agent·invite

Temporary access, on purpose

Hand your machine to the agent you choose — for exactly as long as you choose.

Paste one command. A coding agent you pick gets a real, time-limited login to the computer in front of you, over an isolated SSH server and an outbound tunnel. The machine owns the clock. Stop any time.

curl -fsSL https://agentinvite.app/run | sh

Shows a safety check before anything happens, and installs nothing permanently. macOS is Developer ID signed; the runner’s SHA-256 is pinned in the script you can read first. What to know before you run it.

The flow

Five steps, in this order. No surprises before the safety check.

In short: your computer starts a private SSH server that only it can reach, then opens an outbound tunnel so the agent you picked can reach that server and nothing else. You get one line to hand over. When the time runs out, or you stop it, your computer shuts the whole thing down and tells you what it removed. No port is opened on your router, and your normal SSH stays untouched.

  1. Safety check first

    Before any key, tunnel, or install, the runner asks — on your real terminal — whether someone told you to run this. Enter stops. Only an explicit “I chose this” continues.

  2. Plain disclosure

    It names the machine and account, and states in plain words that the agent can read, change, and delete anything that account can. Then it asks you to start.

  3. Access becomes ready

    A fresh key and an isolated, loopback-only SSH server start behind an outbound tunnel. The countdown begins here — the default is 30 minutes.

  4. One line to your agent

    You get a single high-entropy invitation to paste to the agent you picked. It is a temporary secret. The agent redeems it, decrypts the connection locally, and connects.

  5. Stop, and it’s gone

    Press Stop, close the terminal, or let it expire. The key, listener, tunnel, and session files are removed and the result is verified. A copied credential is useless afterward.

What’s actually true

Honest about the trade you’re making.

The machine owns the clock

Expiry and immediate stop are enforced on the target by the operating system, not by a server. Revocation works even with no internet.

It’s a real login, not a sandbox

The agent gets the true capability of the account you pick. That’s the point — and the reason to invite an agent you trust and stop when done.

The invitation is a bearer secret

Anyone who gets the invitation line before your agent could race it. Hand it only to the agent you chose, and treat it like a password.

No inbound port, no shared SSH

Access rides an outbound tunnel to a loopback-only server on a fresh key. Agent Invite never opens a firewall port or touches your normal SSH service.

Nothing left behind

The one-shot runner removes itself after a verified clean-up. An official OpenSSH package may remain if it was installed for you; nothing of Agent Invite’s does.

You see where it connected from

When the agent redeems the invitation, your terminal shows the address the service saw it come from, and keeps it on screen for the session. If that is not who you expected, stop it right there.

A name an agent gives itself proves nothing

An agent may also describe itself, and that text is shown in quotes because it chose it. The address is the part it could not choose. We show them differently on purpose, and the address is kept only until your session's deadline.

Preview transport

Today the tunnel is Cloudflare Quick Tunnel — a no-SLA preview that can change or drop. If it does, access ends and cleans up rather than hanging open.

Agent Invite revokes the access it manages. It cannot undo commands, files, or credentials an invited agent creates through the account — the same as handing someone your keyboard. Read the agent-side flow →

One way in

Nothing to install, nothing to keep.

Paste the command, clear the safety check, and you are handing off a session in seconds. The runner lives in a temporary directory and removes itself when the session is clean. Every session is temporary by construction. There is no setting anywhere that grants an agent standing access to your machine, and that is deliberate.

The one-shot command

Same isolated SSH server on a fresh key, same outbound tunnel, same operating-system-enforced deadline, same verified clean-up, every time. Closing the terminal does not extend or end anything on its own — the machine still owns the clock.

It is the right choice on a machine that is not yours to install software on, on a server you are only visiting, or when you would rather leave no trace of the tool at all — which is to say, everywhere.

Session-scoped · macOS, Linux & Windows one-liner · nothing installed

Wanting an agent to keep access between sessions is a fair thing to want, and Agent Invite is the wrong tool for it: everything here is built so access cannot outlive its deadline. For standing access, use your normal SSH setup, where the keys and the audit trail are yours to manage.

Windows

One line here too.

Same flow, same clock, same clean-up. If the machine has never had OpenSSH Server the runner installs it as a Windows optional feature — that single change is permanent, needs an elevated terminal, and the runner tells you before it makes it. Everything else is temporary and removed with the session.

irm https://agentinvite.app/run.ps1 | iex

It asks how long before anything starts. To answer up front and skip the question, set it first: $env:AGENT_INVITE_MINUTES=180. Read it before you run it with irm https://agentinvite.app/run.ps1 on its own.

The download is checked

The SHA-256 of the runner is pinned in the script you can read, and checked before anything executes. A swapped download stops the run.

The pipe cannot answer for you

The runner opens the console directly for its safety check and its start prompt, so | iex can deliver the script but cannot consent on your behalf.

BuildSHA-256
agent-invite-windows-x86_64.exe0f88fdb5b74d32f5dc4a1ec6833ead15d84a5b1a3eeb1f64da52a086c169743a

Published so you can check it yourself; the script checks the same value before it runs anything.

Where it runs

The machine you’re inviting from.

macOS

Apple silicon and Intel. One-line command works and is Developer ID signed.

Available

Linux

x86_64 and arm64. One-shot command works; tested on Omarchy, then Arch, Ubuntu LTS, Debian stable.

Available

Windows

x64. One-line command works and installs Windows' own OpenSSH Server if the machine has never had it. Not Authenticode signed yet, so the runner's SHA-256 is what stands behind it — pinned in the script and checked before it runs. The command is here.

Available

The agent that connects can run on macOS, Linux, or Windows — it just needs the invitation and the standard OpenSSH client.

Options

Everything you can change.

There is deliberately very little. A short list you can hold in your head beats a manual you have to read before handing over your machine.

How long

It asks. Fifteen minutes, thirty, an hour, or three — and three hours is the hard ceiling, which no flag, URL, environment value, or clock change can buy past. A machine asked for a session by another machine on your account is capped lower, at an hour.

curl -fsSL https://agentinvite.app/run | sh -s -- 15

Answer the question, or say it up front like this and skip it. Swap 15 for 30, 60 or 180. Anything else is refused.

Ending it

Press s then Enter, or Ctrl+C. Either way you get a checklist showing each artefact removed. Close the terminal and the machine still ends the session on its own deadline.

There is no “extend”. A longer session means a new invitation, deliberately.

What it needs

OpenSSH, already present on every supported machine, and cloudflared for the outbound tunnel. If cloudflared is missing the runner says so before you commit, then fetches the official build and checks it against a pinned SHA-256. It is kept for the session and deleted with it — nothing is installed.

Reading it first

The script is short and meant to be read. Every runner’s SHA-256 is pinned inside it, so the download cannot be swapped without changing the script you just read.

curl -fsSL https://agentinvite.app/run | less

Status

A command-line tool, and only that.

One line to invite, one line to connect. It works today on macOS, Linux and Windows — workstations and servers — and the session lifecycle, the encrypted hand-off and the clean-up are tested end to end on real machines. What to know before you run it: there has been no independent security review yet, the tunnel is a no-SLA Cloudflare Quick Tunnel, and Windows binaries are not code-signed, so a pinned digest is what stands behind them. Use it on machines you’re willing to hand to an agent, and read the script before you pipe it.

curl -fsSL https://agentinvite.app/run | sh

That’s the whole thing. It asks how long before anything starts.