The machine owns the clock
Expiry and immediate stop are enforced on the target by the operating system, not by a server. Revocation works even with no internet.
Temporary access, on purpose
Paste one command. A coding agent you pick gets a real, time-limited login to the computer in front of you, over an isolated SSH server and an outbound tunnel. The machine owns the clock. Stop any time.
curl -fsSL https://agentinvite.app/run | sh
Shows a safety check before anything happens, and installs nothing permanently. macOS is Developer ID signed; the runner’s SHA-256 is pinned in the script you can read first. What to know before you run it.
Shows a safety check before anything happens. Nothing is installed permanently except Windows’ own OpenSSH Server, if this machine has never had it — and it says so before it does. Not Authenticode signed yet, so the runner’s SHA-256 is what stands behind it, pinned in the script you can read first. More on that. What to know before you run it.
The flow
In short: your computer starts a private SSH server that only it can reach, then opens an outbound tunnel so the agent you picked can reach that server and nothing else. You get one line to hand over. When the time runs out, or you stop it, your computer shuts the whole thing down and tells you what it removed. No port is opened on your router, and your normal SSH stays untouched.
Before any key, tunnel, or install, the runner asks — on your real terminal — whether someone told you to run this. Enter stops. Only an explicit “I chose this” continues.
It names the machine and account, and states in plain words that the agent can read, change, and delete anything that account can. Then it asks you to start.
A fresh key and an isolated, loopback-only SSH server start behind an outbound tunnel. The countdown begins here — the default is 30 minutes.
You get a single high-entropy invitation to paste to the agent you picked. It is a temporary secret. The agent redeems it, decrypts the connection locally, and connects.
Press Stop, close the terminal, or let it expire. The key, listener, tunnel, and session files are removed and the result is verified. A copied credential is useless afterward.
What’s actually true
Expiry and immediate stop are enforced on the target by the operating system, not by a server. Revocation works even with no internet.
The agent gets the true capability of the account you pick. That’s the point — and the reason to invite an agent you trust and stop when done.
Anyone who gets the invitation line before your agent could race it. Hand it only to the agent you chose, and treat it like a password.
Access rides an outbound tunnel to a loopback-only server on a fresh key. Agent Invite never opens a firewall port or touches your normal SSH service.
The one-shot runner removes itself after a verified clean-up. An official OpenSSH package may remain if it was installed for you; nothing of Agent Invite’s does.
When the agent redeems the invitation, your terminal shows the address the service saw it come from, and keeps it on screen for the session. If that is not who you expected, stop it right there.
An agent may also describe itself, and that text is shown in quotes because it chose it. The address is the part it could not choose. We show them differently on purpose, and the address is kept only until your session's deadline.
Today the tunnel is Cloudflare Quick Tunnel — a no-SLA preview that can change or drop. If it does, access ends and cleans up rather than hanging open.
Agent Invite revokes the access it manages. It cannot undo commands, files, or credentials an invited agent creates through the account — the same as handing someone your keyboard. Read the agent-side flow →
One way in
Paste the command, clear the safety check, and you are handing off a session in seconds. The runner lives in a temporary directory and removes itself when the session is clean. Every session is temporary by construction. There is no setting anywhere that grants an agent standing access to your machine, and that is deliberate.
Same isolated SSH server on a fresh key, same outbound tunnel, same operating-system-enforced deadline, same verified clean-up, every time. Closing the terminal does not extend or end anything on its own — the machine still owns the clock.
It is the right choice on a machine that is not yours to install software on, on a server you are only visiting, or when you would rather leave no trace of the tool at all — which is to say, everywhere.
Wanting an agent to keep access between sessions is a fair thing to want, and Agent Invite is the wrong tool for it: everything here is built so access cannot outlive its deadline. For standing access, use your normal SSH setup, where the keys and the audit trail are yours to manage.
Windows
Same flow, same clock, same clean-up. If the machine has never had OpenSSH Server the runner installs it as a Windows optional feature — that single change is permanent, needs an elevated terminal, and the runner tells you before it makes it. Everything else is temporary and removed with the session.
irm https://agentinvite.app/run.ps1 | iex
It asks how long before anything starts. To answer up front and skip the
question, set it first: $env:AGENT_INVITE_MINUTES=180. Read it before you run it with
irm https://agentinvite.app/run.ps1 on its own.
The SHA-256 of the runner is pinned in the script you can read, and checked before anything executes. A swapped download stops the run.
The runner opens the console directly for its safety check and its start prompt, so
| iex can deliver the script but cannot consent on your behalf.
| Build | SHA-256 |
|---|---|
agent-invite-windows-x86_64.exe | 0f88fdb5b74d32f5dc4a1ec6833ead15d84a5b1a3eeb1f64da52a086c169743a |
Published so you can check it yourself; the script checks the same value before it runs anything.
Where it runs
Apple silicon and Intel. One-line command works and is Developer ID signed.
Availablex86_64 and arm64. One-shot command works; tested on Omarchy, then Arch, Ubuntu LTS, Debian stable.
Availablex64. One-line command works and installs Windows' own OpenSSH Server if the machine has never had it. Not Authenticode signed yet, so the runner's SHA-256 is what stands behind it — pinned in the script and checked before it runs. The command is here.
AvailableThe agent that connects can run on macOS, Linux, or Windows — it just needs the invitation and the standard OpenSSH client.
Options
There is deliberately very little. A short list you can hold in your head beats a manual you have to read before handing over your machine.
It asks. Fifteen minutes, thirty, an hour, or three — and three hours is the hard ceiling, which no flag, URL, environment value, or clock change can buy past. A machine asked for a session by another machine on your account is capped lower, at an hour.
curl -fsSL https://agentinvite.app/run | sh -s -- 15
Answer the question, or say it up front like this and skip it.
Swap 15 for 30, 60 or 180. Anything else is refused.
Press s then Enter, or Ctrl+C. Either way you get a checklist showing each artefact removed. Close the terminal and the machine still ends the session on its own deadline.
There is no “extend”. A longer session means a new invitation, deliberately.
OpenSSH, already present on every supported machine, and cloudflared
for the outbound tunnel. If cloudflared is missing the runner says so
before you commit, then fetches the official build and checks it against a pinned
SHA-256. It is kept for the session and deleted with it — nothing is installed.
The script is short and meant to be read. Every runner’s SHA-256 is pinned inside it, so the download cannot be swapped without changing the script you just read.
curl -fsSL https://agentinvite.app/run | less
Status
One line to invite, one line to connect. It works today on macOS, Linux and Windows — workstations and servers — and the session lifecycle, the encrypted hand-off and the clean-up are tested end to end on real machines. What to know before you run it: there has been no independent security review yet, the tunnel is a no-SLA Cloudflare Quick Tunnel, and Windows binaries are not code-signed, so a pinned digest is what stands behind them. Use it on machines you’re willing to hand to an agent, and read the script before you pipe it.
curl -fsSL https://agentinvite.app/run | sh
That’s the whole thing. It asks how long before anything starts.