The agent runs in the cloud. The work runs on your machine.
oiia is the product. SubgroupX is the team that builds it. The mark above is the same lockup the app wears in its own top-left corner, captured from the running product rather than redrawn.
oiia is a multi-user agent platform you reach from a browser. Sessions are durable server-side objects, not browser state — but the interesting part is the other end. Where a session executes is a per-session choice, and that includes machines nobody can route to.
Your machines are the execution side. Four sandbox backends sit behind one Sandbox interface,
and a session picks one at creation:
| Backend | Reaches | How |
|---|---|---|
connector |
a machine with no public IP | a daemon you run dials out over WebSocket; the server never initiates. No port forward, no inbound rule, no VPN. |
ssh |
a host you have a key for | ordinary outbound SSH from the server, with its own guard and unlock path |
e2b |
a disposable cloud VM | isolated exec and files, idle-paused with state preserved |
local |
the server itself | path-scoped working directory; bwrap on Linux, seatbelt on macOS |
The connector is the one worth the paragraph. A laptop behind NAT, a lab box on a corporate network, a machine that exists only on Tailscale — the agent works there, on the real files, in place. The UI is identical across all four: same file tree, same interactive terminal, same approval gate. Swapping the target does not change how you work.
That panel is not a screenshot on the landing page — it is the shipped component, running, on numbers
declared as sample. check:layout forbids the module it lives in from importing the API client at
all, so "the public page never attempts an authenticated request" is a property of the module graph
rather than a claim in a comment.
Many agents, and a way to run them. spawn_subagent delegates to a child whose run streams as a
nested timeline. Beyond that there is durable orchestration: an agent tree persisted in SQLite, a
task queue with a permit-based dispatcher, agent teams that span sessions with a shared queue, and
declarative workflows. Agents are addressable — you can steer one mid-run, follow up on a finished
one, and see the whole tree live rather than discovering at the end what your fleet did.
It can do the security work. Alongside the default coding profile, a session can be created under a profile scoped to authorized assessment. A deployment may provision its own model channel for those profiles rather than depending on a consumer endpoint, and provider refusals are classified as a named signal — surfaced to you and to the agent as a specific outcome, instead of a turn that stops with no explanation. The E2B template ships the tooling to match: Java 8/11, recon tools with SecLists, WASM reversing (wabt, wasm-tools, binaryen, twiggy, wasmtime/wasmer), mise/uv, playwright, and the lynx/w3m text browsers.
Sessions outlive the tab. They run on the server. Refresh, lose the network, deploy over them, or come back on a phone — the run continues and the whole history replays in order. The database is the source of truth and the live runtime is a rebuildable cache, which is what makes idle-release, session-switch, redeploy and rewind the same operation: dispose, then lazily rehydrate.
Every device, nothing to download. It is a PWA: display: standalone, maskable icons, and a
service worker that caches the shell and assets per build, so it installs to the home screen on iOS
and Android straight from the browser — no app store, no APK, no TestFlight. Installed or not, it is
the same app against the same sessions, which is the part that matters: start something on a laptop,
watch it from a phone on the train, approve a command from a tablet. There is no sync protocol to go
wrong because there is nothing to sync — the session was never on your device to begin with.
Also included, because a product needs them but nobody switches tools for them: a workspace file tree with preview and uploads, three approval policies, reconnect with replay, MCP servers as first-class tools, share links that redact secrets, an audit log, and Mermaid / KaTeX / syntax highlighting in the transcript.