O

OneCLI

Give every employee a secured, sandboxed pro assistant agent

AgentOpen Source

OneCLI is a self-hosted agent harness for teams: each employee gets their own sandboxed agent, reachable from Slack and the web, while credentials stay in a central vault behind a gateway the agent has to call through — so the agent itself never touches a real credential. Policy is applied centrally across the team, and the platform can be self-hosted from the public repo or used as a hosted service. The core is open source under Apache-2.0; enterprise features are not open source and are licensed separately under the OneCLI Enterprise License for production use. For the person who has to sign off before agents are rolled out beyond the engineering team.

What is OneCLI?

OneCLI is an agent harness for teams: every employee gets their own sandboxed assistant agent, reachable from Slack and the web, while credentials stay in a central vault and are injected scoped per request through a gateway — so the agent itself never holds a real secret. Admins layer policy on top: prohibited actions, rate limits, human approval gates, and per-user tool scoping. The core is open source under Apache-2.0; enterprise features are not open source and are licensed separately for production use.

Key features

  • A sandboxed agent per employee that, in the vendor's words, never holds a password — credentials are injected scoped per request rather than handed to the agent.
  • A single gateway in front of all agents, with keys kept in a vault so agents never see a raw secret.
  • Policy controls that agents cannot override: admin-defined prohibited actions, rate limiting to contain a runaway agent, human approval gates on sensitive operations, and tool access scoped to what each user is allowed to touch.
  • Slack as the primary working surface plus a web app, with agent activity reported back into Slack channels.
  • Connects to the tools work actually happens in — Stripe, Postgres, and GitHub among them — with unlimited projects, secrets, and OAuth connections on every tier.
  • Audit-log retention that scales by plan: 7 days on Trial, 30 days on Team, 90 days on Scale, and custom retention on Enterprise.
  • Bring-your-own Anthropic or OpenAI key (BYOC) from the Team plan upward, which lowers the plan price, or use the hosted models included on every tier.
  • Open-core licensing: the core is Apache-2.0 at github.com/onecli/onecli, with enterprise features under a separate OneCLI Enterprise License; self-hosted deployment is listed as an Enterprise-plan item. The site states SOC 2 Type II is in progress and that the product is GDPR-compliant with a DPA available.

Who it's for

  • Giving non-engineering teams an agent that can act in Stripe, Postgres, or GitHub without any person or agent ever holding the credentials.
  • Slack-native ops and support automation, where the agent does the job and reports what it did back into the channel.
  • A platform or security owner who has to approve an agent rollout beyond engineering and needs approval gates, rate limits, and scoped access before saying yes.
  • Regulated teams that need longer audit retention, a DPA, or a self-hosted deployment under an Enterprise agreement.
  • Teams that already pay for Anthropic or OpenAI and want to point their existing keys at a governed agent layer rather than buying bundled model spend.

When not to use it

If your plan is to self-host in production without an Enterprise agreement, this is the wrong shape: the Apache-2.0 core is public, but self-hosted deployment is listed only on the Enterprise plan and enterprise features are separately licensed. Paid tiers are also hard-capped by seats and agents — Team is $149/month for 5 seats and 10 agents, with extra seats at $49/user/month — so a large team grows into Scale or Enterprise quickly.

FAQ

Is OneCLI open source?

Partly. The core is open source under Apache-2.0 at github.com/onecli/onecli and can be cloned and run. Enterprise features are not open source — they are covered by a separate OneCLI Enterprise License for production use, and supported self-hosted deployment is listed as an Enterprise-plan item. Describing the whole product as open source would be inaccurate.

What does OneCLI cost?

Four tiers are published. Trial is $0 for 7 days with $5 in AI credits, 3 human seats, 3 agents, and 7-day audit-log retention. Team is $149/month for 5 seats and 10 agents, with 30-day audit logs and the option to bring your own Anthropic or OpenAI key; extra seats are $49/user/month. Scale is $499/month for 10 seats and 20 agents with 90-day audit logs; extra seats are $49/user/month when you bring your own LLM key, or $199 on hosted models. Enterprise is custom, with unlimited seats, custom agent limits, self-hosted deployment, and custom audit retention. All tiers include unlimited projects, secrets, and OAuth connections.

Do the agents ever hold our passwords or API keys?

Per the vendor, no. Keys stay in a central vault and are injected scoped per request through a gateway, so the agent never holds a real secret and cannot read raw credentials. On top of that, admins define actions agents are forbidden to take, rate limits that stop a runaway agent, human approval gates on sensitive operations, and tool access scoped to each user. This is the product's own security description, not an independently audited claim; the site states SOC 2 Type II is in progress and that a DPA is available.

Can we use our own model provider instead of bundled credits?

Yes, from the Team plan upward. Bring-your-own Anthropic or OpenAI keys (BYOC) is offered on Team, Scale, and Enterprise, and the pricing page notes that Team and Scale prices drop when BYOC is toggled on. Hosted models are included on every tier, including the Trial's $5 in AI credits.

Open SourceArtificial IntelligenceDeveloper ToolsSecurityCommand Line Tools
Submitted by Jonathan FishnerXLaunched September 12, 2026

Share this launch

Embed this badge

Featured on OrangeBot
<a href="https://orangebot.ai/product/onecli" target="_blank" rel="noopener noreferrer">
  <img src="https://orangebot.ai/api/badge/onecli.svg" alt="Featured on OrangeBot" width="200" height="54" />
</a>

Comments