Protect actions
Hold destructive commands, production deploys, force pushes, and sensitive file reads.
OpenLeash sits beside your agents and watches the moments that matter: secrets, shell commands, file access, deploys, and other risky actions. You start simple, then add cloud, teams, identity, and audit only when you need them 🙂
Your agent asks to do something. OpenLeash checks the risk. Safe work continues; sensitive work gets blocked, masked, or sent for approval.
Hold destructive commands, production deploys, force pushes, and sensitive file reads.
Catch keys, tokens, .env files, kubeconfigs, and other sensitive context before they leak.
Keep a readable trail of the agent, user, action, decision, and reason.
No maze. Pick the card that sounds like you.
I want protection on my own machine, no account, no dashboard.
I want a hosted account for myself, but I am not managing a company.
We want OpenLeash hosted for our company, with policy and audit.
We need to host the APIs, dashboard, database, and identity ourselves.
Hooks call the desktop client first. That keeps Local mode local, and lets cloud modes keep working through the same client.
Installed hooks -> Desktop local API http://127.0.0.1:9317/v1/hooks/:agent/:event Local mode: desktop-client -> local evaluation Managed modes: desktop-client -> local API -> client-api