Skip to content

Claude Code builds the team: connect it, or any app that speaks MCP, to create and manage agents from outside - #64

Merged
danielehrhardt merged 4 commits into
mainfrom
agent/c-pro/a06af3d77631
Oct 5, 2026
Merged

danielehrhardt merged 4 commits into
mainfrom
agent/c-pro/a06af3d77631

Conversation

@danielehrhardt

Copy link
Copy Markdown
Contributor

GODM-49 — the AI can create new agents itself.

What was there, and what was missing

Inside Godmode this already worked: the built-in Godmode agent has agent_create, agent_update, agent_delete (plus automations, tasks, VMs) on the internal godmode MCP server. But that server only answered Godmode's own runs — each run gets a token that dies with it. Nothing outside the app could reach it: not your own Claude Code in a terminal, not Cursor, not a script.

This PR opens that door, with a key per app.

What's new

Settings → Claude Code & MCP

  • Connect Claude Code — one click. Godmode adds itself to Claude Code on this computer for every project (claude mcp add-json --scope user). In the next session: "Create a Godmode agent that checks our competitors' pricing every Monday" — and the agent, its instructions and its schedule show up in Godmode.
  • Connect another app — a key for Cursor, Codex, Claude Desktop or a script, with the config to paste (JSON, the claude mcp add line, URL + header, shell lines). Shown once; Godmode keeps the hash.
  • Each key either sets up and steers or only looks. The list shows when an app was last used and for what; removing it cuts it off at once (and takes Godmode out of Claude Code again).
  • The page lists the 27 tools an app can call, grouped like the app's own pages.

godmode command line (the connector CLI)

export GODMODE_CONNECT_TOKEN=gmc_…
godmode tools                    # what the key can do
godmode call agent_create '{"name":"Scout","role":"Research analyst"}'
godmode mcp                      # the MCP server over stdio — what the apps start

godmode mcp finds the running Godmode through ~/.godmode/core.json on every call, so it keeps working when Godmode restarts on another port, and says "Godmode isn't running" in plain words instead of failing the connection.

Settings: Claude Code & MCP

Claude Code connected

What an app can and can't do

It calls as the built-in agent, through an allowlist (CONNECTOR_TOOLS): agents, automations, tasks, runs, spend, workspaces, VMs. Nothing that needs a run, a chat or a browser — no vault fills, no questions, no delegation, no API tools. The tools themselves are unchanged, so the existing rules hold: an agent created from outside is fill-only, can't manage agents, has no computer use, working folder or SSH servers.

  • Keys only open /mcp — not /mcp/computer, /mcp/vm, /mcp/ssh, and not the dashboard API.
  • Phones and Godmode Cloud can't create or remove keys. Backups leave them out.
  • Every change, and every refused or failed call, is in the audit log as connector.call with the app as actor.
  • GODMODE_CONNECT_TOKEN is stripped from agent runs; Godmode's own runs use --strict-mcp-config, so the Claude Code entry never reaches them.

Worth knowing: a look-only key still sees which logins exist (names, usernames — never a password) and snippets of what runs were asked and answered. A full key can create agents and automations that later act with saved logins. Both are in SECURITY.md.

One fix to existing behaviour, found in review and now reachable from outside: task_update let a caller rewrite the description of a task assigned to a reveal-mode agent without the check routine_update and agent_update already had. It refuses now, for agents and apps alike.

Verified

  • bun test in packages/core: 1422 pass, 0 fail (merged with main). 20 new tests in test/connect.test.ts: key auth, the allowlist, look-only vs full, agent limits, REST, phone/cloud refusal, install and uninstall with a fake claude, the CLI and the stdio bridge.
  • pnpm -r typecheck clean.
  • Live, against a throwaway Godmode and a throwaway Claude Code config: the one-click button registered the server and claude mcp list reports ✔ Connected; a real claude -p session asked for an "Inbox Triage" agent created it with a weekday 08:00 schedule.
  • Independent code review of the auth path: no authorization holes; its findings (bridge crash if Godmode quits mid-call, stale "installed" flag after a failed re-install, refused calls missing from the audit log, access level failing open) are fixed here.

Not tested: the packaged desktop app (the one-click path was exercised with the core run from source), and Windows.

Migration 70 (connectors). Merged with main; the only conflict was the migrations list.

…to create and manage agents from outside

Settings → Claude Code & MCP adds Godmode to Claude Code in one click and gives other apps a key of their own.
A key opens the management tools of the MCP gateway (agents, automations, tasks, runs, VMs), with full or
look-only access; godmode mcp, tools and call bring the same tools to a terminal.
# Conflicts:
#	packages/core/src/db/migrations.ts
# Conflicts:
#	README.md
#	apps/desktop/src/pages/settings/settings-page.tsx
#	packages/core/src/db/migrations.ts
@danielehrhardt
danielehrhardt merged commit d5edfd4 into main Oct 5, 2026
7 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant