Quickstart
Install the CLI and create your first sandboxed agent in two commands.
How It Works
Understand the gateway, sandbox, policy engine, and privacy router.
Sandbox Policies
Declare filesystem, network, process, and inference constraints in YAML.
CLI Reference
Full reference for every command, subcommand, and flag.
Get running in two commands
1
Install OpenShell
2
Create a sandbox and launch an agent
3
Apply a network policy
Protection layers
OpenShell applies defense in depth across four policy domains:Explore by topic
Gateways & Sandboxes
Deploy gateways locally, on a remote host, or behind a cloud proxy.
Providers
Manage agent credentials — injected at runtime, never written to disk.
Inference Routing
Keep inference traffic private by routing to local or self-hosted backends.
Supported Agents
Claude Code, OpenCode, Codex, Copilot, and more work out of the box.
Community Sandboxes
Use pre-built sandbox images or bring your own container.
Tutorials
Hands-on walkthroughs from first sandbox to custom policies.
OpenShell is alpha software — single-player mode. One developer, one environment, one gateway. Multi-tenant enterprise deployments are on the roadmap. Expect rough edges.