Claude Code and Codex
Midna runs Claude Code and Codex in its terminals. Install them the usual way; midna finds them through your login shell.
Starting an agent
Section titled “Starting an agent”- ⇧ ⌘ T opens a new agent in the current project, using the agent you last started there.
- In ⌘ K, type a request and press ⇧ ↩ to start an agent with it as the first prompt.
- Agents can start other agents for you to follow:
midna open --agent claude --prompt "…". - Triggers can start agents from GitHub and Bitbucket events.
If you start claude or codex yourself in a plain shell, it runs, but without midna’s hooks, so midna knows less about it.
What midna adds
Section titled “What midna adds”Midna passes everything on the command line when it launches an agent. It never edits your global Claude or Codex config.
Claude Code gets:
--settingspointing at a file in midna’s data folder that registers midna’s hooks. They report when a turn starts and ends, when a tool runs and when a permission dialog opens, and they check each tool call against your rules.- midna’s status line, which reports cost to Insights (setting
agents.claude.statusline). It replaces your own status line inside midna; turn it off to get yours back, at the cost of spend tracking. --mcp-configwith the midna MCP server (settingagents.mcp).--append-system-promptwith a two-line hint that it’s running in midna and can runmidna capabilities(settingagents.system_hint).
Codex gets -c notify=… so midna hears when a turn ends, plus the MCP server and the same hint through -c options. Midna doesn’t use Codex’s hooks, because they need you to trust them first.
Every terminal also gets MIDNA_SESSION, MIDNA_PROJECT and MIDNA_SOCKET in its environment, TERM_PROGRAM=midna, the midna CLI on its PATH, and MIDNA_SKILL pointing at a short guide for agents (midna skill prints it).
Changes to these settings apply to agents started afterwards.
Status
Section titled “Status”Midna shows an agent as working, needs you, done (finished, and you haven’t looked yet) or idle. It reads that from the hooks, the agent’s terminal title and, for permission dialogs, what’s on screen. When Esc or ⌃ C interrupts a turn, the status follows.
Approvals
Section titled “Approvals”Two kinds of approval reach Needs you:
- Midna approvals. A rule said ask for a Claude Code tool call. Claude waits until you answer in midna.
- Permission prompts. The agent is showing its own permission dialog, because no rule decided and its own settings say ask. Approving or denying in midna presses the answer in the dialog for you.
Codex has no hook before tool calls, so midna rules don’t apply to it; its own approval prompts still show up as permission prompts.
Startup dialogs, like Claude’s folder trust question or Codex’s hooks review, don’t become needs-you items yet. Answer them in the terminal.
Claude Code’s spend shows per turn in Insights and on the Today card. Codex doesn’t report cost, so its spend shows as zero.
Sending messages
Section titled “Sending messages”Type in the terminal as usual, use the composer (⇧ ⌘ D) for long prompts, or attach images with ⌘ I. Agents can message other agents with midna send <id> "…", which arrives as one message even across lines, and --image attaches a picture.
Restarting into the same conversation
Section titled “Restarting into the same conversation”The terminal’s restart button, or midna restart <id>, reopens the agent in the same conversation (claude --resume, codex resume). Midna refuses while the agent has background shells or subagents running, because a restart would lose them. In ⌘ K, Restart … when idle waits until the agent is idle with nothing in flight.
When a newer Claude Code is installed than a terminal is running, midna restarts that terminal into the same conversation once it’s idle. Setting agents.restart_on_update: when_idle (the default), ask to get a needs-you note instead, or off.
Letting agents drive midna
Section titled “Letting agents drive midna”Inside midna, agents use the midna CLI or the MCP server to see other terminals, open shells and monitors you can watch, get your attention, add rules, draft triggers and change settings. What they can’t do is in the security model.