Message your agent from the Messages app on your iPhone, iPad, Watch or the Mac itself. There is no bot to register and no token: the gateway talks to Messages.app on the same Mac, so the conversation is not relayed through anyone else’s server. You can message your own handle from another device.
What has been run on which harness is on the verification log; a feature without a dated row there is unverified.
What works from iMessage today
- Chat: you send a task, the agent answers with its final reply, split across messages if it is long. A typing indicator shows while it works; tool activity stays in the gateway.
- Commands:
/new,/compactand/help. - Code blocks pass through exactly, so what you copy out of a message is what the agent wrote.
Set it up
- Run the gateway on the Mac that is signed in to Messages (macOS 14 or newer). The channel refuses to start anywhere else, because sends would fail.
- Install the
imsgbridge, a small open-source CLI:brew install steipete/tap/imsg - Grant two permissions to whatever launches the gateway: Full Disk Access, to read the Messages database, and Automation → Messages, to send.
- Allow your own handle in
config.json, a phone number or your Apple Account email:"imessage": { "enabled": true, "allowed_handles": ["+15551234567"] } - Restart the gateway and say hi:
warding restart
Who can reach it
Anyone who knows your number can text it, so the allow-list is the whole gate: an empty one authorises nobody, and a message from an unlisted handle gets no reply at all. Group chats are refused, because a reply would deliver tool output to everyone in the thread.
Why not the official plugin?
Anthropic ships a Channels plugin for Claude Code that covers Telegram, Discord and iMessage. If you use only Claude Code and you are happy to keep a session open, it is less setup than this, and it is Anthropic's own.
| Anthropic's Channels plugin | Warding | |
|---|---|---|
| Harness | Claude Code only | the one you dock for chat: Claude Code, Codex, Cursor, Goose, Kimi, OpenCode and others |
| When messages arrive | while that Claude Code session is open, launched with the channels flag | while the gateway runs, which it does as a service on your box |
| Apps | Telegram, Discord, iMessage | 10; 5 with approve buttons, 1 typed, 4 chat-only |
| Approvals in iMessage | see Anthropic's documentation | none in this app yet; gated tool calls are declined unless auto-approve is on |
| Setup | a plugin inside Claude Code | a gateway on your machine plus this app's credentials |
Source: MacStories' hands-on with Claude Code's Telegram and Discord integrations. The longer comparison with Anthropic's built-ins covers Routines and Remote Control too.
Limits, stated plainly
- Owner-only. One person runs this gateway, as themselves, with their files and credentials. There is no shared or team mode.
- One harness for chat. The docked harness answers every channel; switching is one setting. A spawned subagent can be routed to another installed harness; that is registered, not verified.
- Mac only, and the gateway must run on that Mac, which has to stay awake.
- No attachments, tapbacks, edits or group chats in this version.
- Creating jobs from chat (and subagents, and questions the agent asks you mid-turn) relies on the agent’s own tools, which reach kiro-cli only today. On other harnesses, schedule from the dashboard or the CLI; see the schedule page.
Approvals: chat only · All ten channels · Full reference publication pending