Example trace. The agent only ever sees a stand-in token.
Product
A computer your users can trust their agent with.
Each end user gets a long-lived microVM with a trust layer around it. You bring the agent.
temper | computers
A full Linux computer for every end user.
Background services, a browser and an encrypted persistent disk. An agent can live there for months and follow up on tasks across days.
Long-lived microVM
One hardware-isolated VM per end user, with the agent in a sandboxed unit inside.
Encrypted data disk
Each user's files and memory sit on their own encrypted disk.
Suspends when idle
Idle VMs suspend on their own and wake on the next request.
temper | credentials
Real tokens never enter the VM.
The agent holds stand-in tokens. A credential gateway on the host swaps in the real ones on the way out, after checking the token belongs to this VM and this domain.
OAuth under your brand
Your users connect Gmail, Google Calendar and Slack through your own app.
Bring your own keys
Store your API keys once. Agents use them without ever seeing them.
Nothing to steal
A prompt injection that exfiltrates the agent's token gets a useless string.
temper | approvals
Risky actions wait for a real yes.
Sending email, paying, deleting data and other risky actions are held by policy and sent to your backend as signed webhooks. Consent never travels through the chat.
Policies you control
Set defaults for every environment and override them per user.
Signed both ways
Webhooks and decisions are signed, so the agent can't forge a yes.
Five grant scopes
Approve once, for a task, for a session, for a time window, or for good.
temper | browsers
Logged-in browsers, kept on a leash.
Lease a browser that remembers your user's login. The agent can navigate, read and type. It can't read cookies or run its own scripts.
Filtered on the host
Dangerous browser commands are dropped before they reach the browser.
Approval for sensitive forms
Payment, password and delete submissions wait for approval.
Human takeover
Your user can watch live and take control at any moment. The agent can ask for it too.
temper | upgrades
Ship new agent versions without losing memory.
Each upgrade gets a fresh VM, and the user's data disk moves across. Nothing is patched in place.
Gradual rollout
Start with a slice of users and widen in batches.
Health checks
Every swapped VM has to pass before the rollout continues.
Automatic rollback
A bad version rolls back on its own. User data stays put.
How it works
Every outbound action passes through a layer the agent can't touch.
We run the security layer. Neither the agent nor a hijacked prompt can change it.
01In the VM
Agent makes a request
It holds stand-in tokens only, so there is nothing valuable to leak.
02In the VM
Egress allowlist
Domains you haven't allowed are blocked. Every request is recorded.
03On the host
Credential gateway
Verifies the stand-in token, then swaps in the real one.
04Control plane
Policy check
Risky actions are held and sent to your backend as a signed webhook.
05Your backend
You decide
Ask your user however you like, then approve or deny.
Security
Built on the assumption that the agent is already compromised.
Protection can't depend on the agent behaving. It comes from boundaries the agent can't get around.
Tamper-evident audit log
Example
Every request, credential use and approval, hash-chained. Query it in the console or export it.
Time
Domain
Action
Decision
14:02:07
www.googleapis.com
read
allow
14:02:11
gmail.googleapis.com
send
approved
14:03:40
paste.example.net
write
blocked
14:05:02
slack.com
write
allow
Chain intact · seq 1842
Approvals in your product
Example
You get a signed webhook. You choose how to ask your user.
Send email to dana@example.com
gmail · send · expires in 10 min
Approve onceDeny
Egress allowlist
Example
Each environment can reach only the domains you allow.
gmail.googleapis.comallowed
slack.comallowed
api.openai.comallowed
paste.example.netblocked
Human takeover
Example
Your user takes the wheel. The agent is locked out until they hand it back.
mail.google.com
User in controlAgent locked
What we protect against
Credential theft
Real tokens never enter the VM. Stand-in tokens are bound to one environment and its domains.
Data exfiltration
The only way out is through the egress allowlist, and every request is logged.
Unapproved actions
Risky actions are held by policy. Approvals arrive only as signed callbacks from your backend.
Account takeover
One-time codes and reset links are filtered out of mail. Password and code submissions need approval.
Logged-in browser abuse
No cookie access or script execution in logged-in sessions. Users can take over at any time.
Escape and cross-tenant access
A hardware-isolated microVM per user, a sandboxed unit inside it, and a separate encrypted disk for each user.
Runaway spend
Per-environment spending limits, task timeouts and automatic suspend.
Developers
An API for your backend. A console for your team.
Give a user a computer with one call, then handle approvals as webhooks.
REST API
Environments, policies, approvals, audit, browsers and agent releases.
TypeScript, Python and Go SDKs
Typed clients and a webhook signature checker.
Console
Look up any environment, edit policies, search and export the audit log.
import { Temper, verifyWebhook } from "@temper-hq/sdk";
const temper = new Temper({ apiKey: process.env.TEMPER_API_KEY });
// One secure computer per end user
const env = await temper.environments.create({ end_user_id: "user_8f2c" });
// Risky actions arrive as signed webhooks
app.post("/webhooks/temper", async (req, res) => {
const event = await verifyWebhook(secret, req.rawBody, req.get("temper-signature"));
res.sendStatus(200);
if (event.type === "approval.requested") {
const { approval_id, summary } = event.data;
(await askYourUser(summary))
? await temper.approvals.approve(approval_id, { kind: "once" })
: await temper.approvals.deny(approval_id);
}
});
from temper_hq import Temper, verify_webhook
temper = Temper() # reads TEMPER_API_KEY
# One secure computer per end user
env = temper.environments.create(end_user_id="user_8f2c")
# Risky actions arrive as signed webhooks
@app.post("/webhooks/temper")
async def webhook(request: Request):
event = verify_webhook(SECRET, await request.body(),
request.headers.get("temper-signature"))
if event.type == "approval.requested":
approval = event.data
if await ask_your_user(approval["summary"]):
temper.approvals.approve(approval["approval_id"], {"kind": "once"})
else:
temper.approvals.deny(approval["approval_id"])
return {"ok": True}
import temper "github.com/temper-hq/sdk-go"
client, _ := temper.New(temper.WithAPIKey(os.Getenv("TEMPER_API_KEY")))
// One secure computer per end user
env, _ := client.Environments.Create(ctx, temper.CreateEnvironmentParams{
EndUserID: "user_8f2c",
})
// Risky actions arrive as signed webhooks
func handleWebhook(w http.ResponseWriter, r *http.Request) {
body, _ := io.ReadAll(r.Body)
event, err := temper.VerifyWebhook(secret, body,
r.Header.Get("Temper-Signature"), 0, time.Time{})
if err != nil {
http.Error(w, "bad signature", http.StatusBadRequest)
return
}
w.WriteHeader(http.StatusOK)
if event.Type == "approval.requested" {
var a struct {
ID string `json:"approval_id"`
Summary string `json:"summary"`
}
json.Unmarshal(event.Data, &a)
if askYourUser(a.Summary) {
client.Approvals.Approve(ctx, a.ID, temper.OnceScope())
} else {
client.Approvals.Deny(ctx, a.ID)
}
}
}
Package names and install commands are coming with the public release.
Who it's for
Teams whose agents act on behalf of people.
Agent startups
Personal assistants and sales, support or operations agents that work inside each user's mail, calendar and accounts.
Enterprise agent teams
Teams connecting agents to employee mailboxes, calendars and internal business systems, who need an audit trail that passes a security review.
Compare
How Temper differs from code sandboxes.
E2B, Daytona and Fly.io Sprites are good at what they are built for. Here is where the designs differ.
E2B / Daytona
Fly.io Sprites
Temper
Isolation
microVM or container
Firecracker microVM
microVM per end user, with a sandboxed unit inside
Lifetime
Mostly per session
Persistent, sleeps and wakes
Persistent, suspends and wakes
Credentials
Not built in
Organization-level connectors
Stand-in tokens, per-user OAuth under your brand
Risky actions
Not built in
No approval step
Policy and signed-webhook approval
Egress
Not built in
DNS allowlist
Domain allowlist with hash-chained audit
Wake from idle (p95)Benchmark pending
New or replaced VM readyBenchmark pending
We will publish numbers measured under the same workload, not targets.
Based on each vendor's public documentation as of October 2026. Tell us if something has changed.
Build agents your users can trust with their accounts.
We are working closely with a small group of design partners. Tell us what your agent does and we'll show you how Temper fits.