Temper your agents.

Give every agent a place to live.

An always-on computer for each user's agent. It keeps its memory, never holds the real keys, and asks before anything it can't undo.

You ship the agent. We run the security.

One email, end to end
  1. agentPOST gmail.googleapis.com/gmail/v1/users/me/messages/send
  2. egressallow gmail.googleapis.com
  3. gatewaytmpr_••••4f2a → real token (host only)
  4. policycategory=send → hold for approval
  5. webhookapproval.requested → your backend
  6. backendapproved · scope=once
  7. gatewayforwarded · 200 OK
  8. auditseq 1842 · prev 9c41…e07a
Example trace. The agent only ever sees a stand-in token.

Product

A computer your users can trust their agent with.

Each end user gets a long-lived microVM with a trust layer around it. You bring the agent.

temper | computers

A full Linux computer for every end user.

Background services, a browser and an encrypted persistent disk. An agent can live there for months and follow up on tasks across days.

USER VMS · ONE HOSTactivesuspended
  • Long-lived microVM

    One hardware-isolated VM per end user, with the agent in a sandboxed unit inside.

  • Encrypted data disk

    Each user's files and memory sit on their own encrypted disk.

  • Suspends when idle

    Idle VMs suspend on their own and wake on the next request.

temper | credentials

Real tokens never enter the VM.

The agent holds stand-in tokens. A credential gateway on the host swaps in the real ones on the way out, after checking the token belongs to this VM and this domain.

VMHOSTINTERNETAgenttmpr_••4f2aGatewayverify, swapGmail APIreal token
  • OAuth under your brand

    Your users connect Gmail, Google Calendar and Slack through your own app.

  • Bring your own keys

    Store your API keys once. Agents use them without ever seeing them.

  • Nothing to steal

    A prompt injection that exfiltrates the agent's token gets a useless string.

temper | approvals

Risky actions wait for a real yes.

Sending email, paying, deleting data and other risky actions are held by policy and sent to your backend as signed webhooks. Consent never travels through the chat.

signed webhookAgentPolicyYour backendGmail APIheldapprovedsentApproveYOUR USER
  • Policies you control

    Set defaults for every environment and override them per user.

  • Signed both ways

    Webhooks and decisions are signed, so the agent can't forge a yes.

  • Five grant scopes

    Approve once, for a task, for a session, for a time window, or for good.

temper | browsers

Logged-in browsers, kept on a leash.

Lease a browser that remembers your user's login. The agent can navigate, read and type. It can't read cookies or run its own scripts.

AgentBrokernavigate, click, typeread cookiesBROWSER POOLleased
  • Filtered on the host

    Dangerous browser commands are dropped before they reach the browser.

  • Approval for sensitive forms

    Payment, password and delete submissions wait for approval.

  • Human takeover

    Your user can watch live and take control at any moment. The agent can ask for it too.

temper | upgrades

Ship new agent versions without losing memory.

Each upgrade gets a fresh VM, and the user's data disk moves across. Nothing is patched in place.

VM · v1.3VM · v1.4health check passedData disk
  • Gradual rollout

    Start with a slice of users and widen in batches.

  • Health checks

    Every swapped VM has to pass before the rollout continues.

  • Automatic rollback

    A bad version rolls back on its own. User data stays put.

How it works

Every outbound action passes through a layer the agent can't touch.

We run the security layer. Neither the agent nor a hijacked prompt can change it.

AGENTEGRESSGATEWAYPOLICYYOUR BACKEND
  1. 01In the VM

    Agent makes a request

    It holds stand-in tokens only, so there is nothing valuable to leak.

  2. 02In the VM

    Egress allowlist

    Domains you haven't allowed are blocked. Every request is recorded.

  3. 03On the host

    Credential gateway

    Verifies the stand-in token, then swaps in the real one.

  4. 04Control plane

    Policy check

    Risky actions are held and sent to your backend as a signed webhook.

  5. 05Your backend

    You decide

    Ask your user however you like, then approve or deny.

Security

Built on the assumption that the agent is already compromised.

Protection can't depend on the agent behaving. It comes from boundaries the agent can't get around.

Tamper-evident audit log

Example

Every request, credential use and approval, hash-chained. Query it in the console or export it.

TimeDomainActionDecision
14:02:07www.googleapis.comreadallow
14:02:11gmail.googleapis.comsendapproved
14:03:40paste.example.netwriteblocked
14:05:02slack.comwriteallow

Chain intact · seq 1842

Approvals in your product

Example

You get a signed webhook. You choose how to ask your user.

Send email to dana@example.com

gmail · send · expires in 10 min

Egress allowlist

Example

Each environment can reach only the domains you allow.

  • gmail.googleapis.comallowed
  • slack.comallowed
  • api.openai.comallowed
  • paste.example.netblocked

Human takeover

Example

Your user takes the wheel. The agent is locked out until they hand it back.

mail.google.com
User in controlAgent locked

What we protect against

Credential theft
Real tokens never enter the VM. Stand-in tokens are bound to one environment and its domains.
Data exfiltration
The only way out is through the egress allowlist, and every request is logged.
Unapproved actions
Risky actions are held by policy. Approvals arrive only as signed callbacks from your backend.
Account takeover
One-time codes and reset links are filtered out of mail. Password and code submissions need approval.
Logged-in browser abuse
No cookie access or script execution in logged-in sessions. Users can take over at any time.
Escape and cross-tenant access
A hardware-isolated microVM per user, a sandboxed unit inside it, and a separate encrypted disk for each user.
Runaway spend
Per-environment spending limits, task timeouts and automatic suspend.

Developers

An API for your backend. A console for your team.

Give a user a computer with one call, then handle approvals as webhooks.

  • REST API

    Environments, policies, approvals, audit, browsers and agent releases.

  • TypeScript, Python and Go SDKs

    Typed clients and a webhook signature checker.

  • Console

    Look up any environment, edit policies, search and export the audit log.

import { Temper, verifyWebhook } from "@temper-hq/sdk";

const temper = new Temper({ apiKey: process.env.TEMPER_API_KEY });

// One secure computer per end user
const env = await temper.environments.create({ end_user_id: "user_8f2c" });

// Risky actions arrive as signed webhooks
app.post("/webhooks/temper", async (req, res) => {
  const event = await verifyWebhook(secret, req.rawBody, req.get("temper-signature"));
  res.sendStatus(200);

  if (event.type === "approval.requested") {
    const { approval_id, summary } = event.data;
    (await askYourUser(summary))
      ? await temper.approvals.approve(approval_id, { kind: "once" })
      : await temper.approvals.deny(approval_id);
  }
});
from temper_hq import Temper, verify_webhook

temper = Temper()  # reads TEMPER_API_KEY

# One secure computer per end user
env = temper.environments.create(end_user_id="user_8f2c")

# Risky actions arrive as signed webhooks
@app.post("/webhooks/temper")
async def webhook(request: Request):
    event = verify_webhook(SECRET, await request.body(),
                           request.headers.get("temper-signature"))
    if event.type == "approval.requested":
        approval = event.data
        if await ask_your_user(approval["summary"]):
            temper.approvals.approve(approval["approval_id"], {"kind": "once"})
        else:
            temper.approvals.deny(approval["approval_id"])
    return {"ok": True}
import temper "github.com/temper-hq/sdk-go"

client, _ := temper.New(temper.WithAPIKey(os.Getenv("TEMPER_API_KEY")))

// One secure computer per end user
env, _ := client.Environments.Create(ctx, temper.CreateEnvironmentParams{
	EndUserID: "user_8f2c",
})

// Risky actions arrive as signed webhooks
func handleWebhook(w http.ResponseWriter, r *http.Request) {
	body, _ := io.ReadAll(r.Body)
	event, err := temper.VerifyWebhook(secret, body,
		r.Header.Get("Temper-Signature"), 0, time.Time{})
	if err != nil {
		http.Error(w, "bad signature", http.StatusBadRequest)
		return
	}
	w.WriteHeader(http.StatusOK)

	if event.Type == "approval.requested" {
		var a struct {
			ID      string `json:"approval_id"`
			Summary string `json:"summary"`
		}
		json.Unmarshal(event.Data, &a)
		if askYourUser(a.Summary) {
			client.Approvals.Approve(ctx, a.ID, temper.OnceScope())
		} else {
			client.Approvals.Deny(ctx, a.ID)
		}
	}
}
Package names and install commands are coming with the public release.

Who it's for

Teams whose agents act on behalf of people.

  • Agent startups

    Personal assistants and sales, support or operations agents that work inside each user's mail, calendar and accounts.

  • Enterprise agent teams

    Teams connecting agents to employee mailboxes, calendars and internal business systems, who need an audit trail that passes a security review.

Compare

How Temper differs from code sandboxes.

E2B, Daytona and Fly.io Sprites are good at what they are built for. Here is where the designs differ.

E2B / DaytonaFly.io SpritesTemper
IsolationmicroVM or containerFirecracker microVMmicroVM per end user, with a sandboxed unit inside
LifetimeMostly per sessionPersistent, sleeps and wakesPersistent, suspends and wakes
CredentialsNot built inOrganization-level connectorsStand-in tokens, per-user OAuth under your brand
Risky actionsNot built inNo approval stepPolicy and signed-webhook approval
EgressNot built inDNS allowlistDomain allowlist with hash-chained audit
Wake from idle (p95)Benchmark pending
New or replaced VM readyBenchmark pending

We will publish numbers measured under the same workload, not targets.

Based on each vendor's public documentation as of October 2026. Tell us if something has changed.

Build agents your users can trust with their accounts.

We are working closely with a small group of design partners. Tell us what your agent does and we'll show you how Temper fits.

Or write to