Set Up Remote Access to Your Mac from an iPad Mini
This is the second half of the Productivity Coach’s setup. The first half gave you the hooks that write your day down and, if you wanted one, a private GitHub repository to back it up. The agent told you it was not finished. This is the rest.
By the end of this guide, the environment you built is reachable from any device you own. Your Mac stays home doing the work. What you carry is a window onto it, and the window can weigh 300 grams.
One uninterrupted hour, and the agent does most of the typing. What needs your hands is a Tailscale login, an App Store install, and a couple of approvals in System Settings.
Bought Remote Setup on its own? Everything here applies to you too, with two differences: the command that starts the agent, below, and what happens first. That agent assumes nothing about your Mac. Before any of this it installs the terminal tools and puts the folder you work in on a private GitHub repository, asking before each step.
What you are actually building
Three things, and it is worth knowing why each one exists before you start.
A private tunnel. Your Mac becomes reachable from your own devices and invisible to everyone else. This is not a firewall rule or a port you open — it is a network that only your devices can join.
A session that outlives the connection. Right now, if you SSH into a machine and the wifi drops, the session dies and takes the work with it. You reconnect to a blank cursor. What you are installing instead keeps the session running on the Mac whether anything is connected to it or not.
A push that works from the small device. Only if your folder backs up to GitHub. Credential problems tend to surface the first time you push from somewhere new, so this gets checked before you hit it.
Before you start
You need a Mac with Homebrew, which the Knowledge Work Coach installed (the standalone Remote Setup agent installs it for you), and a second device. Your phone counts. An iPad Mini is nicer.
You also need an SSH client on that second device. Termius is the one this guide assumes, free from the App Store, and the agent will walk you through it. Any SSH client works if you have a preference.
And a free Tailscale account. If you do not have one, the agent waits while you make it.
Stay in the Productivity Coach and tell it to continue with remote access:
/secondbrainos:agent_productivity_claude_code_coach
If you bought Remote Setup on its own, start that agent instead:
/secondbrainos:agent_ipad_mini_remote_claude_code_setup
Either way it asks one question at a time. Let it.
Step 1 — What is missing gets installed
The agent checks what you already have and installs only the gaps: Tailscale, as the app, and tmux. Claude Code, git, Homebrew and your hooks are already there and get skipped.
At the end of this step it verifies versions, so you will see confirmation rather than a promise.
What needs your hands: the Tailscale login. It opens a browser, you sign in, and the Mac joins your private network. Then install Tailscale on the second device and sign in with the same account.
Step 2 — The tunnel, and locking SSH to it
This is the step that matters most for safety, so it is worth understanding rather than skimming.
The obvious way to reach your Mac from elsewhere is to enable Remote Login and open port 22 to the internet. Do not do this, and the agent will not let you. A machine with port 22 open to the world gets thousands of automated password attempts within hours. Nobody is targeting you; scripts knock on every door on the internet continuously.
Instead, Tailscale creates a private network between your own devices. Your Mac gets an address in the 100.x.x.x range that only your devices can reach. The door opens from inside the house.
Then SSH gets restricted to that network only. On macOS this is a subtlety worth knowing, because the obvious approach silently does nothing:
macOS ignores
ListenAddressin the SSH config, because SSH is managed bylaunchdrather than by the config file. Setting it looks like it worked and changes nothing. The setting that does work isAllowUsers, restricted to your Tailscale address range.
The agent handles this, adding a line that permits your user only from Tailscale addresses. After any change to the SSH config, Remote Login has to be toggled off and back on in System Settings → General → Sharing. Editing the file is not enough; the change does not take effect until SSH restarts.
Checkpoint: from the second device, ssh to the Mac’s Tailscale address. You should get in. From any other network, you should not be reachable at all.
Step 3 — Sessions that survive the connection dropping
tmux is the piece that makes remote work feel solid rather than fragile. It has been doing this job on servers for thirty years.
The agent configures three things:
Auto-attach on login. When you SSH in, you land in a session called main — the same one, every time, exactly as you left it. If it does not exist yet, it gets created.
Named sessions per project. So the client work and the writing are not sharing one screen. The default one is called main, which is what you land in unless you ask for otherwise.
A terminal that behaves like a window. Mouse support on, so you can scroll and click between panes instead of memorising keystrokes, and a 10,000-line scrollback so the output from an hour ago is still there. Worth knowing: scrolling inside tmux needs Ctrl+B then [, and q to come back out. That one keystroke is the most common early stumble, and mouse support is what makes it mostly unnecessary.
Three connection behaviours, which sound fiddly but save real annoyance later:
| You want | How |
|---|---|
| To resume where you left off | Connect normally. This is the default. |
| A fresh session, leaving the old one running | Set TMUX_SESSION=new in your SSH client’s environment variables |
| A plain shell with no tmux, to list or kill sessions | Set TMUX_SESSION=skip |
That third one is worth setting up as a separate saved host in Termius. When you have three sessions running and want to tidy up, you need a way in that does not immediately attach to one of them.
For these variables to reach the Mac at all, SSH has to be told to accept them (AcceptEnv). The agent adds that and reminds you to toggle Remote Login again.
The agent sets up all three as separate saved hosts, so switching behaviour is picking a different entry rather than editing a variable.
One thing worth knowing, because it is not obvious: more than one device can attach to the same session at the same time, and both see and control the same terminal live. Start something on the Mac, pick up the iPad, and you are looking at the same screen — not a copy of it. Useful for watching a long job from the sofa, and useful for showing someone what you are doing without screen sharing.
Optional: if you have a Slack webhook, the agent can send you a notification on every SSH login, identifying which device connected by name rather than by IP. Genuinely reassuring the first week, and a real security signal after that.
Step 4 — The push, checked from the small device
If you declined GitHub in the Productivity Coach, there is nothing to check here. The agent says so in one line and your remote access is complete without it. Skip to Step 5.
If your folder is on GitHub, this is the check that catches the failure nobody expects.
By default, macOS keeps your GitHub login in the Keychain, and the Keychain cannot be reached from a remote session. So a push works at your desk and fails from the iPad, with an authentication error that makes no sense because “it works on my Mac”. The GitHub step you did earlier stored the login in a file for exactly this reason. Here is where that gets proved.
From the remote session, the agent checks the GitHub login and runs a push that authenticates with GitHub and writes nothing. If both pass, you can commit and push from the small device and the automatic backup of your progress files works no matter where you closed the session from.
If it fails, the agent moves the login to a file and repairs anything fighting it, then runs the check again. Both the Productivity Coach and the standalone Remote Setup agent carry the steps for that.
Step 5 — The round trip that proves it
The setup is not finished when the software is installed. It is finished when you have done this, in order:
- Disconnect from the Mac entirely.
- Pick up the second device. Connect over Tailscale.
- Attach to your tmux session.
- Run one Claude Code command — something small, but real.
- Disconnect mid-task. Close the app. Lock the device.
- Reconnect.
- Find the session exactly where you left it, including anything you typed but never sent.
The agent will not declare this done until you have done that. It matters because every individual piece can look correct while the combination still fails, and the only way to know is to break the connection on purpose.
Troubleshooting
| Symptom | Cause | Fix |
|---|---|---|
| SSH config edited, nothing changed | SSH did not restart | Toggle Remote Login off and on in System Settings → Sharing |
ListenAddress appears to be ignored |
It is — macOS manages SSH via launchd |
Use AllowUsers restricted to 100.* instead |
| Connection works on wifi, not on mobile data | First connections may route via a relay | Run tailscale ping <address> to check direct vs relayed; it settles after NAT traversal |
TMUX_SESSION has no effect |
SSH is not accepting the variable | Confirm AcceptEnv TMUX_SESSION is in the SSH config, then restart Remote Login |
| Landing in a new session every time | Auto-attach not in ~/.zshrc, or placed after an interactive-only block |
Check with grep TMUX_SESSION ~/.zshrc |
| Push fails from the iPad but works on the Mac | GitHub login is in the macOS Keychain, or old credentials are answering first | Ask the agent to move the GitHub login to a file; it has a cleanup step if something older is in the way |
| Cannot reach the Mac at all | Tailscale not running, or the Mac is asleep | Check Tailscale is connected on both ends; set the Mac to not sleep when plugged in |
no server running on /tmp/tmux-*/default |
No sessions exist yet | tmux new -s main |
A session is listed as (dead) |
The shell inside it exited | tmux kill-session -t <name>, then reconnect |
| Screen looks garbled after rotating the iPad | tmux has not redrawn | Detach and reattach |
One setting worth changing while you are here: in System Settings → Energy, stop the Mac sleeping when plugged in. A sleeping Mac is not reachable, and the most common “it stopped working” report is a lid that was closed.
What you can do now
Everything. That is the point, and it is worth being specific about it.
Every command that worked on the Mac works from the small device. Merge the contracts. Compress the photo. Read forty PDFs and search all of them for one clause. Query the spreadsheet Excel refuses to open. Run a six-program skill chain that renders a report and emails it. All of it executes on the machine at home, plugged in and cooled, while you hold something the size of a paperback.
Your notes are there too, searchable by meaning, because the index lives on the Mac alongside them.
The heavy work and the heavy device stopped being the same object.
What this does not do
On its own, Remote Setup does not write your recaps, your weekly strategy or your retros. That is the Productivity Coach, which includes everything in this guide as part of its own setup. If you are going to want both, buy that one.
It does not set up GitHub Actions runners, PR workflows or anything else in the coding direction. Different problem, different product.
And it does not make your Mac a server. This is remote access to a machine you own, for you, from your own devices — which is exactly why it is safe.
What is next
The Productivity Coach is now fully set up. Post 4 in this series is what all of it was for: connecting Todoist, your first daily file, the weekly recap and its one question, the monthly recap that names your patterns, the strategy file and the week’s tasks.
Fair warning about this one though: working from an iPad Mini at 3am because the idea arrived and the Mac is in the other room is genuinely addictive. Mine lives in a backpack for that reason.
