UStackUStack
OneCLI icon

OneCLI

OneCLI is an open-source platform for giving each employee a personal AI agent that works through a secured gateway without seeing real secrets. It helps teams automate work in Slack, on the web, and through CLI or SDK access.

OneCLI

Overview

OneCLI is an open-source platform for giving each employee a personal AI agent that works inside a secured sandbox. The agent runs through a gateway that injects credentials, applies policy rules, and keeps real secrets out of the model’s view.

The product is aimed at teams that want agents to do operational work across company tools without handing over passwords. It can be used in Slack, on the web, and through the CLI/SDK, with options for hosted deployment, BYOC, and enterprise self-hosting.

Key capabilities

Per-person durable agents

Each employee gets a durable agent with its own sandbox, shell, conversation space, memory, skills, schedule, and approval flow. The product is designed so the agent can keep working over time instead of starting from a fresh prompt each time.

Credential injection at the gateway

The gateway injects scoped credentials on each request and the platform says agents never see real secrets. This is the core mechanism behind the product’s security model.

Policy enforcement and approvals

Policy rules are enforced outside the model, including limits on actions the agent may never perform, speed throttling, and human approval for sensitive steps. The homepage shows examples such as blocking repository deletion and pausing before customer email sends.

Multiple access surfaces

Agents can be accessed in Slack and on the web, and the docs add the dashboard plus its own Slack app for each agent. The site also mentions a CLI and SDK for routing coding agents through the gateway.

Shared company tooling with personal scope

The product is built around shared company-level skills, MCP servers, CLIs, and global connections that can be reused across agents while each employee keeps a personal scope in an isolated VM.

Tiered workspace administration

Pricing is organized per person and includes trial, team, scale, and enterprise paths. The pricing page also lists audit logs, resource-level scoping, SSO/SAML, and support tiers as part of the platform packaging.

Common use cases

  • Employee-specific assistants

    Give each employee a dedicated agent that can work in company tools using that person’s scoped access, rather than a shared bot account.

  • Developer workflow automation

    Let engineering agents open pull requests, file tickets, or work through CLIs while the gateway keeps real credentials out of the agent’s view.

  • Business and operations support

    Use agents for operational work such as inbox management, scheduling, or invoice handling across everyday SaaS tools, with approvals for sensitive steps.

  • Governed agent operations

    Apply centralized policy rules when you need to cap risky actions, block certain operations entirely, or require a human sign-off before the agent proceeds.

  • Gateway for existing agents

    Route already-running coding agents through OneCLI’s gateway so they inherit injected credentials and policy enforcement without changing the underlying workflow.

Pros and Cons

Pros

  • Runs agents in an isolated sandbox with gateway-enforced credential injection.
  • Supports policy controls such as disallowed actions, speed limiting, and human approvals.
  • Offers multiple interaction paths, including Slack, web, CLI, and SDK.
  • Pricing is per person rather than per agent, which matches the product’s employee-based model.
  • Includes a free trial with no credit card required.

Cons

  • The source only gives partial detail on exact integrations, so buyers will need to confirm the full connector list for their stack.
  • Some pricing and deployment details are plan-specific, especially around BYOC, enterprise self-hosting, and custom terms.

FAQ

How does OneCLI work at a high level?

OneCLI provides each employee with a personal agent that runs in a sandboxed environment and is accessed through the dashboard, Slack, or the CLI/SDK. The platform injects credentials at the gateway so the agent can work without seeing real secrets.

Is there a free trial?

The source says every workspace starts with a 7-day free trial that includes $5 in AI model credits and does not require a credit card.

Which AI models can be used?

Team and Scale plans include hosted models, while BYOC lets you use your own Anthropic or OpenAI key and have pricing adjusted accordingly. The pricing page also notes that enterprise can support custom model arrangements.

What integrations and channels are supported?

According to the docs, agents can be reached from the dashboard or Slack, and OneCLI also offers a CLI and SDK. The site also describes custom integrations and support for Google, GitHub, Slack, AWS, and 40+ more in the docs.

Can OneCLI be self-hosted?

Enterprise is the plan described for self-hosted deployment, including running the platform in your own cloud, VPC, or on-prem with custom terms. The contact page also highlights enterprise trials, custom integrations, and SSO/SAML setup.

Quick Facts

Category
AI Agent Platform
Primary users
Teams and companies
Deployment
Cloud-hosted, BYOC, and enterprise self-hosting
Access channels
Slack, web, CLI, SDK
Source domain
onecli.sh
Pricing model
Per person, with trial and paid plans

Альтернативы OneCLI

CreateOS Sandbox icon

CreateOS Sandbox

CreateOS Sandbox is an isolated compute environment for running code and agent workloads inside Firecracker micro-VMs. It is designed for workflows that need machine-level isolation, private networking between sandboxes, and programmatic control through SDK, CLI, or MCP.

ByteAsk icon

ByteAsk

ByteAsk is a terminal-first AI coding agent for C and C++ that edits repositories and verifies changes with the real compiler, debugger, sanitizers, and tests before showing a diff. It offers a free tier plus paid plans, with editor connectors and zero-retention handling described in the source.

Goldfish icon

Goldfish

Goldfish is an AI memory app for macOS that helps you reply, write, summarize, and continue using the context already on your Mac. It stores memory locally and writes in your tone.

ArtDeck icon

ArtDeck

ArtDeck is a visual reference board app for iPhone, iPad, and Mac that lets artists collect mixed reference material on one canvas and study it with ToolBox lenses. It works offline, supports optional iCloud sync, and is sold as a one-time purchase with no account required.

Biji icon

Biji

Biji - это универсальная платформа, разработанная для повышения продуктивности с помощью инновационных инструментов и функций.

Malyatko icon

Malyatko

Malyatko is a baby tracker for logging feeding, sleep, growth, teething, and milestones in one app. It works on iPhone, Apple Watch, and widgets, with no sign-up, offline use, and family sharing through iCloud.