The problem came up about five minutes after I set up my Raspberry Pi with Ubuntu Desktop and Codex. I wanted an always-on personal agent with Browser Use, Computer Use, and a residential IP, accessible from both my phone and laptop (keep in mind, this was before Muse and Dots dropped). But a few prompts in, in order to run a command that needed `sudo`, the agent asked me to enter an administrator password in a terminal that–to me as a client on my Macbook–seemingly didn't exist. I then realized: "this dude has some password prompt open on its TTY, and I simply cannot see it."
Unrestricted passwordless sudo would have removed that interruption, but I wanted to keep approving administrator actions myself, so setting up my Pi pivoted into building a Mac app.
And so Syn was born: Syn hooks into sudo after its policy check. It pauses the invocation and shows the machine, account, executable, and arguments on the paired Mac, where I can approve it with fresh Touch ID or Mac-password authentication.
Each approval is cryptographically signed and bound to that specific invocation. The unprivileged network service only relays signed requests and decisions; sudo executes its original command.
The devices communicate directly over mutually authenticated TLS, without the need for a cloud relay. Interactive terminal use also has a password fallback, and Syn works with any eligible commands regardless of which agent—or person—started them.
Current support is macOS 15+ on Apple silicon and Ubuntu 26.04 ARM64 with classic sudo.ws 1.9.x. I have mine set up between my Raspberry Pi and my Macbook with NordVPN Meshnet in the mix to ensure I can connect when outside my LAN, but it should work the same with any compatible VPS or using another virtual LAN (like Tailscale).
If this fits your setup, I’d love folks to try it and share feedback! It's an open-source project, so PRs are super super welcome.