serverRunning
Mac Studio · Claude 1 · sonnet-5-5
Converting payment amounts to minor units
✻ Refactoring… 1:12
todo-appWaiting for approval
MacBook · Claude 1 · opus-5-5
Now I'll run the tests.
docs-siteWaiting for input
MacBook · Claude 2 · haiku-4-5
Updated three pages of the install guide.
ml-notebookRunning
Mac Studio · Ollama · qwen3-coder
Checking the data cleanup script
2 subagents running · 3 total
api-server Running
Mac Studio · Claude 1 · sonnet-5-5 · ~/work/api-server · main
■ StopFilessonnet-5-5 · highPermissions: Auto⋯
Convert payment amounts to each currency's minor unit, and make sure the same order can't be charged twice
I'll add an amount conversion function and pass an idempotency key to the payment call.
Editedsrc/payments/charge.ts +2 −1
31 export async function charge(order: Order) {32- const res = await gateway.pay(order.total);32+ const amount = toMinorUnits(order.total, order.currency);33+ const res = await gateway.pay(amount, { key: order.id });34 if (!res.ok) throw new PaymentError(res.code);
Bashnpm test -- payments
PASS src/payments/charge.test.ts ✓ sends KRW without decimals (3 ms) ✓ does not charge the same order twice (5 ms)+14 more lines
All 18 tests passed. I'll update refunds the same way.
✻ Refactoring… 1:12 · ↓ 2.8k tokensStop (Esc)
Model·effort/compact/clear/cost/status
Message to api-server
⌘↵ to send · drag and drop files or paste with ⌘V

Waiting for approval 1

todo-app · Permission request · Bash
npm test -- login
AllowDeny

Agent hosts

MacBook2 sessions · 12ms
Mac Studio2 sessions · 18ms

Hook events

14:02PermissionRequest · todo-app
14:01PostToolUse · api-server
13:58Stop · docs-site
13:57SubagentStop · ml-notebook
todo-appWaiting for approval
MacBook · opus-5-5 · xhigh · Permissions: Default
Add a show-password button to the login screen and run the tests
Added the button. Now I'll run the tests.
Editedsrc/Login.tsx +9 −1
41 <input type={show ? "text" : "password"} />42 + <button onClick={toggle}>Show</button>
Permission request · Bash
npm test -- login
AllowAlways allow this commandDeny
Brewing… 42s · ↓ 1.2k tokens
Message to todo-app
SessionAlertsTasksUsageManage

DesktopSession list, conversation, and approvals side by side in three wide columns

PhoneThe same sessions in one hand — approve, answer, interrupt

Runs on your company server

SSemBridge is installed on a server your company operates. Developers keep using Claude Code on their own Macs as usual, and carry on with those sessions away from their desks through the company server.

Relayed by your company server

The web console, the relay, the display copy of conversations, and conversation backups all live on one company server. Remote control never goes through an outside cloud service.

Account secrets stay on each Mac

Claude credentials and Ollama keys are kept only on the developer's Mac. Even when logging in from the web, the server only relays the process and never stores the secrets.

Macs make outbound connections only

The Agent on each Mac connects out to the company server. No ports need to be opened on the Mac, and Agent connections are accepted only from the internal network (VPN).

Every remote command is audited

Who, which session, what, and the result are all recorded. The web console opens only after an ID, password, and OTP.

Admin screens

Admins handle everything on the web: registering and removing hosts (developer Macs), each Mac's account login status, available models and defaults, usage, server settings, and retention periods.

Conversation backup · Restore

Conversation history on each Mac is backed up to the company server every 10 minutes. When an admin finds and restores a backed-up conversation, it can be opened with “Resume” in a new session.

Claude Code's communication with the model (the Anthropic API and others) still happens directly from each Mac, independent of the console.

At a glance

Answer Claude's questions, check how much you've used, and hand work off to another Mac — without sitting at the terminal. The screens below are drawn with made-up sample data.

Claude is asking
Deploy scope
How far should I go?
Up to the dev server (Recommended)Production after a rehearsal
Through productionDuring tonight's maintenance window
Type your own — answers with this text instead of the options
Send answerDon't answer
Answer questions on the spotClaude's questions appear as cards. Single choice, multiple choice, or your own text — answers are passed back in the same form as in the terminal.
Estimated cost
$412
▲ 18%
Cache hit rate
96%
▼ 0.8%p
5 hours23%
Weekly71%
⚠ At the current pace, you'll hit the weekly limit on Friday at 14:00
Usage and limit forecastsSee account limits (5-hour and weekly) with a forecast at the current pace, and cost estimates at API rates — by model, project, and time of day.
api-server → Mac StudioMoving
Export conversation2.1 MB
Pack working folder38 MB
Upload to server62%
Extract on destination Mac
Resume
Move to another MacHand a conversation (and, if you like, its working folder) to another Mac and keep going. The move continues even if you close the web page, and the progress is shown when you come back.
MacBook · ShellEscTab^CPgUpClose window
dev@macbook:~/work/api-server$ git status -s M src/payments/charge.ts ?? src/payments/refund.ts dev@macbook:~/work/api-server$ npm test -- payments Tests: 18 passed, 18 total dev@macbook:~/work/api-server$
Web terminalOpen a developer Mac's shell, or the actual tmux screen of a claude session, in a new window. It opens only when enabled locally on that Mac, and asks for an OTP once more when opening.
Promptsapi-server · 24 · newest first
#24 · 14:02↳
Update refunds the same way and run the tests
#23 · 13:41↳
Convert payment amounts to each currency's minor unit, and make sure the same order can't be charged twice
#22 · 11:20 · 1 image↳
Clean up the error messages to look like this screen
Prompt listSee just your own instructions, otherwise buried among everything the AI did. Click ↳ to jump to that spot in the conversation and read on from there.
SSemBridge
한국어English日本語简体中文FrançaisEspañolBahasa IndonesiaTiếng Việtភាសាខ្មែរالعربية
10 languagesUse the web console in your team's language. The browser remembers your choice, and numbers and dates follow that language too. Arabic reads right to left.

Wide on desktop, one-handed on phone

The same console works on any screen. In a desktop browser, the session list, conversation, and alerts sit side by side in three columns, with plenty of room for the file editor and usage dashboard; on a phone, the bottom tabs switch between Session, Alerts, Tasks, Usage, and Manage. The screens below are also drawn with made-up sample data.

Three wide columns, collapsible when needed

The session list on the left, the conversation in the middle, and approvals and hosts on the right — all on one screen. Collapse the side columns and sessions shrink to a summary rail (status, elapsed time, approval count), alerts to an icon rail, and the conversation gets wider.

  • Edited files as line-numbered diffs, long output collapsed
  • This browser remembers what you collapsed
  • ⌘↵ to send, drag and drop files

Swipe sideways to see more

File explorer and editor

Browse the session folder as a tree and edit two files side by side. Unlock, edit, and save with ⌘S; files Claude changes are reloaded right away.

  • Markdown preview · image viewer
  • Rename · duplicate · delete to Trash (no permanent deletion)
  • Nothing inside .git or .claude can be edited

Swipe sideways to see more

Usage dashboard

See account limits with a forecast at the current pace, and compare estimated cost, requests, output, and cache hit rate against the previous period. Daily per-model bars and a day × hour heatmap show when and where usage went.

  • Periods: today · 7 days · 30 days · 90 days · this month
  • Spike days are marked with ▲
  • Costs are estimates at API rates

Swipe sideways to see more

What you can do

Do on the web exactly what you did in the terminal. The source of truth is always the conversation files on each Mac; the server keeps a copy for display.

Live conversation view

Watch the conversation, tool calls, results, and subagents live, in the same order as the terminal. Edited files appear as line-numbered diffs, long output is collapsed, and Markdown, mermaid diagrams, and images are rendered. Each session also shows the account (Claude or Ollama) it actually uses.

Permission approvals · Answering questions

When Claude asks for permission to run a command or asks a question, a card appears on the web and on your phone. The same prompt stays open in the terminal, and whichever answer comes first wins. Confirmation dialogs that appear only in the terminal (for example, the background work check on exit) can also be answered from the web.

Prompts · Files · Interrupt

Send long text as is. Drag files onto the input box or paste them, and they are uploaded to the session folder and inserted as @path. Watch the progress line and interrupt just like pressing Esc.

New session · Resume

Start new sessions in tmux inside allowed folders, and resume finished conversations. Conversations from folders you only used in the terminal also appear in the resume list (just like claude --continue), and resuming under a different account copies the conversation file to that account.

Model · effort · Permission mode

Change the model and effort mid-session (by default for this session only), and switch among the five permission modes (Default, Accept edits, Plan, Auto, Bypass permissions).

Move session

Move a finished session to another Mac and continue there. The working folder can come along too (excluding folders that can be regenerated), and a progress bar shows each step.

File explorer · Editor

Browse, preview, and edit the session folder. Files Claude changes are reflected right away, and deleting only ever moves files to the Trash. Open it in a new window to view files while following the conversation.

Web terminal

Open a developer Mac's shell, or the actual tmux screen of a claude session, on the web. Scroll, drag to select and copy, and clear with ⌘K just like a terminal; the number of scrollback lines is set in Settings. It opens only when enabled locally on that Mac.

Prompt list

See only the prompts people typed in that session, newest first. Click one to jump to that spot in the conversation and review from there — even in older history (within the server's retention period).

Tasks — background agents

See the background agents and workflows running right now across all sessions on one screen, along with those that finished in the last 24 hours.

Usage dashboard

See account limits with a forecast at the current pace, cost estimates, daily per-model bars, the heaviest sessions, and a day × hour heatmap. Costs are estimates at API rates.

Remote host and account management

Connect a developer Mac with the one-line install command that “Add host” generates. See the Claude and Ollama account login status for each Mac and log in from the web; update the Agent remotely with “Update now”.

Conversation backup · Restore

Conversation history and copies of files from before Claude edited them are uploaded to the company server every 10 minutes. See the archive size, free disk space, and backup status per host, and restore what you choose.

Audit log · Retention cleanup · Metrics

Every remote command is recorded: who, which session, what, and the result. Old records are cleaned up according to the retention periods you set, and sensitive values such as tokens are masked. Metrics such as connection latency per host are shown too.

10 languages

Use the web console in Korean, English, Japanese, Simplified Chinese, French, Spanish, Indonesian, Vietnamese, Khmer, or Arabic. Pick one with the 🌐 button at the top; Arabic is displayed right to left.

How you'll use it

Connect your developers' Macs to a single company server. Developers simply keep using claude inside tmux, as they always have.

Install on your company server

Host the relay server (web application server · database) on-premises. The web console sits behind your company's HTTPS proxy, and Agent connections are opened only inside the internal network.

Connect developer Macs

An admin creates a one-line install command with “Add host” (single-use enrollment code, valid for 15 minutes). Paste it into the Mac's terminal, and the Agent is installed and connected.

Carry on from anywhere

claude sessions launched in tmux show up on the web. Follow the progress from desktop or phone, and approve, answer, give the next instruction, or interrupt.

How it works

The Agent on each Mac reads claude's conversation files and hooks, sends them to the company server, and types commands from the web into tmux. Because the Agent connects out to the server, no ports need to be opened on the Mac.

SSemBridge architecture On each Mac at the left, claude writes conversation files and sends hooks to the Agent; the Agent reads the conversation files and opens a WebSocket to the company server in the middle. The company server consists of a web application server and a database, and browsers and phones on the right connect to it over HTTPS and WebSocket. Each Mac (many) claude Claude Code in a tmux window Conversation JSONL · original SSemBridge Agent Single Go binary · launchd write read hook Company server Web Application Server SSemiYa F/W Relay · login · audit Database UI cache · settings Web Browser Desktop Phone Home screen WebSocket · Agent connects out HTTPS·WS Installed on-premises Login + OTP required
Swipe sideways to see more
  • The source of truth is the conversation files on each Mac. The server only keeps a copy for display, so even after a server restart, the Agent resends from where it left off and fills it back in.
  • One-way connection from Agent → server — the server never connects into the Mac. Commands arrive over the same connection and are typed into tmux.
  • Hooks are received on 127.0.0.1 only. Even if the Agent is down, claude is not slowed down (it gives up within 1 second).
  • The web console sits behind your company's HTTPS proxy and opens only after login + OTP; every remote command is recorded in the audit log.
Agent

Single Go binary

Runs on each Mac under launchd. Tails conversation files · receives hooks · controls tmux · updates remotely.

Server

SSemiYa F/W
Web Application Server

WebSocket relay, REST, audit log, conversation backup storage. Installed on-premises.

Web

Vanilla JS modules

No build tools, no external resources. Desktop and phone, light and dark themes.

DB

Database

Display copy of conversations, account and model catalog, usage, audit log.

Security principles

Because this tool runs commands remotely on developers' Macs, we drew the lines it must never cross before building it.

  • All relaying and storage for remote control happen on the company server — never through an outside cloud service.
  • Macs only open outbound connections to the company server — there are no inbound ports.
  • Account secrets (Claude tokens, Ollama keys) stay only on each Mac. The server never stores them.
  • Host enrollment codes and tokens are stored only as hashes, and an enrollment code can be used once, within 15 minutes.
  • Agent connections are not exposed through the external proxy and are accepted only from the internal network (VPN).
  • The web console always requires an ID, password, and OTP, and administrative tasks (hosts, accounts, settings, restoring backups) are for admins only.
  • New sessions open only inside allowed folders, and the Agent performs the final check on file paths (anything outside the session folder, .git, or .claude is rejected).
  • Every remote command is recorded in the audit log (who, which session, what, and the result).
  • The web terminal opens only when enabled locally on that Mac (it cannot be enabled from the web), and asks the admin for an OTP again each time it is opened. Opening, closing, and byte counts are recorded in the audit log, but keystrokes are not, and it closes after 30 minutes without input.
  • Token-like values are masked wherever they appear on screen or in records.
  • The web console loads no external scripts or fonts (CSP), and uploads have their size and path checked twice.

Requirements

What SSemBridge needs to run.

  • Each Mac needs macOS and tmux. Sessions launched outside tmux (in a regular terminal) are view-only; reopen them with “Resume in tmux” on the web to control them.
  • The company server needs a web application server (WAS) and a database. The web console goes behind your company's HTTPS proxy, and Agent connections are opened only inside the internal network (VPN).
  • Claude Code and Ollama accounts are the ones already in use on each Mac. Accounts and billing remain subject to your existing agreements with each service.
  • Claude Code's log format, hooks, and screens change from version to version. The Agent is updated to match verified versions (currently 2.1.288–2.1.291), and updates are pushed to each Mac with “Update now” on the web.
  • Usage costs are estimates at API rates. They are not subscription fees or actual billed amounts.

Considering SSemBridge for your team?

Tell us how many developers you have and about your Mac and server environment, and we will recommend the right setup. Contact us for pricing and terms as well.

Contact sales

halo@levelupsoft.com

On-premises installation by default · Levelupsoft Inc.