Skip to content
ZAIQZAIQ

Palm Free and open source

Download Palm.

Let your coding agent install it. Copy the prompt, paste it into Claude Code, Codex or any agent on your Mac, and it does the work, stopping only for the few steps that need you.

View on GitHub

Mac with Apple silicon and macOS 26 or later · Tailscale on both devices · the iPhone app or your phone's browser

What the agent leaves to you

  • Allow Palm on the Mac

    Screen Recording and Accessibility, in System Settings. Only you can grant those.

  • Sign in to Tailscale

    On the Mac and on the phone, with the same account.

  • Pair your phone

    Scan the code on the Mac's screen, then set up Face ID.

The agent prompt

Everything your agent will be asked to do. Read it before you paste it.

Read the prompt ↓
Install Palm on this Mac for me.

Palm (https://github.com/zaiqltd/palm, open source, MIT, made by Zaiq) lets me use this Mac from my phone over my own Tailscale network: the live screen, files, terminal and coding agents. After you clone it, read README.md and SECURITY.md. If they disagree with anything below, follow the README.

Work through the steps in order and run the commands yourself. When a step needs me (an installer, a password, System Settings, my phone), stop, tell me exactly what to do, and wait. If a command fails, show me the error and stop; don't work around it.

First ask me: the iPhone app, or Palm in my phone's browser? The browser needs no Apple account and no phone build. If I'm not sure, choose the browser.

Rules
- Palm's server stays on 127.0.0.1:4318, published only to my tailnet by Tailscale Serve. Never use Tailscale Funnel, never open router or firewall ports, and never run `tailscale serve reset` (it deletes every Serve rule on this Mac, not just Palm's).
- Never grant macOS permissions yourself or change the TCC database. I grant them in System Settings.
- Never ask for, print or save a pairing code or pairing link. Pairing happens between the Mac's screen and my phone.
- No sudo. Delete nothing outside the clone.

1. Check this Mac
- `uname -m` is arm64 and `sw_vers -productVersion` is 26 or later. If not, stop: Palm needs Apple silicon and macOS 26.
- `xcode-select -p` prints a folder. If not, run `xcode-select --install` and wait while I finish the installer. The Command Line Tools are enough for the Mac side.
- `node -v` is v24. If not, install Node.js 24: `nvm install 24` if I use nvm, otherwise `brew install node@24` with `$(brew --prefix node@24)/bin` first on PATH.
- `tailscale status` shows this Mac connected. The command may be at /Applications/Tailscale.app/Contents/MacOS/Tailscale. If Tailscale is missing or signed out, ask me to install it from https://tailscale.com/download and sign in. My phone needs the Tailscale app too, signed in to the same tailnet.
- iPhone app only: Xcode 26 or later in /Applications, and xcodegen (`brew install xcodegen`).

2. Build and install Palm (a few minutes)
Clone it to ~/palm, or to a new folder if that one exists:

    git clone https://github.com/zaiqltd/palm ~/palm
    cd ~/palm
    npm ci

Run `security find-identity -v -p codesigning`. If it lists an "Apple Development" or "Developer ID Application" identity, put its 40-character fingerprint in the export line below. If it lists none, leave the export line out: ad hoc signing works, but macOS then forgets Palm's permissions on every update. Run these in one shell:

    export PALM_MAC_SIGNING_IDENTITY=<fingerprint>
    npm run native:build && npm run build && npm run package:mac && npm run install:mac

Palm is now in ~/Applications/Palm.app and running. This must return JSON:

    curl -s http://localhost:4318/api/local/setup

3. Permissions (me)
Run `open http://localhost:4318`. Tell me to click Open setup, then Open Mac setup, and to allow Palm under Screen Recording and Accessibility (each Allow opens System Settings › Privacy & Security). Then run the setup curl again: status.screenPermission and status.controlPermission must both be true. If they stay false after I have allowed both, ask me to choose Quit Palm from Palm's menu bar icon, then run `open ~/Applications/Palm.app` and check again.

4. Put Palm on my tailnet

    tailscale serve --bg --https=8443 http://127.0.0.1:4318
    tailscale serve --bg --https=8444 http://127.0.0.1:47820
    tailscale serve --bg --https=8445 http://127.0.0.1:47821
    tailscale serve --bg --https=8446 http://127.0.0.1:47822

8443 is Palm; 8444 to 8446 carry dev-server previews. If Tailscale prints a link to turn on Serve or HTTPS for my tailnet, give it to me, wait, then run the command again.

Then give Palm its private address, or pairing shows no QR code. Take Self.DNSName from `tailscale status --json` without the final dot (like my-mac.tail1234.ts.net) and run this with that name in place of MY-MAC.MY-TAILNET.ts.net:

    curl -fsS -X POST http://localhost:4318/api/local/connection -H 'Origin: http://localhost:4318' -H 'Content-Type: application/json' -d '{"origin":"https://MY-MAC.MY-TAILNET.ts.net:8443"}'

The setup curl now shows that address as remoteOrigin.

5. The iPhone app (skip this for the browser)
Ask me to: connect the iPhone to this Mac with a cable and tap Trust; turn on Developer Mode (Settings › Privacy & Security › Developer Mode; the phone restarts); add my Apple Account in Xcode › Settings › Accounts (a free one works); and, under Manage Certificates there, add an Apple Development certificate if there is none. Then find:
- PALM_DEVICE_ID: the iPhone's UDID, hardwareProperties.udid in `DEVELOPER_DIR=/Applications/Xcode.app/Contents/Developer xcrun devicectl list devices --json-output "$TMPDIR/devices.json"`
- PALM_TEAM_ID: the OU value in `security find-certificate -c "Apple Development" -p | openssl x509 -noout -subject`
- PALM_BUNDLE_ID: a bundle id of my own, like com.myname.palm (a bundle id belongs to one Apple team)

    PALM_BUNDLE_ID=<bundle id> PALM_TEAM_ID=<team id> PALM_DEVICE_ID=<udid> scripts/ios-build.sh install

Before I open Palm the first time, I trust the developer in Settings › General › VPN & Device Management. With a free Apple account the app stops opening after 7 days; run this step again to reinstall.

6. Pair (me)
Tell me: on the Mac, at http://localhost:4318, click Pair an iPhone. Then:
- Browser: scan the QR code with the phone's camera and Palm opens in the browser. For the full-screen app, first tap Share › Add to Home Screen, open Palm from the Home Screen and type the code the Mac shows (a Home Screen app keeps its own sign-in). Tap Connect to my Mac, then Set up Face ID.
- iPhone app: open Palm, scan the QR code and tap Connect to my Mac.
Codes work once and expire in two minutes (New pairing code makes another); a pairing lasts 30 days.

Finish with a short summary: what you installed and where, what you checked, and anything still waiting on me.

Or install it yourself

You need Node.js 24 and Apple's Command Line Tools on the Mac, and Tailscale on both devices. The iPhone app also needs Xcode; the browser needs nothing more. Every detail is in the README.

  1. Build and install Palm on the Mac

    git clone https://github.com/zaiqltd/palm
    cd palm && npm ci
    npm run native:build && npm run build
    npm run package:mac && npm run install:mac

    Then allow Palm under Screen Recording and Accessibility in System Settings.

  2. Put it on your tailnet

    tailscale serve --bg --https=8443 http://127.0.0.1:4318

    Never with Funnel: Palm is for your own devices only.

  3. Tell Palm its address

    Open http://localhost:4318, choose Open setup, then Open Mac setup, and save your Mac's tailnet address under Private connection, like https://your-mac.your-tailnet.ts.net:8443.

  4. Pair your phone

    Choose Pair an iPhone and scan the code: with the phone's camera for the browser, or from the Palm app. Codes work once and expire in two minutes.

A paired phone can see and control your Mac, reach your files, open shells and start agents. Read the security notes before you install it.

What Palm does · Palm is built by Zaiq and is not affiliated with Apple, Anthropic, OpenAI or Tailscale.