Consilium for VS Code
Share the Claude Code session of the folder you have open, from a button in the
status bar. No terminal.
Español más abajo — see Consilium para VS Code.
What it does, exactly
When you press Share session:
- It takes the open folder as
SESSION_WORKDIR — that is "the shared project".
- It starts the
runner on your machine, pointing at the room you configured.
- It gives you the invitation link, ready to copy.
Whoever receives the link enters through the browser, writes, and their messages
are injected into your session with their name in front.
What it does NOT do
It does not run Claude in the cloud. Claude runs here, on your machine, under
your subscription and over your files. The room (Vercel, or wherever you deploy
it) only relays messages; it never talks to Claude.
That is why this process has to be alive: if you close VS Code or press "stop
sharing", the room is left without a session.
Your sessions never get lost
A Consilium invitation link is the only copy that exists — the relay only stores
its hash. So everything that passes through a link is written down:
Consilium: my sessions lists every room you can reopen — the ones you
host and the ones you joined — and lets you go back in, open them in the
browser, copy the link, rename them, or drop them. It works without being
connected to anything, which is the case that matters: you closed the window
and you no longer remember the link.
- Joining is resumed on its own. VS Code reloads the extension host by itself
(when updating an extension, reloading the window, waking from sleep). Sharing
already survived that; being inside someone else's room now does too.
Consilium: new side session opens another room over the same project, with
its own conversation, and saves its link on the spot. Opened from the browser,
that link reaches only the tab that asked for it — and gets lost with it.
- Paste a link from that same list to add a session you were given, or one
you opened elsewhere.
Language
The extension speaks English and Spanish. The first time it starts it asks which
one you want; after that it lives in consilium.language and
Consilium: language / idioma changes it whenever you like.
auto follows the editor. One caveat: the command names in the palette always
follow the editor's display language, because VS Code resolves those before the
extension runs — everything else (dialogs, menus, notifications, the log) follows
your setting.
Installation
The extension is self-contained: it ships its own bundled runner, so you do
not need to clone anything to use it.
From the Marketplace, or with the .vsix your own deployment serves:
Extensions → ⋯ → Install from VSIX…
The first time you share, it downloads the Claude engine (~250 MB) into the
extension's storage. It is deliberately not inside the package: it is a different
binary per operating system, so each machine fetches its own. It happens only
once, and it needs node and npm on the PATH.
You need Claude Code and your subscription in order to share. To join
someone else's project you need none of that: the link they send you is enough.
First run
The first time it asks for two things: your room's URL and its RUNNER_SECRET.
Both are stored (the secret, encrypted) and are not asked for again on that
machine.
The order it looks in:
- VS Code's encrypted secret storage (where it lands after the first time).
- The clone's
.env, if you have configured consilium.repoPath.
- It asks you.
The secret is not stored in settings.json: it goes to the editor's
encrypted storage. If you had the previous version, it is migrated
automatically and removed from the setting. Consilium: forget the stored secret deletes it if you want to change it.
Settings
| Setting |
Default |
What for |
consilium.language |
auto |
Language of the extension's own messages |
consilium.relayUrl |
— |
Room URL |
consilium.repoPath |
— |
Development only: use the runner from a clone |
consilium.model |
claude-opus-5 |
Model for the session |
consilium.toolAllowlist |
Read,Glob,Grep,TodoWrite |
Tools that do not ask for permission |
consilium.shareOnStartup |
false |
Share when a folder is opened |
consilium.whoApproves |
writers |
Who can approve tools |
consilium.autoApprove |
off |
Permanent automatic approval |
About permissions
Everything not in consilium.toolAllowlist —Write, Edit, Bash…— asks for
permission before running, with a banner in the room. With no answer within 120
seconds, it is denied.
Who can approve is up to you, via consilium.whoApproves or from the button's
menu → Who approves tools:
| Value |
Who approves |
writers (default) |
you and anyone with a write link |
host |
only you |
A read-only link never approves. Keep in mind what you are granting: approving a
Bash runs a command on your machine, with your credentials and your files.
Widening the allowlist is a deliberate decision: whatever you add there stops
asking for permission for every participant, not just for you.
Security
- Use user settings, not workspace ones, so nothing ends up in a repository.
- If you have
ANTHROPIC_API_KEY in the environment, the extension warns you and
the runner refuses to start: it would bill against the API instead of using
your subscription.
- Anyone entering the room as
host can approve permissions on your machine. On
a deployment reachable from the internet, set AUTH_MODE=token in the room.
Consilium para VS Code
Comparte la sesión de Claude Code de la carpeta que tengas abierta, desde un
botón en la barra de estado. Sin terminal.
Qué hace exactamente
Al pulsar Compartir sesión:
- Toma la carpeta abierta como
SESSION_WORKDIR — eso es «el proyecto compartido».
- Arranca el
runner en tu máquina, apuntando a la sala que configuraste.
- Te da el enlace de invitación, listo para copiar.
Quien reciba el enlace entra por el navegador, escribe, y sus mensajes se
inyectan en tu sesión con su nombre por delante.
Qué NO hace
No ejecuta Claude en la nube. Claude corre aquí, en tu máquina, bajo tu
suscripción y sobre tus ficheros. La sala (Vercel o donde la despliegues) solo
reparte mensajes; nunca habla con Claude.
Por eso hace falta que este proceso esté vivo: si cierras VS Code o pulsas
«dejar de compartir», la sala se queda sin sesión.
Tus sesiones no se pierden
Un enlace de invitación de Consilium es la única copia que existe — el relay solo
guarda su hash. Así que todo lo que pasa por un enlace queda anotado:
Consilium: mis sesiones enseña todas las salas que puedes reabrir —las
que compartes tú y aquellas en las que has entrado— y deja volver a entrar,
abrirlas en el navegador, copiar el enlace, cambiarles el nombre o quitarlas.
Funciona sin estar conectado a nada, que es el caso que importa: cerraste
la ventana y ya no te acuerdas del enlace.
- Estar dentro se retoma solo. VS Code recarga el host de extensiones por su
cuenta —al actualizar una extensión, al recargar la ventana, al volver de
suspender—. Compartir ya sobrevivía a eso; estar en la sala de otra persona,
ahora también.
Consilium: nueva sesión aparte abre otra sala sobre el mismo proyecto,
con su propia conversación, y guarda su enlace en el momento. Abierta desde el
navegador, ese enlace llega solo a la pestaña que lo pidió — y se pierde con ella.
- Pegar un enlace desde esa misma lista añade una sesión que te hayan pasado,
o una que abriste en otro sitio.
Idioma
La extensión habla inglés y español. La primera vez que arranca pregunta cuál
quieres; después vive en consilium.language y
Consilium: idioma / language lo cambia cuando quieras.
auto sigue al editor. Un matiz: los nombres de los comandos en la paleta siguen
siempre al idioma del editor, porque VS Code los resuelve antes de que la
extensión arranque — todo lo demás (diálogos, menús, avisos, el registro) sigue a
tu ajuste.
Instalación
La extensión es autónoma: trae su propio runner empaquetado, así que no hace
falta clonar nada para usarla.
Desde el Marketplace, o con el .vsix que sirve tu propia instalación:
Extensiones → ⋯ → Install from VSIX…
La primera vez que compartas descargará el motor de Claude (~250 MB) en el
almacén de la extensión. No va dentro del paquete a propósito: es un binario
distinto por sistema operativo, y así cada máquina se trae el suyo. Solo pasa
una vez; hace falta tener node y npm en el PATH.
Necesitas Claude Code y tu suscripción para compartir. Para unirte al
proyecto de otra persona no hace falta nada de eso: basta el enlace que te pasen.
Primer uso
La primera vez pide dos datos: la URL de tu sala y su RUNNER_SECRET. Quedan
guardados (el secreto, cifrado) y no se vuelven a pedir en esa máquina.
El orden en el que busca:
- Almacén cifrado de VS Code (donde queda tras la primera vez).
.env del clon, si has configurado consilium.repoPath.
- Te lo pregunta.
El secreto no se guarda en settings.json: va al almacén cifrado del
editor. Si tenías la versión anterior, se migra solo y se borra del ajuste.
Consilium: olvidar el secreto guardado lo borra si quieres cambiarlo.
Ajustes
| Ajuste |
Por defecto |
Para qué |
consilium.language |
auto |
Idioma de los mensajes de la extensión |
consilium.relayUrl |
— |
URL de la sala |
consilium.repoPath |
— |
Solo desarrollo: usar el runner de un clon |
consilium.model |
claude-opus-5 |
Modelo de la sesión |
consilium.toolAllowlist |
Read,Glob,Grep,TodoWrite |
Herramientas que no piden permiso |
consilium.shareOnStartup |
false |
Compartir al abrir una carpeta |
consilium.whoApproves |
writers |
Quién puede aprobar herramientas |
consilium.autoApprove |
off |
Aprobación automática permanente |
Sobre los permisos
Todo lo que no esté en consilium.toolAllowlist —Write, Edit, Bash…—
pide permiso antes de ejecutarse, con un banner en la sala. Sin respuesta en
120 segundos, se deniega.
Quién puede aprobar lo decides tú con consilium.whoApproves, o desde el menú
del botón → Quién aprueba herramientas:
| Valor |
Quién aprueba |
writers (por defecto) |
tú y quien tenga enlace de escritura |
host |
solo tú |
Un enlace de solo lectura no aprueba nunca. Ten presente qué estás concediendo:
aprobar un Bash ejecuta un comando en tu máquina, con tus credenciales y
tus ficheros.
Ampliar la allowlist es una decisión consciente: lo que añadas ahí deja de
pedir permiso para todos los participantes, no solo para ti.
Seguridad
- Usa los ajustes de usuario, no los del espacio de trabajo, para que nada
acabe en un repositorio.
- Si tienes
ANTHROPIC_API_KEY en el entorno, la extensión te avisa y el runner
se niega a arrancar: facturaría contra la API en vez de usar tu suscripción.
- Quien entre en la sala como
host puede aprobar permisos sobre tu máquina.
En un despliegue accesible desde internet, pon AUTH_MODE=token en la sala.