Handback

For headless, remote & agentic machines

When your machine
needs a browser,
Handback hands
it to you.

An OAuth login, a “click to authorize,” a localhost callback — triggered on a box you can't see, opened on the Mac, iPhone, or iPad in your hand. Or run the engine right in the Mac app.

One purchase for Mac, iPhone & iPad. The Engine is free.

✓ logged in on agent-box

“A browser just opened on a machine I can't see.”

Agentic boxes and remote dev servers constantly try to open URLs in a browser nobody's looking at — and worse, OAuth flows redirect to localhost on that box, so the login hangs forever. Handback fixes both.

  1. 01

    It starts on a box you can't see

    codex login on a box — or on a Mac in Engine mode — wants a browser, and waits for the sign-in to call back to localhost:1455.

  2. 02

    The link lands on your phone

    Or on your Mac or iPad: the Engine hands it to the app on your devices, and it's logged in that machine's history.

  3. 03

    You sign in, in the app

    The sign-in page opens right there — in an in-app sheet on the iPhone, in your browser on the Mac.

  4. 04

    The callback goes home

    The app catches the localhost redirect and tunnels it back to the box. The terminal carries on.

Peer to peer

Nothing in the middle.

The Engine on the box catches the link and hands it to the app on your device. When a CLI's sign-in redirects to localhost on the box, the app binds that port on your device and tunnels the callback back — so headless logins actually complete.

How Handback connects Inside your network, the free Handback Engine on the box hands the link over the tailnet, LAN or a secure WebSocket to the Handback app on your Mac, iPhone or iPad, with no relay in between. When the sign-in redirects to localhost, the app binds that port on the device and tunnels the callback back to the box's localhost. YOUR NETWORK agent-box the box you can't see handback engine codex waits on :1455 Mac · iPhone · iPad your devices Handback app binds localhost:1455 01 the link tailnet · LAN · wss no relay in between 02 the OAuth callback, tunneled back from the device's loopback How Handback connects Inside your network, the free Handback Engine on the box hands the link to the Handback app on your devices with no relay in between, and the app tunnels the OAuth callback from the device's localhost back to the box. YOUR NETWORK agent-box the box you can't see handback engine codex waits on :1455 Mac · iPhone · iPad your devices Handback app binds localhost:1455 01 the link tailnet · LAN · wss no relay in between 02 the callback
No relay
Your machines talk directly. There's no relay we run — nothing in the middle to leak, and no monthly bill to pass on. That's why it's a one-time price.
No account
No Handback server, no sign-up. Your link history — links can carry auth codes — stays on your devices, and the Engine's controls answer only on its own machine.
Your network
A Tailscale tailnet (recommended) or a trusted LAN over plain ws://, or wss:// through a TLS proxy in front of the box. The app dials out, so your laptop can roam.

More than an opener

A private, local-first dashboard of every link your machines hand back.

Every machine, one place

Connect all your agentic boxes. Each one's links land in its own history — searchable, stored on your device. Auto-open per machine, or just capture and notify.

Engine mode on the Mac

Agents on a Mac? The app runs the engine itself and can become the default browser: links opened by terminals and agents are handed back, your own clicks open locally.

Loopback callbacks that finish

OAuth CLIs redirect to localhost on the box — unreachable from your laptop. Handback tunnels the callback back, so headless logins actually complete.

Up and running in a minute

The Engine runs where your agents do. On a Linux or headless box it's a free Homebrew install; on a Mac it's built into the app. Pair once, done.

  1. 01

    Start an engine

    On a Linux or headless box, install the free Engine. On a Mac, turn on Engine mode in the Handback app.

  2. 02

    Pair it

    Scan the pairing QR or paste its URI into the app on your devices. One time.

  3. 03

    Get your links back

    Links land on your Mac, iPhone or iPad. Sign-in callbacks tunnel home automatically.

Full guide in the docs.

Linux / headless box
# install the free engine
brew install jereco/tap/handback

# catch links + pair your devices
handback install
handback pair --host your-box:8765 --qr

# keep it running (or: handback serve)
brew services start handback
Mac

Open Handback → Settings → Engine

Turn on “Act as an engine on this Mac,” confirm your tailnet address, then Show pairing QR… — no Homebrew needed.

One price. Every device.

Mac, iPhone & iPad on one purchase. Glance from the menu bar, or pick up where you left off on your phone.

Handback · one-time

On the box

The Engine

Free

Linux & macOS · Homebrew · built into the Mac app

On your devices

The Handback app

One-time

A single purchase, not a subscription — price announced at launch.

  • Mac, iPhone & iPad (universal)
  • Unlimited machines & link history
  • Loopback OAuth callback tunnel
  • Free updates
Request early access

Launching soon — early-access seats are free until 1.0.

Questions, answered

Do my machines need to be on the same network?

No. The app dials out to each engine, so your laptop can roam. Put both on a Tailscale tailnet (recommended) or a LAN you trust, where plain ws:// is fine, or put a TLS reverse proxy in front of the box and pair over wss://. There's no relay either way.

Why do headless OAuth logins hang without Handback?

CLI logins redirect the browser to localhost on the box (RFC 8252). If the browser is on your laptop, that localhost is the wrong machine — the code never arrives. Handback binds the port on your device and tunnels the callback back to the box, so the login just finishes. On an iPhone the sign-in opens in an in-app sheet; on a Mac, in your browser.

Where does my link history live?

On your devices. There's no Handback server and no account — links (which can carry auth codes) never touch infrastructure you don't own.

What happens if my phone is off when a link arrives?

The Engine keeps it. Links that arrive while no device is connected stay on that machine for 24 hours and are delivered when a device connects, marked “arrived while you were away” — they're never opened automatically. The terminal on the box also prints the link, so you can open it there.

What runs on the agentic box?

The Engine: a free single-binary daemon for Linux and macOS. It catches links through $BROWSER and xdg-open on Linux, and on a headless Mac through a default-browser helper — so gh, gcloud and agents that call open are all caught.

Do I need the Rust engine on my Mac?

No. On a Mac you use, the Handback app is the engine: Settings → Engine runs the bundled engine for you, starts it at login, listens on your tailnet address once you confirm it, and can become the default browser — links opened by terminals and agents are handed back to your other devices, your own clicks open in your usual browser. Ran the Homebrew engine there before? Import its pairing and your devices keep working.

Why one-time pricing?

Because there's nothing for us to keep running. Your machines talk peer-to-peer; no relay, no sync service, no monthly bill to pass on.