The timing couldn't have been much worse—or perhaps more deliberate.
On April 12, a Kuwait-based developer who goes by halfwhey pushed an open-source project called Claudraband to GitHub, promising to give Anthropic's Claude Code the session persistence and remote-control features the company hasn't yet built itself. By April 13, the repository had collected 170 stars and seven forks. A post on Hacker News drew developers eager to extend their workflows beyond what the official tool allows.
But Claudraband arrived at a precarious moment. Just days earlier, on April 4, Anthropic had tightened the screws on third-party tools that access its AI models, blocking several projects outright and leaving others in a regulatory fog. The new wrapper operates in what some observers are calling legally murky territory—its author insists it doesn't violate Anthropic's rules, but the company's recent enforcement suggests otherwise.
Whether Claudraband represents innovation at the edges or a test case for how far Anthropic will let developers push remains to be seen.
What It Actually Does
At its core, Claudraband wraps the official Claude Code terminal interface and adds the features power users have been asking for. That includes persistent sessions via tmux or an experimental xterm.js backend, meaning your work survives when you close the terminal. Sessions live under ~/.claudraband/, and you can resume them later—even respond to pending permission prompts through a --select flag.
The tool also runs an HTTP daemon for headless and remote control. Documented endpoints let you list sessions, resume them, handle permissions, and stream events via Server-Sent Events. For developers who want to orchestrate Claude Code programmatically without rebuilding the entire stack, that's the appeal.
Then there's an ACP server mode that hooks into editors like Zed and Toad. Zed itself announced ACP support roughly seven months back, and Claudraband positions itself as a bridge—editors can drive a real Claude Code session while keeping continuity intact.
Finally, it ships as a TypeScript library. The createClaudraband function accepts parameters for model selection, permission modes, terminal backend, and logging levels. Methods include startSession, resumeSession, listSessions, plus per-session operations like prompt, awaitTurn, and interrupt. For one-off tasks, you can simply run npx @halfwhey/claudraband "review the staged diff" and be done with it. The library bundles Claude Code version 2.1.96 by default.
The Architecture Gambit

Halfwhey's README emphasizes what the project doesn't do as much as what it does. "We do not touch OAuth and do not bypass the Claude Code TUI," it states plainly. "You must authenticate through Claude Code, and every interaction runs through a real Claude Code session."
That design choice matters a great deal. Instead of spoofing credentials or intercepting API calls—tactics that landed other projects in Anthropic's crosshairs—Claudraband automates the official terminal interface through local terminal multiplexers. The tmux backend is considered stable and first-class. The xterm.js option is experimental, slower, intended mostly for headless fallback.
Permission handling stays within the same framework. Developers can choose from modes like default, plan, auto, acceptEdits, or—more controversially—dontAsk and bypassPermissions, both flagged as dangerous in the docs. The HTTP daemon surfaces permission requests at GET /sessions/:id/pending-question and accepts responses via POST /sessions/:id/permission.
On launch day, halfwhey pushed six versions in a single afternoon. Version 0.2.0 went out at 15:20. Version 0.6.1 landed at 20:43. That kind of velocity signals either impressive productivity or interface churn, depending on your perspective. Early adopters should brace for change.
Anthropic's Gray Zone
Anthropic has spent the past few months drawing boundaries around how third parties can interact with Claude. In February, The Register reported that the company revised its legal terms to prohibit third-party harnesses used with Claude subscriptions, citing concerns about spoofed clients and missing telemetry signals.
The enforcement intensified in early April. On April 4, Anthropic blocked third-party agent tools like OpenClaw from subscription usage outright. TechRadar Pro and Axios covered the crackdown, and Reddit threads filled with reports of bans and account blocks for users running scripts or wrappers with consumer OAuth tokens.
Eight days later, Claudraband launched.
The project's architecture arguably sidesteps some of Anthropic's stated concerns. It doesn't manipulate OAuth tokens. It doesn't pretend to be an official client. Every command flows through a legitimate, authenticated Claude Code session. The wrapper simply drives that session through documented terminal interfaces and exposes programmatic hooks.
But that technical distinction may not matter much to Anthropic's policy team. The company's guidance around "third-party harnesses" remains broad and vaguely worded, and recent enforcement actions suggest a willingness to sweep aggressively. The Agent Wars blog summary from April 12 called Claudraband's legal position "murky," and the project's README contains no safe-harbor statement from Anthropic—no official blessing, no informal nod.
It exists in the space where innovation meets enforcement. And that space has been shrinking.
The Crowded Field

Claudraband isn't alone. A small constellation of community-built interfaces has sprung up around Claude Code in recent months: claude-code-webui, claudeCodeUI, Claudia GUI, Claudeck, Glyphic. Most target front-end pain points—web access, mobile support, cost tracking, settings tweaks.
Claudraband takes a different tack. It focuses on workflow automation: the HTTP REST interface for managing existing sessions, the TypeScript library for orchestration, the ACP server for editor integration. It's infrastructure for power users building custom tooling, not a UI facelift.
That positioning aligns, oddly enough, with signals from Anthropic itself. The company's official Help Center published "Claude Code power user tips" just two days before Claudraband's launch, covering parallel sessions, worktrees, hooks, and voice input. Claude Code version 2.1.90 added /powerup interactive lessons, as noted in discussions on Reddit. Another recent update brought "computer use" capabilities to the CLI, letting Claude control apps and UI for testing purposes.
The product is clearly moving toward more sophisticated use cases. Whether Anthropic plans to support third-party automation in that future—or keep advanced capabilities locked inside first-party walls—remains anybody's guess.
What Developers Need to Know

Installation follows standard npm conventions: npm install -g @halfwhey/claudraband for global access, or one-off execution via npx @halfwhey/claudraband. The package installs both claudraband and cband aliases for convenience.
Documentation spans three detailed guides covering CLI commands, library API, and daemon endpoints. Examples walk through persistent local sessions, daemon-backed workflows, and ACP server setup. The library quick-start demonstrates session creation, prompting, and detachment in just a few lines of code.
Caveats abound, though. The xterm backend carries an "experimental" label. Interface stability will likely remain a moving target given the launch-day release cadence. And most importantly, users operate without any real clarity on whether their usage complies with Anthropic's terms of service.
Halfwhey's GitHub account was created on March 20, less than a month before the project went live. The code is released under the MIT license, with explicit framing as a personal, ad-hoc tool rather than an official SDK or supported product. That language might offer some legal cover. It might not.
For developers already knee-deep in Claude Code workflows—especially those juggling multiple sessions, building editor integrations, or orchestrating automated testing—Claudraband offers capabilities the official product simply doesn't provide. Whether those capabilities come with acceptable risk depends on Anthropic's next enforcement move and your individual tolerance for operating in undefined policy space.
Some will see it as a necessary workaround. Others will view it as poking a bear that's already shown its claws. Both perspectives have merit.
The tool exists. The demand appears genuine. The rules remain ambiguous. And in the world of AI tooling right now, that combination tends to produce interesting outcomes—one way or another.
