OpenShell

An open-source AI agent runtime for Linux and Apple Silicon macOS that restricts file, network and credential access and supports private model endpoints.

Screenshot of OpenShell website

OpenShell is a self-hosted runtime for teams running autonomous AI agents that need access to files, APIs and credentials. It runs agents in sandboxes with kernel-level isolation and explicit access policies. It's open source under Apache 2.0 and supports Linux and macOS on Apple Silicon, with Docker, Podman or host virtualization.

It works with coding assistants including Claude Code, OpenCode, Codex and GitHub Copilot CLI. Teams can give each sandbox access to selected files and approved network destinations while blocking privilege escalation and dangerous system calls. Agents receive credential placeholders; OpenShell supplies the real credentials only to requests bound for authorized endpoints.

Policies are reviewable YAML files that teams can keep in version control. Formal verification checks proposed changes for risky additions, such as access to another host with credentials or permission to call another API method. Those changes wait for human review. Network rules and credential attachments can change at runtime, while file and process restrictions stay fixed for the sandbox's lifetime.

Teams can connect sandboxes to self-hosted or private model endpoints. The runtime can run locally, and its gateway can also run on Kubernetes. The default workload uses Ubuntu, with support for custom containerized environments.

OpenShell collects anonymous operational telemetry by default, which teams can disable. It excludes prompts, user content, credentials, file paths, hostnames and model or provider names.

Similar to OpenShell