Supervise your agents

Your agents,
on a short leash.

Neku watches long-running coding agents on machines you already own. It pulls you in only when one holds a tool call, and denies that call if you never answer.

Claude Code · OpenCode · Codex · your machines, your keys

The problem

Agents fail quietly, and always while you are away.

It ran an hour, then stalled

The last thing you saw was a healthy task. It has been sitting on a question for forty minutes and nothing told you.

The hold lands at the worst time

An agent is waiting on rm -rf ./dist while you are on a train. The laptop that could answer is at home, asleep.

So you tail terminals by phone

SSH, tmux, pinch, squint, scroll back. A terminal is not a control surface for six agents on three machines.

What Neku gives you

A control surface, not a terminal.

Four things the app does that a shell on your phone cannot.

Session inbox with states

Every session on every host, sorted by who needs you. Five states, each a glyph and a label.

Spans, not noise

Subagents nest inside the session, so you open the chain that matters instead of a transcript.

Approvals with the receipt

The command verbatim, the span chain that produced it, and a countdown that denies on timeout.

Policies, budgets, breaker

Allow, ask or deny by pattern. Rate-limit meters and a breaker that halts a runaway host.

How it works

Four steps, about ten minutes.

01

Install the daemon

One command on each host. It finds the agents you already run.

02

Pair a device

Scan a code. Keys are exchanged directly, never held by the relay.

03

Agents report in

Sessions, spans and held tool calls arrive encrypted end to end.

04

Decide from anywhere

Push arrives, you read the command, you hold to approve.

Live where you are

The approval comes to you.

A held call raises a push on every paired device. The sheet carries the command, the span chain and the clock.

Push, then the whole picture

The notification names the project, the host and the command it is holding.

Hold to approve, 600 ms

A deliberate press. No single tap anywhere in Neku runs a command.

Offline disables decisions

If the host is unreachable the buttons go dead rather than pretend.

Timeouts always deny

Miss the window and the call is denied, the agent told why, the denial logged.

Privacy

Your data never leaves your machines.

The relay moves sealed bytes between your hosts and your devices. It cannot open them.

How Neku data flows: your hosts to the relay to your devices, with the account server off to the side Your hosts seal every frame and send it through the encrypted relay to your paired devices, which decrypt it locally and send back signed decisions. The relay only forwards sealed bytes it cannot open. The account server, off to the side, holds only your plan, seats and device public keys — metadata, never session content. metadata Your hosts daemon runs beside your agents code, transcripts & keys stay here Encrypted relay forwards sealed frames it cannot open them Your devices decrypt locally, you decide approvals signed on device Account server plan · seats · device keys metadata only, no content
The relay only moves sealed bytes and their sizes between your hosts and your devices. It never sees your code, commands, diffs or decisions, and approvals are signed on the device.
  • gold — sealed frames (state, spans, held calls)
  • grey — your signed decisions
  • dashed — entitlements & device public keys (metadata only)
  • Code and transcripts stay on your hosts. Neku reads what the agent already prints on the machine. Nothing is uploaded to run it.
  • The relay carries ciphertext. It routes sealed payloads and their sizes. It cannot read a command, a diff or a path.
  • The account server holds entitlements. Plan, seats and paired device public keys. No sessions, no commands, no output.
  • Keys live on your devices. Approvals are signed on the device and verified against a pinned key. The cloud cannot forge one.

Read the security overview

Supported agents

Detected automatically on the host.

claude-codecodexopencode · more via the adapter API

[CUSTOMER QUOTE — two sentences on leaving agents running overnight and being pulled in only for the calls that matter]

[NAME, ROLE] · [COMPANY]

Pricing

Start free. Pay when you add hosts.

Free

[PRICE] forever
  • 1 host · 2 devices
  • 7-day history
  • Ask-by-default policies

Pro

MOST POPULAR
[PRICE] per month
  • 5 hosts · 5 devices
  • 90-day history
  • Full policies, budgets, push

Team

[PRICE] per seat
  • Unlimited hosts and devices
  • 365-day history · audit log
  • Shared policies · SSO

Every tier fails closed: a held call denies when the countdown runs out. See full pricing →

Questions

Before you install.

Is Neku a terminal emulator?

No. It does not stream a pty and you cannot type into the agent. It shows state, spans and held tool calls, and carries your decision back.

What happens if I never answer?

The hold expires and the call is denied. Timeouts always deny, the agent is told why, and the denial is written to the session.

Does my code leave my machines?

No. Code, transcripts and terminal output stay on your hosts. The relay only routes sealed bytes it cannot open. See the security overview.

Which agents work today?

claude-code, codex and opencode are detected automatically on the host, with more via the adapter API. See the documentation.

Put your agents on a short leash.

Install the daemon, pair a phone, and watch the first session land in the inbox.

free tier · 1 host · 2 devices · timeouts deny