One Sandboxed Agent Per Employee, With Credentials That Never Leave the Gateway
You've probably tried running an autonomous agent for yourself by now. Maybe it's great. But what happens when three people on your team want the same thing? Now you're spinning up separate instances, tracking whose agent is whose, and figuring out how to hand out API keys without passing them around in Slack. OneCLI is an open-source platform that answers that problem by treating agents as something a team provisions, not something an individual cobbles together.
What It Does
OneCLI is a platform for running AI agents as a team. You create an agent per person, give each agent the access it needs, and it works inside a sandbox, routed through a gateway that injects credentials and enforces your policy. The agent itself isn't a single prompt—it's a durable thing. It has its own isolated sandbox with a filesystem and a shell, and the only way out is the gateway, so it can reach what you granted and nothing else.
The rest of the agent is built out similarly: it has a conversation (its own dashboard page, or Slack, with images and files), memory that the platform keeps so it's never lost and that you can read and edit at any time, skills you write once and stay available, and a schedule so the agent can plan future work and get woken up at the right time.
On the team side, OneCLI integrates with your identity provider so agents get provisioned on behalf of each employee's identity, straight from the company IdP. Policy lives in one place and gets enforced across every agent in the workspace. Connections like LLM keys or service accounts are shared at the team level and granted per agent without ever being handed to one.
The project started as a credential vault for AI agents, written in Rust. The team noticed most of the demand came from people running autonomous agents like Hermes, OpenClaw, and NanoClaw—and that two things were missing: managing secrets and permissions, and multiplayer management for teams.
Why It's Cool
The gateway is the whole trick. Every autonomous agent out there is built for one person, and for one person they're great. The moment you replicate that across a team, it gets messy. OneCLI's answer is to make the sandbox's only exit a gateway that injects credentials on the way out. That means the agent never holds the key. It's a clean separation that solves the "how do I give my agent access to X without pasting a secret into a config file" problem at the architecture level rather than the policy level.
Deterministic human-in-the-loop approvals. This is the detail that makes the whole thing usable for real work. For actions you need 100% control over—sending the email, deleting the Linear ticket, emptying an S3 bucket—approvals happen in the chat itself. Not a separate dashboard, not a webhook you have to wire up. The approval is part of the conversation.
Global connections granted per agent. Shared credentials like LLM keys or service accounts live at the team level and get granted to individual agents without ever being handed to one. If you've ever tried to rotate a key that's been copied into six different agent configs, you'll appreciate why this matters.
An agent per person, reachable where people already are. Each employee gets their own sandboxed agent, reachable from the dashboard or Slack. That's a small thing on paper and a big thing in practice—nobody has to learn a new tool to talk to their agent.
Memory you can read and edit. The platform keeps what the agent learns, so it isn't lost between sessions. Being able to inspect and correct that memory directly is the kind of feature you don't realize you need until an agent has confidently remembered something wrong for a week.
How to Try It
You've got two options. The cloud-hosted version is at onecli.sh. If you'd rather run it yourself:
git clone https://github.com/onecli/onecli.git && cd onecli
pnpm install
pnpm run setup
Then open http://localhost:10254.
The repo is at github.com/onecli/onecli. There's also a Discord and docs if you want to dig deeper before installing anything.
Final Thoughts
OneCLI is aimed squarely at teams—specifically teams that have already decided they want autonomous agents doing real work and are now staring at the operational mess that decision creates. If you're a solo developer running one agent for yourself, you probably don't need this yet. If you're the person who got voluntold to roll out agents for your company, this is the missing layer. It's early, and the README is honest that the project pivoted from a credential vault into a full platform, which is usually a good sign that the team is building what people actually asked for rather than what they originally planned.
Follow @githubprojects for more developer tools and open source projects.