A Linux kernel is booting inside this page. Your agent gets terminals, files and processes on it through WebMCP. You sit at the same terminal — and you hold the only key to anything irreversible: those tools do not exist until you grant them, and stop existing when you revoke. Nothing here leaves the browser. Pair a machine of your own and this same page operates that instead.
Booting…
No staged changes. When the agent stages an edit it appears here as a ghost, before anything touches disk.
The machine's own VGA text console, drawn by the emulator. The shell you and the agent use is on the serial line; this is what a monitor plugged into the box would show. Opening this view registers screen_capture; closing it removes the tool.
The machine above is disposable and lives in this tab. Bonnie's host runs on your real
computer and pairs it to this page over a direct peer connection — no relay, no account.
Your agent then gets the same catalogue, generated from what that machine has:
tmux terminals that outlive the tab, the real filesystem, the screen, Codex subagents.
Ask your agent for bonnie_install_plan, or:
git clone https://github.com/meshbergio/bonnie cd bonnie && ./install.sh bonnie pair # prints a URL and a QR code — open it in this page
Warranted tools do not exist until you grant them here, on your own page, with a real click. A tool call cannot produce one.
Every call, warrant and command lands in an append-only ledger the agent can read back — including what happened while it was not looking.
The page is static. Once paired, it makes no requests to its own origin — the counter in the footer is the measurement.
Granting registers these tools. Until you click, they do not exist in the agent's catalogue — there is no name for it to call. Revoking deletes them again, mid-task if need be.
Grant these once and stop being asked. It holds until you turn it off — no expiry, across reloads. The agent can never turn this on; only you can, and turning it off is one tap from anywhere.