Agents
Coding agents, run by the system.
Claude Code, Codex, OpenCode, Gemini and Kimi run on Rime as sessions the operating system keeps track of. Each one starts in a sandbox, none of them can become root, and the ones waiting for you are always at the top of the list.




A session, not a stray terminal
Type a in any terminal and Rime starts your agent in a terminal it owns. The agent itself is unchanged: the real claude or codex, in a real terminal. The difference is that Rime now knows it is there. It can tell you what the agent is doing, keep it running when the terminal window closes, and let you attach from another terminal, or from your phone.
Rime only tracks sessions it starts. Typing codex on its own still works exactly as it always did.
a "fix the failing tests"astarts one,allists them,aareattaches,adshows what it changed. Ctrl + ] detaches without stopping it.- Six adapters: Claude Code, Codex, OpenCode, Gemini CLI, Kimi CLI, and any other terminal program.
rime agent default codexpicks the onearuns. - Every session has a state: starting, working, waiting for you, needs permission, complete, failed or exited. Claude reports its own through hooks; the others are read from the terminal.
What needs you comes first
The Agents tab of the Dashboard is the Agent Center. A privilege request waiting for your decision sits at the top, then every session that is waiting for you or needs a permission, then the rest, most recently active first. Each row says which project and worktree the agent is in, how long it has been running, what it started, and, for Claude, the model, how much context is used, and how much of your five-hour and seven-day allowance is left.
- A notification when an agent is waiting for you, needs a permission decision, finishes or fails, with Focus terminal and View output.
- Pause, resume and stop from the row; the terminal opens where the session really is.
- Rime Search finds sessions by agent, project or state: Attach to claude · rime-os.
A sandbox by default
Every session starts in a bubblewrap sandbox. The system is read-only, and your home directory is empty except for the project the agent was started in. Nothing else is there to read or to break. Your SSH keys, other projects, the camera and sound devices and every other process are outside it.
The environment is cleared too; only the variables the agent itself needs, such as its own API key, come through. If the sandbox cannot be built, the session does not start.
- Network is open by default, because most agents talk to their provider's API.
--network allowlist,brokeredandofflinenarrow it. An allowlist decides where traffic may go; it does not stop a leak to an allowed host. --sandbox unrestrictedexists, is drawn in red wherever the session appears, and confines nothing.
Never root. You decide, at the machine.
Inside a session sudo does not work: no process in it can gain privileges. When an agent needs something from the system, it asks, in a closed vocabulary of eight requests (install, remove, upgrade, rebuild or roll back packages, pin, roll back the system, update). There is no request that runs a command. The agent waits, the request appears at the top of the Agent Center, and you approve it with your own password.
rime request ask install clang --reason "Needed to build the tests"sudo rime request approve 3- A session cannot approve its own request, and nothing on a phone can approve any.
- Longer trust is time-limited:
--system-access sessionlasts 30 minutes by default and 8 hours at most, and the password prompt appears on your desktop, never inside the agent's terminal. - Locking the screen revokes root grants. Agents keep working.
Credentials an agent can use, but never read
An agent that deploys a site or pushes a branch needs a credential. On Rime it never gets one. The credential lives in rime-secretd, a root service, which does the operation itself and hands back only the result. It has no way to return a credential at all, so there is nothing for the agent to leak.
rime secret grant cloudflare cloudflare.wrangler.deploy- Git push and fetch, Cloudflare (DNS, Workers, R2, D1, KV, deploys), S3, WebDAV, Google Drive, Microsoft Graph and MCP servers.
- Granted per project and per operation. A production deploy can require a one-time approval.
- For Cloudflare, each operation runs on a short-lived token scoped to that one operation.
Parallel work you can take back
Give each agent its own git worktree and several can work on one project at once without touching each other. Rime tells you, per worktree, whether it has changes, whether it would merge cleanly, what happened to the tests it saw run, and whether it is ready to hand over. A checkpoint captures the project before the agent starts, so rime agent undo can put it back. When one agent gets stuck, a handoff writes down where it got to and starts another on it.
rime agent run "fix issue 217" --worktree issue-217 --checkpointWORKTREE BRANCH DIFF CONFLICTS TESTS READY
issue-217 agent/issue-217 4f +81/-12 clean passed yes
issue-221 agent/issue-221 2f +19/-3 1 file(s) failed would conflictrime agent handoff 4 --to codexClose the lid. The work carries on.
While a session is running, closing a laptop's lid keeps it awake with the screen, keyboard light and Bluetooth off, and Wi-Fi power saving off so a VPN holds. If it gets too hot, or the battery reaches 20 %, Rime checkpoints the sessions and suspends anyway. With nothing running, the lid sleeps the laptop as it always did.
rime lid statusClosing the lid: what counts as live work, the guards, and rime lid report.
On the machine next door, too
Rime reaches your other machines over your own SSH configuration. Run a build on the desktop from the laptop, or start, list and attach to agent sessions on another Rime machine as if they were local. The Agent Center lists them under Remote devices.
rime host run katana -- make -j20rime agent list --host katanaRime Remote, on your phone
Rime Remote is the Android app for your agents. It lists every session on each paired computer, needs-you first. You can watch a session's live terminal and reply when it is waiting, from the keyboard, by voice, or with a photo or file dropped into its inbox. You can also pause, resume, interrupt or stop it, and start a new one in any project, with its own worktree. Nothing runs on the phone: an agent started from it runs on the computer and keeps going when you put the phone away. By default it pauses while the computer's screen is locked; rime agent lock --remote continue keeps it running.
It cannot approve anything that needs root. By design, and with no setting to change that: the phone shows what is waiting at the machine, and can revoke permissions already given.
- Pairing: Settings › Devices › Pair a device shows a code on the computer. It works once, for three minutes, and pins that computer's key on the phone. The phone makes a new key for each computer and keeps it in Android's keystore behind your fingerprint or screen lock.
- On the phone: the list of paired computers and their keys, and nothing else. No transcripts, no scrollback, no history, no backup.
- The connection: end-to-end encrypted (Noise, X25519 and ChaCha20-Poly1305), direct on your network when it can, otherwise through a relay.
- Notifications come through UnifiedPush (ntfy, for instance), with no Google services. Each carries a few encrypted numbers; the text is written on the phone.
Rime Remote 0.1.0 for Android
Published 29 September 2026 · Android 9 or later · 35.1 MB · build 1831
Download the APK Install and pair Release notes
- SHA-256
- de4c53e09d1cb1e1ea7aac3115acf465bf2b62ed857aa03b0d1ba82a5959626d
- Signed by
- 9b2418f3cd37ba2ae83cdaeec5068280e02dc64135fdb1bb9fcb247326a66c67
apksigner verify --print-certs rime-remote-0.1.0+1831.gdf44d939.apkThe certificate's SHA-256 digest must match "Signed by". Android will only ever update the app from an APK signed by the same key, and the app checks Rime's releases for updates itself.
What agents on Rime don't get
- Root. Not by asking, not from a phone. A person approves each privileged operation, at the machine.
- Your credentials. They can use the ones you grant through the broker; they can never read them.
- Your home directory. Only the project they were started in.
- A guarantee against a kernel exploit. The sandbox is for mistakes, and Rime says so.