# Admin UI

> See and edit this machine's Claude Code setup in the browser.

## Open it

```sh
aisync ui
```

A browser opens with this machine's config folders (`~/.claude`, `~/.claude-*`) on the left. Press Ctrl+C in the terminal to stop it.

| Tab | What you can do |
|---|---|
| Overview | Sync state, hardcoded-token findings, Diff, Pull, Push, Capture |
| MCP servers | Add, edit, delete servers. Tokens show as `{{secret:name}}` |
| Files | View, edit, add and delete CLAUDE.md, skills, agents and commands |
| settings.json | Saved after a JSON syntax check |
| Secrets | Names and where they're used; add, replace, delete |

Changes in the UI apply to this machine's files. To share them with other machines, press Push on the Overview tab.

## Tokens stay off the screen

- Stored token values are never sent to the browser; you see names and where they're used.
- A plain-text token still in an MCP server is masked on the page and put back when you save.
- To save a server that has a plain-text token, tick "Move secrets to the encrypted store". The token then moves to the store and the server is saved with a reference.
- There is no way to read a token value (`secret get`) in the UI. Use the terminal if you must.

## Access

- It listens on `127.0.0.1` only, and every request needs the token from the link printed at start, which is new each time.
- Requests from other websites fail the Host and Origin checks.
- Only files aisync manages (settings files, skills, agents and so on) can be written. Your login and conversation history can't.
