Self-hosted · open source · MIT
Second•
Seat
Give anyone a live seat where your AI codes — share Claude Code, share Codex, share OpenCode. Links that expire. Guests you can kick mid-keystroke. Your keys never cross the wire.
How it works
Three moves. Then you're sharing.
Run one command
npm i -g second-seat once, then second-seat share -- --tunnel starts the relay, serves every connection, and opens a free public URL. No ports. No accounts to configure.
Send a link
Pick an expiry — a day, a week, a month. Each share is its own revocable token. Everyone signs in; nobody sees your passwords.
Revoke anytime
Your guest opens the link and gets a real PTY on your box. Done with them? Revoke. They're gone mid-keystroke; everyone else stays.
Why it wins
Built like infrastructure. Priced like air.
One seat is one human. Sharing a machine is fine; sharing a subscription gets accounts banned. Guests bring their own quotas — your keys never cross the wire. Links die on schedule: 1d / 7d / 30d / forever, swept every 15 s, revoked in one.
Under the hood
Your machine does the work.
The relay just carries keystrokes.
- Guest link = bearer token. Every message is validated against expiry and revocation; dead links 403.
- One sandbox per guest. Their shell is rooted in its own directory; your keys never enter its environment.
- Transcripts by default. Everything relayed is appended to a log you can read later.
Questions
Asked, answered.
No sales call required.
What exactly do guests see?
A real terminal (PTY) in their browser, rooted in a per-guest sandbox directory on your machine — not a chat box. You pick the mode per share: Full, Read-only, or Approve-every-command. Everything relayed lands in a transcript you can read. Honest caveat: a guest shell runs real commands in its sandbox, so share with people you trust.
Is it secure — does my API key leave my machine?
No. Your keys stay in your environment; guest shells start without them (on macOS that's enforced with a Seatbelt profile that also locks down file access). Guests bring their own quota — their own API keys or their own licensed Claude Code / Codex sessions. The relay carries keystrokes, not credentials.
Can I self-host it? What does it cost?
Yes — that's the point. MIT-licensed and free: npm i -g second-seat, then second-seat share -- --tunnel gets you a public URL through Cloudflare's free tunnel. State lives in ~/.second-seat on your box. There is no server bill because there is no server we run.
Sharing a machine vs. sharing a subscription — what's the difference?
One seat is one human. Sharing your hardware is fine; handing out your Claude Max or Codex Plus-Pro login is not — those are single-user plans and pooling them risks bans. Second Seat is built for the compliant path: guests get your machine but bring their own quota. Only pool quota where your provider's team or enterprise plan explicitly allows it.
What happens when a link expires or is revoked?
It dies. The relay validates every message against expiry and revocation and sweeps expired shares every 15 seconds. Revokes are thorough: guests on that token drop mid-keystroke while you and your other shares are unaffected. Claiming a dead link just gets a 403.
Which AI tools are supported?
Anything that lives in a terminal. Out of the box: opencode with your own keys, your own licensed Claude Code and Codex sessions, or a plain shell. The agent drives a PTY — swap one line (SHELL_CMD) to change what guest shells boot into.
Put your terminal to work.
Stay in the loop
One email when something worth it ships.
This page has no backend — submitting opens your own mail app, addressed to the maintainer. Prefer zero email? Watch the repo and releases ping your GitHub inbox instead.