# AI Coding

> Source: https://www.allsweb.com/sixpanel/docs/ai-coding
> Markdown for agents: https://www.allsweb.com/sixpanel/docs/ai-coding.md
> Publisher: AllsWeb (www.allsweb.com)

Part of: SixPanel documentation

**What this page is for:** have a coding agent change the code of one project for you.
You write what you want in a chat inside the panel; a coding program runs on your
server, as that project's own account, reads the code, changes it and checks its work.
You see every file it reads and every change it makes, and it works on a **staging
site** first, so the live website is not touched until you move the work there.

AI Coding runs **Claude Code** (Anthropic's coding program) — or **Codex** (OpenAI's)
when the provider you use is a ChatGPT plan. The panel installs the program, keeps it
current and starts it; you never open a terminal for it.

Open **AI Coding** in the panel's menu for the whole server, or **AI Coding** inside a
project or a website to work on that one.

**You need**

- **SixPanel Pro.** Without it the page shows an upgrade card above what it does. See
  **[Your AllsWeb account and SixPanel Pro](https://www.allsweb.com/sixpanel/docs/allsweb-account-and-pro)**.
- The owner's login. A temporary login and the read-only demo cannot use AI Coding.
- A server with enough memory — see [What the server needs](#what-the-server-needs).
- An **AI provider** that can serve coding — see
  [Providers and plans](#providers-and-plans).

**The rule that does not move:** the program works as the project's own account, never
as root, inside that one project. It cannot use `sudo`, and anything it asks the panel
to do — a deploy, a look at the logs — goes through the panel's own checks and
approvals, as for any other AI agent. With Claude Code the panel also refuses the
commands that destroy data; with a ChatGPT plan, Codex's sandbox is the limit — see
[With a ChatGPT plan: Codex](#with-a-chatgpt-plan-codex).

---

## Where it is

- **AI Coding** (panel menu) — for the whole server: what the server needs, the coding
  programs and their versions, the provider in use, every project with its number of
  sessions, and the last sessions. **Open** beside a project takes you to its page.
- **AI Coding** inside a **6amMart project**, and inside a **website** of the kind
  static, Node.js, PHP or WordPress — the chat itself: your sessions on the left, the
  conversation in the middle, where it runs on the right. On a phone the three are
  tabs: **Sessions**, **Conversation**, **Where it runs**.

A **Create with AI** website has no AI Coding page: its **Build with AI** page is the
same thing, with a live preview and Publish. See
**[Create with AI](https://www.allsweb.com/sixpanel/docs/websites-and-apps#create-with-ai)**.

## What the server needs

The server's AI Coding page lists each of these with what your server has and what is
needed:

| | Needed | Works, but slow below |
|---|---|---|
| **Memory** | 2 GB | 4 GB |
| **Free disk** on `/opt` | 1 GB | 3 GB |
| **CPU cores** | — | 2 |
| **Processor type** | amd64 or arm64 | |
| **Linux kernel** | 6.5 or newer | |

When a row says **Not enough**, the page says *Upgrade the server first — at least 4 GB
of memory and 3 GB of free disk for smooth work*, and nothing can be installed or
started until the server has it. A row that says **Low** is a warning: AI Coding works,
long work may be slow.

How many sessions can work at the same moment depends on the memory: one on a small
server, up to four on a large one, and never two in the same project. The page says
how many are working now.

## The coding programs

The panel installs the program the first time it is needed — **Install Claude Code**
on the page, one job, a few minutes — into a folder of its own that no project can
change. Signing in with a ChatGPT plan installs Codex the same way. A program is run
exactly as its publisher ships it: the panel downloads it, checks it against the
publisher's own checksum, starts it once as an unprivileged user, and tries it (see
below) — only then is it put in use, and the version it replaced is kept.

Codex runs a session's commands inside a sandbox, and that sandbox needs the server's
own `bubblewrap` package. The install job installs it from your release's own archive
when the server has none. Where it cannot, the job stops there and says the one command
to run on the server — `apt-get install -y bubblewrap` — and you press **Install**
again after it.

The package alone is not always enough: the server must also let an ordinary user start
a sandbox with it. The install job tries that once, before it tries Codex. Where
bubblewrap cannot start — user namespaces switched off on the server, or a container
guest that does not allow them — the job stops there with what bubblewrap answered and
the one command to check it with. Nothing is installed and no report is sent: the cause
is the server, not the version of Codex, and SixPanel does not change that setting for
you.

Each program has a card on the server's AI Coding page:

- **Version in use** and the **newest on this channel**.
- **Channel** — *Stable* is the tested line; *Latest* gets every new version first.
- **Update by itself** (on by default) — once a day the panel looks for a newer
  version and installs it while no session is working.
- **Check now** — the same, at once.

**Channel** and **Update by itself** are one setting for both programs: change either on
one card and the other card shows the same. Codex has a single line of releases, so the
channel changes nothing for it.

**A newer version is tried before it is used.** The panel runs it through a scripted
session on your server — text, a change that needs your permission, a question, Stop,
continuing a session — without using your provider or any tokens. Only a version that
passes every check replaces the one in use. When one does not pass, AI Coding keeps
working on the version it has, the card says **held back** with the checks that failed,
and the report goes to AllsWeb so that a SixPanel update can follow (*Reported to
AllsWeb*, with the time). With automatic problem reports turned off, the card offers
**Send this report** instead; it carries the program's version and the failed checks,
never a project, a conversation or a file. See
**[Problem reports](https://www.allsweb.com/sixpanel/docs/problem-reports)**.

## Providers and plans

AI Coding uses an AI provider you added on **AI → Providers**. The page shows which
one, its model, and the program it works with; **Change** opens AI → Providers. A new
session can also pick another provider of your list.

There are two kinds, and they differ in one thing you should know:

- **An API key** (Anthropic, or another provider or endpoint that can serve coding).
  **The key never leaves the panel.** The program talks to a door inside the panel,
  which adds the key and passes the request on; the project's account never sees it.
- **A plan — Claude (Pro, Max, Team) or ChatGPT (Codex).** You sign in **once, on
  AI → Providers**, not per project. Anthropic and OpenAI allow a plan to be used only
  inside their own coding program, so **a plan's sign-in is handed to that program,
  which works as the project's own account: while a session is working, the sign-in is
  within that program's reach.** The Claude sign-in can only make model requests, and
  you can end it at claude.ai at any time. A plan serves AI Coding and Create with AI's
  coding — not Tia and not monitoring.

When the provider is a plan that is not signed in (or its sign-in has ended), the
AI Coding page says so and sends you to **AI → Providers**; there is no sign-in on the
AI Coding page itself. A Claude plan's sign-in lasts one year: from two weeks before
its end the provider line here says *Its sign-in ends in … days*, as its row on
AI → Providers and the bell at the top of every page do. See
**[AI providers](https://www.allsweb.com/sixpanel/docs/ai-assistant#providers)** — its **What is the difference?**
puts a plan beside an API key in three lines.

## Start a session

1. Open **AI Coding** in the project or website.
2. On the right, choose **where it runs** — see the next section. **Staging site** is
   chosen for you.
3. Choose the **mode**, and if you like the **model** and the **effort** (more effort
   thinks longer and uses more tokens).
4. Write what you want changed and press **Start** (or **Ctrl+Enter**, **⌘+Enter** on
   a Mac).

The program reads the code first, does the work, and ends by saying what it changed and
how it checked it. Write again to continue: a session remembers its conversation, also
after the panel was restarted. **New session** starts a fresh one; a session can be
renamed or deleted from the list — deleting removes the conversation from the page, not
what it changed in the code.

### What you see

- **Its words**, as they are written.
- **A row for everything it does** — a file it read, a search, a command it ran, a
  change. A change opens to its **diff**, with the lines added and removed.
- **A permission card** when it needs your yes: what it wants to run or change, and
  **Allow**, **Always allow** (for the rest of this session, for that kind of command)
  or **Deny** — with a line for what it should do instead.
- **A question card** when it needs a decision from you.
- **Stop** while it works. What was changed up to that moment stays.
- **Waiting for your approval** when it asked the panel for something the panel asks
  you about (a deploy, for example) — the same card as in the bell at the top.

### Modes

With **Claude Code**:

| Mode | What it does |
|---|---|
| **Ask before changes** | Every file change and every command waits for your Allow. The mode production starts in. |
| **Edit files, ask before commands** | Files are edited without asking; a command still waits. The mode a staging site starts in. |
| **Plan only** | It reads the code and proposes a plan. Nothing is changed. |
| **Bypass permissions** | Nothing is asked. What the panel never allows is still refused. On production the agreement you ticked to work there covers it — nothing more is asked. |

**Codex** has no step that waits for your Allow, so it is not offered the first two. Its
modes are **Plan only**, **Edit files and run commands in the project** (inside the
project's folder, without asking), and **Bypass the sandbox**. The page always shows the
modes of the program your provider works with.

**Rules for this project** (at the bottom right) holds what applies to every session of
the project: commands to always allow, commands to never allow, and standing
instructions such as "write comments in English". What the panel never allows stays
refused whatever is written there.

### How a turn runs

A **turn** is one message of yours and the work the program does for it.

- **As the project's own account**, in the project's code folder — the same account the
  panel's Terminal gives you for that project. It cannot use `sudo`, it cannot read
  another project, and the panel's own files are out of its reach.
- **One turn per project**, and a few at once on the server (one on a small server, up
  to four on a large one). Turns on a ChatGPT plan run one at a time on the whole
  server. A turn that cannot start yet is refused with the reason, and nothing is
  queued: send the message again when the other has finished. One message does wait:
  the first of a session whose staging site was still being made or set up. The session
  says so, and it is sent when the turn in its way has ended.
- **Stop** asks the program to stop, and ends it if it does not. What it changed so far
  stays.
- **A panel update or restart ends a running turn**; the session says so, and your next
  message continues the same conversation.
- **The conversation is kept by the panel**, not in the project: the newest 2,000 events
  of each session. Deleting a project or a staging site deletes the sessions opened on
  its own AI Coding page. A session opened on the project that worked on a staging site
  stays in the project's list after that staging site is deleted, and says so when you
  write in it. Moving a project to another server ends its running turn.

### What it asks you, and what is never allowed

In **Ask before changes** every edit and every command waits for your answer. **Always
allow** keeps the program's own suggestion — for that kind of command, for this session
only: it never adds a folder outside the project and never turns asking off.

With **Claude Code**, some things are never allowed, in any mode: `sudo`, and the
commands that wipe a database or cache its settings by hand (`migrate:fresh`,
`db:wipe`, `config:cache`, `wp db reset` and the like). Your own extra rules are under
**Rules for this project**. **Codex** cannot use `sudo` either, but the panel's list is
not applied to it: its sandbox is the limit — see
[With a ChatGPT plan: Codex](#with-a-chatgpt-plan-codex).

**The `sixpanel` command works inside a session** — status, logs, deploy, commit, sync
— for this one project, whether or not **Let an agent work on the server itself** is
switched on (see
**[An agent on the server, inside one project](https://www.allsweb.com/sixpanel/docs/terminal-and-ssh#an-agent-on-the-server-inside-one-project)**).
What it does shows on the **Activity** page as *via ai:mcp:code:* and the account's name;
anything that cannot be taken back (a promote, a delete, a restore) still waits for your
approval — in the session, and in the bell at the top of every page.

### With a ChatGPT plan: Codex

When the provider is a ChatGPT plan, the work is done by **Codex** — OpenAI's own coding
program — because OpenAI allows a plan only inside that program. The panel installs it,
keeps it current and tries every new version before using it, exactly as for Claude
Code. It differs in five things:

- **None of its modes asks.** *Plan only* reads the project and proposes a plan; no file
  can be written (the panel's own tools still answer — see the next point). *Edit files
  and run commands in the project* edits files inside the project's folder and runs
  commands there without asking. *Bypass the sandbox*: no sandbox, and nothing is
  asked. A session with Codex never shows a permission card or a question card — so
  work on a staging site, as with every session.
- **Its sandbox has no network.** In *Plan only* and *Edit files*, a command Codex runs
  cannot write outside the project's folder and cannot open a connection — not to the
  internet and not to this server's own services. So `composer install`,
  `npm install`, `git fetch` and `git push` do not work there, and neither does the
  `sixpanel` command typed in a shell. The panel's own tools still work, because Codex
  reaches them directly: in *Edit files* all of them — status, logs, what changed,
  commit, deploy, the staging-site tools — and anything of theirs that needs your
  approval waits for you as always. In *Plan only* it is the ones that only read
  (status, logs, what changed): a tool that changes something — a deploy, a commit, a
  setting — is refused there, so *Plan only* changes nothing through the panel either.
  When a step needs the network (a package to install), Codex tells you which command
  it needs: run that turn in *Bypass the sandbox*.
- **No diff, and the answer comes whole.** A file Codex changes is listed by name with
  what happened to it — added, edited or deleted — but not which lines; the staging
  site's *what changed* card shows those. Its answer appears when it is ready, not word
  by word.
- **Rules for this project are read by Claude Code only.** Codex does not apply the
  allow and deny lists, and the session says so when you have any. The same goes for
  the panel's list of commands that are always refused: in *Plan only* and *Edit files*
  Codex's sandbox is the limit, and in *Bypass the sandbox* there is none — choose it on
  production only when you mean it.
- **One Codex turn at a time** on the whole server, across all projects: OpenAI permits
  one user of a plan's sign-in at a time. A second one is refused until the first has
  finished — send the message again then. Codex reports what a conversation has used so
  far; the session shows each turn's own share of it.

## Staging first

A session works on one of two places, and the page says which on every session.

**Staging site (recommended).** The work is done on a private copy of the project —
its own files, its own database, its own address. With a staging site ready, the
session uses it. With none, the session **makes one first**: the ordinary staging site,
on a branch of its own when the project is deployed from git, and your message starts
when it is ready. If another turn is working at that moment — another session of the
same project, or as many turns as this server runs at once — your message waits, the
session says so, and it is sent when that turn has ended. A session that could not run
at all (no provider that is ready, no engine installed) is refused before a staging site
is made for it. Where this server has no temporary address to give a staging site
(no AllsWeb account is connected, or its plan has none), the page asks for **a domain
of your own** right there: point it at this server first, write it in, and the session
makes the staging site on it. See **[Staging & Testing](https://www.allsweb.com/sixpanel/docs/test-copies)**.

*A custom app* — a Node.js app, or a PHP app the panel cannot set up by itself — gets
its copy **not started**: the agent's first job is to point the copy at its own
database, the panel then looks through the whole folder, and when it finds nothing
left that names production the session shows **Start the staging site**. Starting it is
your press, never the agent's — and your word: start it only if the app uses the
staging site's own database and no other, because the panel cannot see a password the
app keeps encrypted or loads from somewhere else.

Where the panel **could not look** — the app's database is not on this panel, or
production's password is one a search cannot find — the session shows no Start. The
agent tells you what comes first (a second database, made where production's is), and
you start the staging site on its **Set up by hand** card on the project's
**Staging & Testing** page, which asks for your tick. See
**[Set up by hand](https://www.allsweb.com/sixpanel/docs/test-copies#set-up-by-hand)**.

**Production, directly.** Offered only where the code does **not** come from git, and
only behind an agreement you tick for that session: *changes are made on the live
website, and a mistake is live at once*. The panel asks you to confirm it is you, and
before the session's first message it saves the database and tells you when the files
were last backed up — run a backup first if that was long ago.

Where the code **does** come from git, production is not edited in place: the next
deploy would refuse or undo the change. The page says so; work on a staging site and
move the work from there.

## Move the work to production

On a staging site that works on a **branch**, the right side of the session shows the
git card of that staging site: the files that changed, **Commit and push**, and how far
production is behind. **Move to production** opens the promote of that card — one job
that backs up production's database, merges the branch, deploys, checks that production
answers, and puts production back if any of that fails. Its result is written into the
session. See
**[Working on a branch and promoting](https://www.allsweb.com/sixpanel/docs/test-copies#working-on-a-branch-and-promoting)**.

Where there is **no git**, the page says that moving the work needs a repository:
connect one on the project's **Deploys** page, then start a staging site on a branch of
its own.

## What it cannot do yet

- **Undo one turn.** A staging site and git are the safety here (Create with AI keeps
  its own Undo).
- **Move a staging site's changes to production without git.**
- **Work while the project is being moved** to another server, or while its staging
  site is being made or refreshed — the page says why, and sessions start again when
  that has finished.
- **Run as root**, or outside the one project it was opened in.

## How to check it worked

- The server's AI Coding page shows **This server has what AI Coding needs** and a
  version on the program's card.
- A session ends with **Done** and the time it took; every change it made is a row you
  can open.
- On a staging site, open the staging address from the right side and look at the
  change before you press **Move to production**.

## If it went wrong

- **"Upgrade the server first"** — the server has less than 2 GB of memory or 1 GB of
  free disk. Add memory or free space; nothing else unblocks it.
- **"… is not installed on this server yet"** — press **Install**. If the job fails,
  its log says why; a version already in use stays in use.
- **"… is not ready for coding"** — the provider is a plan that is not signed in, or a
  provider whose last check failed. Open **AI → Providers**.
- **A newer version is held back** — nothing to do: AI Coding works on the version in
  use. The server's AI Coding page lists the checks that did not pass.
- **A turn "Stopped with an error"** — the sentence under it is the reason (the
  provider was overloaded, the limit of your plan was reached, …). Send the message
  again; the session continues where it was.
- **The panel was restarted while it worked** — that turn ended; the session says so,
  and your next message continues it.
