Set up
Install it, start it, pair it.
The sidecar is a small server that runs on the machine whose files you want the agent to reach. It is the only thing you install.
Install and start
Install the @corenel/sidecar package; it needs Node 22 or later. Then start it on the folder you want to share:
It listens on this machine only (127.0.0.1, port 4858) and prints what it is serving, then an address and a pairing token under PAIR FROM ANY DEVICE. Without --root it shares the folder you started it in; repeat --root to share several. It runs while the command is open. corenel-sidecar --help lists every option.
Pair it with the browser
- Open Corenel and click the sidecar indicator at the bottom of the rail.
- Under Paste what it printed, paste the whole block the sidecar printed, or just the token.
- Name this device if you like, then Connect.
The dialog’s first step, Run this on the machine you want to reach, builds the exact command for This machine, Another machine on your network, or Anywhere (a public URL through the cloudflared tunnel, so a phone can pair from elsewhere). Starting the sidecar with --open opens Corenel in your browser already paired.
Choose and add folders
The location bar at the top of the workspace picks which shared folder is active. The agent’s file tools cannot reach anything outside the shared folders.
To add folders from the browser while the sidecar runs, start it with --allow-add-under <dir>. The location bar’s Folder menu then offers Add a folder, which browses folder names beneath that directory and nowhere else, and can create a new one. A folder added this way is saved to the sidecar’s settings, so it is still shared after a restart. From a terminal, corenel-sidecar roots add <path> does the same.
Turn on the shell
The shell is off until you start the sidecar with --allow-shell (the pairing dialog’s Shell switch adds it to the command for you). Even then, under the default policy every command stops and asks you first.
A command you approve runs with your permissions and is not limited to the shared folders.
Unattended
Run crew agents on their own clock.
Started with --daemon, the sidecar also runs crew agents itself, so scheduled and triggered runs fire with no browser open.
Start it as a daemon
- Sign the sidecar in once. It opens your browser, where you approve the sign-in:$ corenel-sidecar login
- Start it with
--daemon:$ corenel-sidecar --daemon --root ~/work/apiIts startup lines say whether it is run-capable and that its clock is on. - Pair it from the browser as above. Your crew agents are sent to it, and the Crew page shows Daemon connected.
A daemon run needs a model: set one on the agent, or start the daemon with --default-model <id>. An agent with neither fails fast, before any call to a model. Model calls go through the gateway on your sign-in.
What it enforces
- Each agent’s budget, on every run. A dollar cap on a model the daemon cannot price refuses to start rather than never tripping.
- A Continuous trigger needs a dollar or token budget, and fires at most once a minute.
- Schedule triggers are cron expressions matched against UTC.
- When a step needs approval and nobody is attending, the agent’s unattended mode decides: deny (the default), park until someone answers, or allow. See Approvals, policy and Home.
Check on it
corenel-sidecar statusshows the sidecar running on this machine: pid, port and uptime.corenel-sidecar stopstops it.corenel-sidecar doctorreports what this machine would serve and what is wrong, and exits non-zero on a definite fault.corenel-sidecar setuprecords this machine’s settings in its config file, so you stop retyping flags;corenel-sidecar configreads or changes one setting.
Going further
Sandboxes, and an agent you already have.
Isolate sessions in a microVM
By default a session runs in the sidecar’s own process, still limited to the shared folders. Start the daemon with --isolation microvm (it needs the msb runtime) and each session runs in its own sandbox behind a kernel boundary. The startup lines say which mode is in effect. Activity, under Live, shows each session with its CPU and memory, and lets you pause, snapshot or destroy it.
Drive Claude Code through Corenel
Then choose Claude Code in the model picker, under On your machine, and chat as usual. Each of its tool calls asks Corenel’s policy first (--acp-policy is standard, read-only or autonomous; standard by default), and a call aimed outside the shared folders is refused. By default it signs in with your existing Claude subscription; --acp-auth switches that to an API key.