Private machines. Agent-ready.
Give AI agents scoped, temporary access to real machines without SSH credentials, inbound ports or a VPN.
Linux · macOS · Windows · outbound connections only
Default workspace
3 machines · 1 active access
Machines
production-api
linux · x64
studio-mac
darwin · arm64
rpi5
linux · arm64
Policy decision
Allowedagent deploy-agent
machine production-api
capability process.exec
expires in 42 minutes
event operation.created
decision allowedAgent
scoped token
Odyshell
policy + relay
Machine
outbound client
One route. Explicit authority.
The web owns people and access. The CLI requests approval. The client on each machine maintains the outbound connection.
- 01
Run ods login
The CLI creates a short-lived device code and opens the Odyshell web app.
- 02
Approve in the browser
Clerk confirms the user and organization. Odyshell binds the CLI to that workspace.
- 03
Connect a machine
A one-time enrollment token gives the local client an identity. It connects outbound and waits.
Control lives outside the model.
Prompts can ask. Odyshell decides. Machine identity, capability checks, expiry and path boundaries are enforced before an operation reaches the client.
| Boundary | Odyshell uses |
|---|---|
| Connectivity | Outbound from the machine |
| Identity | Machine key + workspace token |
| Authority | Capabilities and machine scopes |
| Time | Expiring agent sessions |
| Evidence | Operation metadata and results |
Start with the useful limit.
Plans limit managed capacity. They never weaken execution policy or shorten the audit trail to create an upgrade.