🔨 AndrewBuild

Claude sends code, Andrew's Mac builds it. Nothing runs until Andrew approves the session on the Mac itself.

How a session works

  1. Claude calls POST /start-session and gets a session_id, a private secret, and a mac_command.
  2. Andrew runs mac_command in Terminal. The agent shows who asked (IP, location, user agent) and asks him to type yes.
  3. The agent prints a 4-digit code. Andrew gives it to Claude, and Claude activates the session with it plus the secret.
  4. Claude uploads the project and queues jobs. Andrew watches each one run live in Terminal, and Ctrl+C kills the session.

API for Claude

All session calls send Authorization: Bearer $SECRET. Full instructions: /skill.

# 1. start
curl -s -X POST https://build.707andreww.site/start-session -H 'Content-Type: application/json' -d '{"label":"MyApp debug build"}'

# 2. activate with Andrew's code
curl -s -X POST https://build.707andreww.site/api/sessions/$SID/activate -H "Authorization: Bearer $SECRET" -H 'Content-Type: application/json' -d '{"code":"1234"}'

# 3. send the project (lands in ~/AndrewBuild/$SID on the Mac)
tar czf - --exclude .git --exclude build --exclude DerivedData . | \
  curl -s -X PUT "https://build.707andreww.site/api/sessions/$SID/upload?clean=1" -H "Authorization: Bearer $SECRET" --data-binary @-

# 4. queue a job, then wait for it
curl -s -X POST https://build.707andreww.site/api/sessions/$SID/jobs -H "Authorization: Bearer $SECRET" -H 'Content-Type: application/json' \
  -d '{"type":"run","argv":["xcodebuild","-list"]}'
curl -s "https://build.707andreww.site/api/sessions/$SID/jobs/$JOB?wait=25" -H "Authorization: Bearer $SECRET"

# other job types
{"type":"inspect","path":"build/Build/Products/Debug-iphonesimulator/MyApp.app"}
{"type":"screenshot"}            # booted simulator -> artifact
{"type":"cleanup"}               # delete the Mac folder, keep session

# 5. grab artifacts, end the session
curl -s -o shot.png "https://build.707andreww.site/api/sessions/$SID/artifacts/$NAME" -H "Authorization: Bearer $SECRET"
curl -s -X DELETE "https://build.707andreww.site/api/sessions/$SID?mac=delete" -H "Authorization: Bearer $SECRET"   # or ?mac=keep

What the Mac agent allows

Commands: xcodebuild, xcrun (simctl, swift, lipo, otool and a few other tools), swift, swiftc, xcodegen, codesign, lipo, otool, file, plutil, du, ls. There's no shell. Path arguments must stay inside ~/AndrewBuild/<session> or Xcode's own folders.

Heads up: building a project runs that project's own code (build phase scripts, Swift package plugins). The allowlist stops stray commands. It doesn't make untrusted projects safe to build.