Odyshell
Open infrastructure for AI agents

Private machines. Agent-ready.

Give AI agents scoped, temporary access to real machines without SSH credentials, inbound ports or a VPN.

Linux · macOS · Windows · outbound connections only

Default workspace

3 machines · 1 active access

Free

Machines

production-api

linux · x64

studio-mac

darwin · arm64

rpi5

linux · arm64

Policy decision

Allowed
agent       deploy-agent
machine     production-api
capability  process.exec
expires     in 42 minutes

event       operation.created
decision    allowed

Agent

scoped token

Odyshell

policy + relay

Machine

outbound client

One route. Explicit authority.

The web owns people and access. The CLI requests approval. The client on each machine maintains the outbound connection.

  1. 01

    Run ods login

    The CLI creates a short-lived device code and opens the Odyshell web app.

  2. 02

    Approve in the browser

    Clerk confirms the user and organization. Odyshell binds the CLI to that workspace.

  3. 03

    Connect a machine

    A one-time enrollment token gives the local client an identity. It connects outbound and waits.

Control lives outside the model.

Prompts can ask. Odyshell decides. Machine identity, capability checks, expiry and path boundaries are enforced before an operation reaches the client.

BoundaryOdyshell uses
ConnectivityOutbound from the machine
IdentityMachine key + workspace token
AuthorityCapabilities and machine scopes
TimeExpiring agent sessions
EvidenceOperation metadata and results

Start with the useful limit.

Plans limit managed capacity. They never weaken execution policy or shorten the audit trail to create an upgrade.

Free
For one person proving the workflow.
$0
  • 2 machines
  • 1 workspace
  • 3 active agent tokens
  • All operation capabilities
Team
Shared administration and more connected machines.
Soon
  • 10 machines
  • 3 workspaces
  • 25 active agent tokens
  • Team roles and shared audit
Billing will be enabled after the MVP validates usage.