For headless, remote & agentic machines
When your machine needs a browser, Handback hands it to you.
An OAuth login, a “click to authorize,” a localhost callback — triggered on a box you can't see, opened on the Mac, iPhone, or iPad in your hand. Even the loopback callback tunnels back, so headless logins actually finish.
One purchase for Mac, iPhone & iPad. The sender is free.
$ gh auth login
✓ Logging in… opening browser:
https://github.com/login/device
[handback] opened on Jere's MacBook ✓ https://github.com/login/device
from gh auth login
“A browser just opened on a machine I can't see.”
Agentic boxes and remote dev servers constantly try to open URLs in a browser nobody's
looking at — and worse, OAuth flows redirect to localhost on that box, so the login hangs forever. Handback fixes both.
How it works
Install the sender
A tiny free daemon on your agentic machine (macOS or Linux) catches every browser link.
Pair it
Run handback pair — scan the QR or paste the URI into the app. One time.
Get your links back
Links open on the Mac in front of you. OAuth callbacks tunnel home automatically.
Sender (free, on the box) → receiver (the app, on your devices). Peer-to-peer, no relay.
More than an opener
A private, local-first dashboard of every link your machines hand back.
Every machine, one place
Connect all your agentic boxes. Each one's links land in its own history — searchable, never lost, stored on your device.
Opening is optional
Capture and notify by default; flip on auto-open per machine. Every link is logged whether or not a browser ever opens.
Loopback callbacks that finish
OAuth CLIs redirect to localhost on the box — unreachable from your laptop. Handback tunnels the callback back, so headless logins actually complete.
No cloud in the middle
Your machines talk directly — LAN, a reverse proxy, or Tailscale. No relay we run, no account, nothing to leak. That's why it's a one-time price.
Mac, iPhone & iPad
One purchase, every device. Glance from the menu bar, or pick up where you left off on your phone.
The sender is free
The daemon on your agentic box is free and open. Install it with Homebrew, pair once, done.
Up and running in a minute
# install the free sender
brew install jereco/tap/handback
# capture browser links + pair with your devices
handback install --default-browser
handback pair --host your-box:8765 --qr
# keep it running
brew services start handback Then scan the QR in the app. Full guide in the docs.
One price. Every device.
- Mac, iPhone & iPad (universal)
- Unlimited machines & link history
- Loopback OAuth callback tunnel
- Free updates · free open-source sender
Launching soon — early-access seats are free until 1.0.
Questions, answered
Do my machines need to be on the same network?
No. The app dials out to each box, so your laptop can roam. Put both on a Tailscale tailnet (recommended), point the app at a TLS reverse proxy in front of the box, or stay on your LAN.
Why do headless OAuth logins hang without Handback?
CLI logins redirect the browser to localhost on the box (RFC 8252). If the browser is on your laptop, that localhost is the wrong machine — the code never arrives. Handback binds the port on your device and tunnels the callback back to the box, so the login just finishes.
Where does my link history live?
On your devices. There's no Handback server and no account — links (which can carry auth codes) never touch infrastructure you don't own.
What if no receiver is connected when a link fires?
The sender prints the URL right back into the terminal on the box, so it's never lost. Auto-opening locally is an opt-in for non-headless machines.
What runs on the agentic box?
A free, open single-binary daemon for macOS and Linux. It captures links via $BROWSER, xdg-open on Linux, or a default-browser helper on macOS — so tools like gh, gcloud, and agents that call open are all caught.
Why one-time pricing?
Because there's nothing for us to keep running. Your machines talk peer-to-peer; no relay, no sync service, no monthly bill to pass on.