# codexapp: the Codex app UI in a browser, including Termux on Android

> codexapp is an MIT-licensed npm package that puts the Codex app-server UI behind a local web server on port 18923, with a Cloudflare tunnel on by default. It is a remote-access bridge, not a mobile client.

**friuns2/codex-mobile** — 🚀 Run Codex Mobile Anywhere: Linux, Windows, or Termux on Android 🚀

- Repository: https://github.com/friuns2/codex-mobile
- Website: https://friuns2.github.io/codex-mobile/
- Stars: 947 · Forks: 193
- Language: TypeScript
- License: MIT
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/friuns2-codex-mobile

## What codexapp actually solves for Codex users on a phone or a headless box

Codex ships as a desktop app. If your work happens on a Linux server, a Windows machine you are not sitting at, or an Android phone, the app-server is there but the UI is not. codexapp is a bridge: it starts a local web server that exposes Codex app-server workflows as a browser interface, so the same projects and conversations are reachable from any browser that can reach the host. The package description in package.json calls it "a lightweight web interface for Codex that runs on top of the Codex app-server, allowing remote access from any browser".

The intended audience is narrow and specific. People running Codex on a machine without a desktop session. People who want to start or check a thread from a phone. People who already live in Termux on Android and want the agent loop in the same place as their shell. It is not a hosted service and it is not a replacement for the Codex CLI: the README describes it as a UI layer over app-server, so the agent work still happens wherever Codex is authenticated. The npm package is named codexapp and installs two binaries, codexapp and codexui, both pointing at dist-cli/index.js.

## Architecture: a Node CLI, a browser front end, and cloudflared in the startup path

The repository is TypeScript with a Vite-built front end and a tsup-built CLI. The build script runs vue-tsc and vite build for the front end, then tsup for the CLI, which is consistent with the Vue dependency implied by the tooling and the dist/ plus dist-cli/ layout in the published files list. Node 18 or newer is required, declared under engines in package.json.

The default startup path is the interesting design decision. Running the CLI starts the web server, and according to the README it also runs `cloudflared tunnel --url http://localhost:<port>` unless you pass `--no-tunnel`. The tunnel URL, a terminal QR code, and a password are printed together in the startup output. That means the out-of-the-box behaviour is to publish your Codex UI to a public Cloudflare URL, with a password as the only stated gate. The README does not describe how that password is generated, stored, or rotated, and it does not document an authentication layer for the local server itself. Treat the default as convenient rather than private, and reach for `--no-tunnel` when the host is already on a network you trust.

There is also a login step. On startup codexapp will run `codex login` unless you pass `--no-login`, which the README frames as the escape hatch for providers or AI gateways that are already authenticated. If you run Codex against a non-OpenAI gateway, that flag is the difference between a working start and a login prompt you cannot satisfy.

State lives in CODEX_HOME. The export and import features are built around that assumption: a project ZIP includes matching Codex chat JSONL history under `.codex-project/chats/`, and imported chats are rewritten for the destination CODEX_HOME, project path, and currently selected provider and model so they can be resumed in the new environment. That rewriting step is the part worth understanding, because it means an imported conversation is not a byte-identical copy: it is adjusted to fit where it landed.

## Install and first run: npx codexapp, then a browser on port 18923

The README recommends running the package directly rather than installing it globally. Node 18 or newer must be on PATH first; the Linux and Windows sections both begin with a version check.

```bash
node -v   # should be 18+
npx codexapp
```

After the server starts, the README says to open `http://localhost:18923` in a browser. The startup output also prints the tunnel URL, a QR code, and a password when the tunnel is enabled. The QR code is the practical path for a phone: scan it, land on the tunnel URL, and enter the printed password.

If you are on Android, the setup runs inside Termux and needs Node installed through the Termux package manager before the same command works.

```bash
pkg update && pkg upgrade -y
pkg install nodejs -y
npx codexapp
```

The README lists background requirements for Android that matter more than the install itself: keep the process running in the current Termux session, disable battery optimization for Termux in Android settings, keep the persistent Termux notification enabled, and optionally run `termux-wake-lock`. If Android kills the process, you return to Termux and run `npx codexapp` again. Nothing in the documentation describes a service supervisor or an auto-restart, so on Android the process lifetime is your problem.

For a private setup instead of a public tunnel, the README gives a Tailscale Serve recipe aimed at iPhone and iPad Safari, where a secure context appears to matter for mobile browser access and dictation.

```powershell
npx codexapp --no-tunnel --port 5900
tailscale serve --bg 5900
```

The README states this keeps access private to your tailnet, and that authentication behaviour may differ from direct remote access depending on proxying details. It also notes a rough edge: if conversations created in the web UI do not immediately appear in the Windows app, restarting the Windows app may refresh them.

## The Telegram bridge is the only access control the README specifies in detail

codexapp can forward messages between a Telegram chat and a mapped Codex thread. The bridge is configured entirely through environment variables set before startup.

```bash
export TELEGRAM_BOT_TOKEN="<your-telegram-bot-token>"
export TELEGRAM_ALLOWED_USER_IDS="<your-telegram-user-id>,<optional-second-id>"
export TELEGRAM_DEFAULT_CWD="$PWD" # optional, defaults to current working directory
npx codexapp
```

The README is explicit that `TELEGRAM_ALLOWED_USER_IDS` is required for safe access: only allowlisted Telegram user IDs can use the bridge, and if no allowed user IDs are configured, incoming messages are rejected. That is a fail-closed default, and it is the clearest security statement in the whole document. To find your ID, the README suggests messaging the bot and then calling the Telegram getUpdates endpoint and reading `message.from.id`.

Commands include `/start`, `/threads`, `/newthread`, `/thread`, `/current`, `/history`, `/status`, `/whoami`, and `/help`. Outgoing assistant messages are sent with Telegram `parse_mode=HTML`, with an automatic plain-text fallback if HTML delivery fails. Note the asymmetry: the Telegram path has an allowlist, while the web UI path has a password printed to the terminal and no documented allowlist. If you care about who can reach the agent, that gap is the thing to resolve before deployment.

## Where codexapp is the wrong tool

The default tunnel is the biggest caveat. A public Cloudflare URL with a terminal-printed password is a reasonable way to try the UI from a phone once. It is a poor default for a machine holding credentials and repository access. The README does not document password rotation, session expiry, or a way to disable the password and rely on an external auth proxy, so hardening means putting something in front of it or using `--no-tunnel` and a private network such as Tailscale.

Mobile Safari is acknowledged as imperfect. The README says some minor mobile Safari CSS issues may still exist but do not prevent normal use. That is a fair description of a UI that was not designed mobile-first, and it means anything relying on precise touch targets or keyboard behaviour is a gamble.

There is no documented rollback or downgrade path. Releases move fast, with v512, v513, and v514 all published within about a day of each other in May 2026, and the last push to the repository was on 2026-05-26. The README does not describe how to pin or revert a version, so if a release breaks your setup, the recovery route is npm version pinning rather than anything the project documents.

The import path buffers. The README states that exports stream ZIP bytes with response backpressure handling and skip generated and git-ignored folders, while imports still buffer the selected ZIP once because the browser upload arrives as a single file. On a phone with a large project archive, that buffering is where memory pressure will show up.

Finally, codexapp is not a Codex reimplementation. It does not replace the CLI or the app-server, and it will not work without a Codex install you can authenticate. If you have no Codex setup, this package gives you a web page that cannot do anything.

## Alternatives and how the approach differs

The obvious comparison is plain SSH plus the Codex CLI. That path has no web server, no tunnel, and no browser surface, and it inherits whatever authentication your SSH configuration already enforces. You lose the browser UI, the hold-to-dictate voice input, the project picker, and the ZIP export and import flow that carries chat JSONL history between machines. codexapp exists precisely because those conveniences are hard to get over a terminal, so the trade is real in both directions: SSH is less surface area, codexapp is more usable from a phone.

A second comparison is a general remote-desktop or VNC session to the machine running the Codex desktop app. That keeps the real desktop UI and its exact behaviour, including anything codexapp has not reimplemented, but it streams pixels and assumes a persistent graphical session. codexapp streams a web UI and works on a headless Linux box where no desktop session exists at all. If your host has no display server, VNC is not an option and codexapp is.

A third is Tailscale Serve on its own, without codexapp. That publishes an existing local service into a tailnet, but it publishes nothing useful here unless something is already serving the Codex UI. The README's own recipe combines the two: codexapp provides the server, Tailscale Serve provides the private network and HTTPS. They are complementary rather than competing.

## Maintenance, upgrade cost, and licence

The repository is not archived. Its last push was on 2026-05-26, which is close to four months before the date of this article, so the project is not being pushed to right now; the release cadence in May 2026 was rapid, with three tagged releases inside roughly 24 hours, and then the public commit activity stops in what is available here. Plan for a project that moved fast and then went quiet, and check the repository yourself before depending on it.

Upgrades are npm upgrades. The package is published as codexapp with the version field at 0.1.87 in the repository's package.json, so it is pre-1.0 and the version number gives you no compatibility promise. Because the CLI is invoked through npx, an unpinned invocation will pull whatever is latest at run time, which is the opposite of reproducible. Pinning a version in a script or a local install is the only lever the documentation implies for controlling what you get, and there is no documented migration guide between releases.

Licence is MIT, per the repository metadata and the LICENSE file at the top level. MIT is permissive and places few obligations on you beyond retaining the copyright notice and permission text in copies or substantial portions. This is not legal advice, and the package bundles third-party dependencies with their own licences, so read LICENSE and the dependency tree rather than treating the repository's MIT label as covering everything in the tarball.

## Conclusion

Adopt codexapp if you want the Codex app-server UI reachable from a phone or another machine and you accept that a web server and, by default, a Cloudflare tunnel sit between your browser and your Codex credentials. Skip it if you need an audited, hardened remote-access layer: the README documents an allowlist for the Telegram bridge but says nothing about authentication for the web UI itself, so verify what protects port 18923 before you expose it beyond localhost, and read the LICENSE file rather than this article for the MIT terms.

## FAQ

### Can I use Codex on mobile with codexapp?

Yes, through a browser rather than a native app. codexapp starts a local web server, and the README's Termux instructions cover Android while the Tailscale Serve recipe covers iPhone and iPad Safari.

### Is codexapp available on Windows?

Yes. The README has a Windows section that checks for Node 18 or newer and then runs npx codexapp, and it also gives a PowerShell example combining --no-tunnel --port 5900 with tailscale serve.

### How do I install codexapp?

Install Node 18 or newer, then run npx codexapp. On Android the README installs Node through Termux with pkg install nodejs before running the same command, and the package declares engines node >=18.

### What is codexapp?

It is a lightweight web interface for Codex that runs on top of the Codex app-server, letting you reach the UI from any browser on Linux, Windows, or Termux on Android.

### Is codexapp only for Mac?

No. The README documents Linux, Windows, and Termux on Android, and the package metadata lists Linux, Windows, and Android as supported platforms.

### Is codexapp on iPhone?

There is no native iOS app in the repository. The README describes reaching the UI from iPhone or iPad Safari by running codexapp with --no-tunnel and publishing it inside a tailnet with tailscale serve.

## Sources

- [friuns2/codex-mobile on GitHub](https://github.com/friuns2/codex-mobile)
- [License: MIT](https://github.com/friuns2/codex-mobile/blob/main/LICENSE)
- [Project website](https://friuns2.github.io/codex-mobile/)
- [README](https://github.com/friuns2/codex-mobile/blob/main/README.md)
- [Releases](https://github.com/friuns2/codex-mobile/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/friuns2-codex-mobile
