OneCLI
Sandboxed AI agents for teams that never hold a real password
Visit website →About
OneCLI gives every employee a personal AI agent that runs inside a sealed sandbox. Agents connect to GitHub, Gmail, Notion, Slack, Dropbox, and your CRM, but they never see real credentials: they handle placeholders, and the OneCLI gateway injects the actual secret at the network layer after a request is approved.
The platform enforces rules outside the model instead of relying on prompt discipline. Some actions are blocked outright, suspiciously fast activity is throttled, and sensitive operations pause for human approval. Each agent is scoped to its owner's access, so a support agent cannot wander into billing systems.
OneCLI is fully open source with a self-hosted deployment option alongside its managed service, and agents work from Slack or the web. The Y Combinator-backed team reports more than 350K downloads of the open-source release.