Neurise EN / Blog / Claude Code from your phone

How to control Claude Code from your phone: four methods

One decision with four variants: how much convenience you want, and how much control you are willing to hand over. We rank them from the simplest to the most technical.

There are four practical ways to control Claude Code from your phone: Anthropic's native Remote Control mode, the Orca app, a private Tailscale network, or a persistent tmux session over SSH. Remote Control is the simplest, because the agent keeps running on your own computer the whole time and the phone is only a window onto that session. Tailscale and tmux give you the most control, and you pay for it with setup work and full responsibility for who can get in.

In short

  • Anthropic launched Remote Control on 24 February 2026, initially for the Max plan only. The documentation now lists Pro, Max, Team and Enterprise.
  • The session stays local: Claude Code makes outbound HTTPS requests only and never opens an inbound port on your machine.
  • Server mode handles up to 32 concurrent sessions by default, and the Bash sandbox is off by default.
  • Orca, released under the MIT licence, runs more than 30 CLI agents side by side. Its phone app is a viewer, not a workstation.
  • Tailscale plus tmux is the do-it-yourself route: a WireGuard-based network with no port forwarding, and a session that survives a dropped connection.

What Anthropic's Remote Control actually does

Remote Control is a layer that connects a Claude Code session running on your machine to the Claude app on your phone and to claude.ai/code in any browser. VentureBeat covered the launch on 24 February 2026 and noted that it was open only to Max subscribers at first. Anthropic's documentation now lists the Pro, Max, Team and Enterprise plans. On Team and Enterprise the feature is off by default, and an organisation owner has to switch it on in the admin settings.

There are three ways to start it. In your project directory, claude remote-control launches server mode: the terminal shows a session URL, and pressing the space bar displays a QR code to scan with your phone. If you would rather have an ordinary interactive session that can also be picked up remotely, start claude --remote-control. And if a conversation is already under way, the /remote-control command (short form /rc) hands the current session, history included, over to remote access. The same command works in the VS Code extension.

Server mode handles up to 32 concurrent sessions by default, and the option that controls how sessions are created can give each one its own git worktree, so two parallel sessions do not trample each other's files. You can also send a photo or a file from your phone: Claude sees photos directly in the message, while other files are downloaded to your machine and passed in as @ file references. If your laptop sleeps or the network drops, Claude Code reconnects on its own and delivers the queued messages, including permission prompts.

The important point is that the agent never moves; only the console does. It is a close relative of the idea behind loop engineering, where you supervise the system around an agent rather than each individual prompt. Anthropic's documentation says your file system, MCP servers, tools and project configuration all stay available in the remote session. Because the session keeps running on your machine, that also covers any skills you have installed, such as the ones in our round-up of SEO skills for Claude Code.

The four methods side by side

The real difference between these methods is not how hard they are to install. Each one puts your trust somewhere else: in the model vendor, in a third-party app, or in your own network setup.

MethodWhat it actually doesEffortWhen it makes sense
Remote Control (Anthropic) Connects the Claude app and claude.ai/code to a session running on your computer Low: one command Day-to-day work on your own laptop
Orca (Stably AI) Runs several CLI agents in separate git worktrees; the phone is for monitoring and sending the next prompt Medium: an app on two devices Several agents at once, including ones other than Claude Code
Tailscale A private WireGuard-based network between phone and machine, with no port forwarding Medium: an account and a client on both devices Reaching a machine in the office or your own server
tmux over SSH A persistent terminal session that keeps running after the client disconnects Higher: a terminal app on the phone and SSH keys Full control of the terminal, not just the conversation

In practice the last two nearly always travel together, because they solve different problems: Tailscale provides the route to the machine, SSH handles the login, and tmux makes sure the task does not die with the connection.

Orca, when you run several agents at once

Orca is an open-source workspace for running many coding agents simultaneously, developed by Stably AI and released under the MIT licence. Its repository lists more than 30 CLI agents it can run side by side, each in its own git worktree: alongside Claude Code you will find Codex, Cursor CLI, OpenCode and GitHub Copilot CLI, among others. The iOS and Android app is a thin client. It shows agent status, sends a notification when a task finishes and lets you type the next prompt, while all the computation stays on your computer.

The price of that convenience is one more link in the chain of trust: the app, the device pairing and the channel between them. A practical rule of thumb: the more agents you run in parallel, the less you actually read what each of them is doing.

Tailscale and tmux, the do-it-yourself route

Tailscale builds a private network, called a tailnet, on the open WireGuard protocol. Its documentation stresses that connections between devices in a tailnet work through firewalls and NAT without port forwarding or elaborate firewall rules. Your phone then sees your computer as if the two were sitting on the same desk, and nothing is exposed to the public internet.

tmux is a terminal multiplexer, and its own description covers exactly what matters here: you can detach programs that keep running in the background and reattach them later from a different terminal. For an agent session, that means a dropped connection on the train does not kill a long task, and when you reconnect you return to the same window, not a copy of it. Anthropic's Remote Control documentation gives the same advice for remote machines: start the session inside tmux or screen if it has to keep running after you disconnect from SSH.

This is the most labour-intensive route, and also the only one where the entire access chain belongs to you. It also works when the agent lives on a server in the office or on a desktop machine running local models, rather than on a laptop you carry home.

The easier it is to approve an action with one thumb, the less time you spend reading what you are actually approving.

Security when you steer a session from your phone

The connection model is the strong part. The local Claude Code session makes outbound HTTPS requests only and never opens an inbound port on your machine. Traffic runs through the Anthropic API over TLS, and the connection relies on several short-lived credentials, each scoped to a single purpose and expiring independently. Help Net Security analysed the mechanism the day after launch, and its conclusions match the documentation.

The real risk moves somewhere else: to what you approve. Anthropic's documentation describes push notifications that bring permission prompts straight to your phone, so you can approve tool calls from wherever you are. That is convenient, and precisely why it calls for caution, because on a small screen it is easier to tap "yes" than to read the whole command. In Manual mode Claude Code starts with read-only permissions and asks before every change, but the Bash sandbox, which isolates the file system and the network, is off by default in server mode, so switching it on is your job. How the habit of quick approval gets exploited is the subject of our piece on agentjacking, attacks that hijack agents through fake error messages (in Polish).

Organisations get extra safeguards. Trusted Devices, a beta feature that an organisation owner can make mandatory, requires a device enrolled in advance and a sign-in no more than 18 hours old, refreshed with Face ID, Touch ID, Windows Hello or a passkey. Anthropic states that it never receives or stores biometric data, only the device's public key and basic metadata. The whole mode can also be switched off outright with a dedicated setting, including through settings managed centrally by the company.

Anthropic's security documentation adds a recommendation that makes particular sense for phone-driven sessions: run scripts and tool calls in virtual machines, especially when the agent talks to external web services. It closes with a line worth not skipping: no set of safeguards makes a system completely immune to attack.

What we do not know about this mode

On privacy the documentation is candid, but you have to draw the conclusions yourself. While the connection is active, the session transcript (your messages, the model's responses and tool activity) is stored on Anthropic's servers so that the conversation stays in sync across devices. Command execution and file access stay local; the transcript does not. Organisations bound by a Zero Data Retention requirement cannot enable the mode at all.

There are hard technical limits too. Remote Control does not work if you use Amazon Bedrock, Google Cloud Agent Platform or Microsoft Foundry, or if you point the API address at your own gateway. The Bash sandbox supports macOS, Linux and WSL2, but not native Windows. Dialogs forwarded to the phone, other than permission prompts, expire after five minutes by default and close with their default answer, which in practice means an unread message makes the decision for you.

What we have not found is any independent measurement comparing these four methods on setup time or the number of incidents. There is vendor documentation and there are accounts from individual teams, so any claim that one method "is safer" would today be an opinion, not a finding. If the native mode gained a read-only variant or a hard cap on actions approved from the phone, the picture could change, but that is speculation, not an announcement.

What it means for a small business

If you do not run a development team, the question is not "which method should we pick". It is this: does anyone in the company have remote access to a machine where an agent can change files and run commands, and is that access written down anywhere? It is an ordinary organisational question with a new tool inside it.

Three decisions are worth making before anyone scans the first QR code. First, which machine the agent works on, and it should certainly not be the one holding production data. If the agent works on your website, for example applying technical SEO fixes or editing structured data, give it a staging copy rather than the live server. Second, who is allowed to approve actions from a phone, and whether that person understands what they are approving. Third, what happens when that phone is lost: is a remote sign-out enough, or do you also need to cut off access to the machine?

The practical conclusion for a business owner is simple: steering an agent from your phone is a convenience for someone who already understands what they approve. If you are still deciding where an agent makes sense at all, the real choice is between an off-the-shelf chatbot and a dedicated agent, not how to drive one from the sofa. And for most of the team, a short list of sensible AI uses on a phone will do more good than a remote terminal.

Setting it up in five steps

  1. Sign in to Claude Code with your claude.ai account using /login. An API key on its own is not enough, because Remote Control does not support it.
  2. Run Claude Code once in your project directory and accept the workspace trust prompt. Your home directory will not do, because trust is not saved there permanently.
  3. Start server mode, press the space bar and scan the QR code with your phone, or open the session from the list at claude.ai/code.
  4. Before you leave your desk, set the permission mode so that every change needs your approval, and consider switching on the Bash sandbox.
  5. When you are done, disconnect the session from the status panel. The local session in your terminal keeps running; it simply stops responding to your phone.

Common questions

What is the simplest way to use Claude Code from a phone?

The native Remote Control mode. Type claude remote-control in your project directory, press the space bar, scan the QR code and pick up the session in the Claude app or at claude.ai/code.

Does my phone get access to my files?

Not directly. Command execution and file access stay on your machine, and the phone is only a window onto the session. While the connection is active, however, the conversation transcript is stored on Anthropic's servers.

Is it safe to control Claude Code from a phone?

The connection itself is outbound-only HTTPS and opens no port on your computer. The remaining risk is what you approve with a single tap on a small screen, so keep permissions minimal and consider switching on the sandbox.

When should I choose Tailscale and tmux over the native mode?

When the agent runs on your own server, when you need a full terminal rather than just the conversation, or when you do not want the session transcript stored on the vendor's servers.

Sources

Read next

Find out whether AI recommends your company.

Start with the free SEO and GEO audit, delivered in 5 working days. We check how the models describe your brand and hand back a prioritised list of changes.