The platform
Every path to production, on one set of rules
A browser terminal, your own CLI, a CI pipeline, an AI agent over MCP—all through the same access rules, the same judgment, and the same record. Commands an agent runs are judged before they reach the host.
Enjoy the free version forever. Upgrade for full features when you're ready.Roll out the payments hotfix
ActiveSession purpose
Deploy the 1.14.2 hotfix to the payments API and confirm charges recover. Restart is expected; no schema change.
Session features
- Web terminalWeb
- CommandCLI
- Privilege elevationCLI
- File transferWeb
- Code editorWeb
- Port forwardingWeb
Three of six declared. The three it did not ask for stay unavailable for the session's whole life—checked before any rule, any MFA challenge and any model call, and a superuser gets the same answer.
Target servers
prod-docker-1 · us-east-1
Usage time
38% elapsed · expires in 1h 51m
Extension needs a fresh approval.
Our customers
Backed by · Partners
- Rabbit Ventures


Shell is the most powerful interface to any system
Claude Code didn't succeed by adding another abstraction layer. It succeeded by going straight to the shell. AI agents operate production the same way—so Alpacon judges the commands they run, at the shell, before they reach the host.
One policy · every interface
However your team reaches production
Web console, terminal, pipeline, or AI agent—every path runs through the same access rules and lands on the same record.
Web console
Browser terminal & files
Websh and WebFTP in the browser, with no inbound port on the host.
CLI
Your terminal, governed
Shell, transfers, batch commands and port forwarding, under the same policy as the console.
API · CI/CD
Pipelines & automation
Service tokens scoped to a preset command set—deny by default.
MCP · AI agents
Agents, on the same rules
No interactive shell, and a human decides from medium risk up.
One operation, three dialects
Ask in natural language, type it in your terminal, or POST it from a pipeline—the same command meets the same judgment and lands on the same record.
One identity. Every agent. Every server.
AI agents, engineers, and CI/CD pipelines authenticate once—then access exactly what they're authorized for. No per-agent credentials. No key rotation.
See how access worksVerify your identity
Confirm with your fingerprint or face to continue.
Scoped execution, not sandboxes
Don't cage AI agents in sandboxes—give them production access with per-command judgment. Define exactly which commands each agent can run, and route privileged ones to a human out of band before they execute.
Explore all features- 02:02:40session openedMFA verified · prod-docker-1
- 02:04:19tail -f /var/log/payments/app.logAllowed · secrets masked in the recordLow
- 02:07:12payments.env → /opt/payments/Recorded. File transfer is ACL-gated, not risk-judged.
- 02:13:21sudo systemctl restart payments-apiHeld for a human, then approved by Eunyoung JeongMedium
- 02:19:55sudo rm -rf /var/lib/postgresql/16/mainRejected. The agent was told it was refused, and nothing more.Critical
Every action. Recorded. Searchable.
Every Websh and command-API session is recorded, and recognised credential formats are masked as the record is written—not cleaned up afterwards. Session analysis reads the whole session and maps what happened to MITRE ATT&CK techniques. Controls map to SOC 2, NIST 800-53 and ISO 27001 IDs, so your compliance lead starts from a control matrix instead of building one.
See security and complianceWebsh session · prod-server
The operator tried to read /etc/shadow, then downloaded a script from an unknown host and tried to run it. The download failed with a 404 and nothing executed.
- Commands
- 4
- Risk factors
- 2
- Confidence
- Medium
- Attack chain
- Partial

