mrkeyoor.com_
Mon 28 Sept 19:23 UTC
Dev Toolsevaluationupdated 26 Aug 2026

cockpit-tools review

Cockpit Tools is primarily documented in Chinese, and a substantial English README exists. It is a desktop account switcher and quota dashboard for Codex, GitHub Copilot, Cursor, Windsurf, Kiro, Antigravity, Grok CLI, and several other AI coding products, with isolated instances and local gateway features.

+209stars / 7d
Verdict

Our Cockpit Tools build succeeded in 77 seconds after a 198-package install, but the repository offered no general test target for us to run. The app can save real time for one technical user juggling many coding accounts, provided local credential files and a fast-changing release line are acceptable. Commercial teams should stop at the CC BY-NC-SA license, and security-sensitive users should wait for signed macOS builds and a real vulnerability policy.

We ran it

Lab card: what happened when we ran cockpit-toolsScreenshot of cockpit-tools (github.com/jlcodes99/cockpit-tools#readme)
Install✓ · 15s198 packages · 235 MB
Build✓ · 77s
Testsn/ano test script
Known vulns00 critical · 0 high · 0 moderate · 0 low (npm audit)
Repo1558 files~692,184 lines of source · 52.1 MB · 3 CI workflows · tests dir

Answers from our run

Does cockpit-tools build from source?

Dependencies installed in 15 seconds (198 packages), and the build succeeded in 77 seconds. We cloned commit 883cf08 into a clean Debian container with 3 CPUs and no project-specific setup.

Does cockpit-tools have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Does cockpit-tools have known vulnerabilities in its dependencies?

npm audit found none in the dependency tree at the time of our run.

Who should not use cockpit-tools?

Companies planning internal or commercial use without a separate agreement: the README applies CC BY-NC-SA 4.0 and explicitly bars enterprise internal commercial use.

What are the alternatives to cockpit-tools?

CC Switch, CLIProxyAPI, Antigravity Manager. Our Cockpit Tools build succeeded in 77 seconds after a 198-package install, but the repository offered no general test target for us to run.

Setup3/515-second install; native builds still need Rust and Tauri
Docs3/5Detailed bilingual README, but security policy is placeholder text
Community4/516,568 stars and same-day activity, with a crowded issue queue
Maturity2/5No general test target, unsigned macOS builds, rapid fixes

Who it’s for

Individual developers who legitimately use several accounts or providers and want one local status screen.
People running parallel coding-client instances with separate profiles and working directories.
Codex, Claude Code, and OpenCode users who need local provider mapping or quota visibility.
Users comfortable inspecting where OAuth and API credentials are stored on their own machine.

Who it’s NOT for

Companies planning internal or commercial use without a separate agreement: the README applies CC BY-NC-SA 4.0 and explicitly bars enterprise internal commercial use.
Anyone who requires every stored token to be encrypted: the English README says Grok CLI access and refresh tokens are plaintext JSON protected by OS account isolation and file permissions.
macOS users who will not bypass Gatekeeper for unsigned software: the README says releases lack Developer ID signing and notarization and suggests removing quarantine.
Teams relying on the repository security policy: SECURITY.md still contains placeholder reporting text and lists unrelated 5.1.x and 4.0.x support rows while the release line is 1.3.x.
Users who cannot risk account-switching regressions: current issues report missing Codex chat history, invalid configuration after switching, failed client launches, and repeated reauthorization.

Setup reality

Our sandbox installed 198 npm packages in 15 seconds and used 235 MB. The build passed in 77 seconds, and npm audit found 0 known vulnerabilities. No general tests script or target was available, so the lab skipped tests even though the repository contains a tests directory.

Source work needs Node.js 18 or newer, npm 9 or newer, Rust, and the Tauri toolchain. Normal users can download macOS, Windows, or Linux packages. Each managed service still needs its own valid OAuth session, API key, local client installation, or executable path.

The app writes account state into its own data directory and into official client paths such as ~/.codex and ~/.grok. Its WebSocket binds to 127.0.0.1 on port 19528 by default. macOS releases are not signed or notarized, and the README recommends a quarantine bypass when Gatekeeper blocks them.

Sixteen coding products share one account dashboard

Cockpit Tools puts account status, quota use, reset times, and launch controls for 16 named coding products into one Tauri desktop app. The list includes Codex, GitHub Copilot, Cursor, Windsurf, Kiro, Antigravity IDE, Grok CLI, CodeBuddy variants, Qoder, Trae variants, Zed, and ZCode. The primary README is Chinese, while a detailed English edition and an 18-language interface are available.

This is useful for a specific kind of developer: someone with legitimate access to several accounts who repeatedly signs out, changes local credentials, or launches separate client profiles. Managed instances can use different directories and account bindings. The dashboard also refreshes quotas and can keep more than one client instance running. That convenience comes from writing the formats and paths used by many unrelated applications, so upstream changes can break switching without warning.

Local storage includes plaintext Grok tokens

The project says its account database stays on the machine rather than in a Cockpit cloud account. It also writes selected credentials back to official locations such as ~/.codex, ~/.grok, and ~/.zcode/v2. On Unix, Grok credential directories use mode 0700 and files use 0600, but the access and refresh tokens inside remain plaintext JSON. File permissions are the main protection.

A local WebSocket service binds to 127.0.0.1 and uses port 19528 by default. It can be disabled when plugin integration is unnecessary. OAuth, token refresh, quota checks, and update checks still contact each provider. Backups need special care because copying the application data or home-directory credential files may copy live sessions. The README advises redaction and account removal on shared machines.

What happened when we ran it

Our sandbox installed commit 883cf08 in 15 seconds, adding 198 npm packages and occupying 235 MB. The build passed in 77 seconds. Npm audit found 0 known vulnerabilities in the installed Node dependency set. The checkout measured 52.1 MB, contained 1,558 files, and had roughly 692,184 lines of source, much of it in the bundled sidecar code.

We did not run tests because the package exposed no general test script or target. The repository does contain a tests directory and one narrowly named Codex API-key test command, but that is not a project-wide entry point. Our scan also found 3 CI workflow files and no Dockerfile. A successful web build therefore gives less confidence than a passing suite across credential import, switching, instance isolation, and client launch behavior.

The lab result covers the Node install and declared build in an unprivileged Debian container with 3 CPUs and 8 GB of RAM. It does not show that the Tauri desktop package launches, that each supported client is detected, or that OAuth refresh works. Those need release-package checks on macOS, Windows, and Linux with disposable test accounts rather than primary credentials.

Current issues describe switching and history failures

Issue 2099 reports recent Codex work records disappearing after account switches and says visibility repair and instance import did not recover them. Issue 2101 reports conversations failing to resume after a switch because config.toml contained an invalid transport under an MCP server entry. Other reports from August 26 describe access-denied client launches, repeated login prompts, and OAuth refresh revocation.

These reports do not prove Cockpit deleted every affected conversation, and several contain little diagnostic detail. They do identify the highest-risk boundary: the app changes another product's local state while that product may also be running or updating it. Before regular use, export the original client state, test one disposable account, close the target client during switching, and verify that old sessions remain visible after a restart.

macOS installation requires bypassing a trust control

Cockpit Tools ships .dmg, .msi, .exe, .deb, .rpm, and AppImage packages. The macOS release flow does not use Apple Developer ID signing or notarization. Its troubleshooting section recommends --no-quarantine, removing the quarantine attribute with sudo xattr, or choosing Open Anyway in system settings when Gatekeeper blocks the application.

That is a serious tradeoff for software holding many OAuth tokens. A checksum and public source help, but they do not replace signed provenance for a downloaded binary. Cautious macOS users should build from reviewed source or wait for notarized releases. Windows and Linux users should still verify the release asset and keep the data directory inside a single-user OS account.

The license rules out ordinary company adoption

GitHub's API did not identify a standard license file for the repository. The README states CC BY-NC-SA 4.0 and goes further, explicitly barring commercial use including internal enterprise use, paid integration, services, and resale without written authorization. That is a straightforward stop sign for a company hoping to put Cockpit on employee machines.

The security policy creates another review problem. It contains template instructions telling maintainers what to write and lists supported versions 5.1.x and 4.0.x, while the current release is v1.3.32. GitHub recorded that release and a new push on August 26, 2026, with 16,568 stars and 477 combined issues and pull requests. Development is active, but a fast release cadence does not repair unclear security handling.

Cockpit Tools makes the most sense as a personal convenience on a locked-down machine. The 77-second build and 0 npm advisories make inspection approachable, while the missing general test target, plaintext token storage, unsigned Mac build, license limit, and account-switching reports set a low ceiling on trust. Use disposable accounts first, keep backups outside its managed paths, and disable the local service when nothing consumes it.

Alternatives

ProjectWhat it isPick it when
CC Switch gh↗A cross-platform desktop switcher for Claude Code, Codex, OpenCode, OpenClaw, and Grok Build.pick this instead when your account set centers on Claude Code and Codex and you want a narrower desktop tool.
CLIProxyAPI gh↗A local proxy that exposes several coding subscriptions through compatible API shapes.pick this instead when API translation and routing matter more than a graphical account dashboard.
Antigravity Manager gh↗A Tauri desktop manager focused on Antigravity account switching.pick this instead when Antigravity is the only client you need to manage.

What people are saying

  1. [github-trending] jlcodes99/cockpit-tools

Sources

  1. Cockpit Tools Chinese README
  2. Cockpit Tools English README
  3. Cockpit Tools v1.3.32 release
  4. Cockpit Tools security policy
  5. Issue 2099: missing Codex work records
  6. Issue 2101: invalid transport after switching

More dev tools reviews

coursebook · ink · kitter · flea · sonicloud_opensdk · cn · the whole board →