tunneler.ai · private beta

Governed identities
for AI agents.

Connect an account you own. Every action your agent takes, reply, post, DM, vote, email, gets a verdict, waits for your approval, and lands in an audit log, before anything ever leaves.

Owned accounts only. Not a bot army.

scroll
Watch it decide

The verdict happens before the send.

One connect flow, any account RedditEmailXLinkedInFacebookGitHub
What it is

Identity ops, not posting tools.

Tunneler decides which identity speaks, whether it should speak at all, whether it can link, and when a human takes over. Six parts do that work.

01 · CAPTURE

Real session capture

You log into your own account in a real browser, streamed to you. The session is captured server-side and encrypted at rest. No stored password, no automation fingerprint on the login.

02 · GATE

A verdict before every action

Identity fit, daily limits, link policy, disclosure, fake-customer and payment checks, run before the draft is written and again before it sends.

03 · HOLD

Human approval queue

First posts, promo links from young accounts, sensitive DMs and gray areas wait for a person. Sending stays off until you arm it.

04 · LOG

Append-only audit trail

Every action, every verdict, every permalink, written once and kept. You always know what happened and why.

05 · LIMIT

Per-account limits

Replies, posts, votes, DMs and promo links are capped per identity, so accounts season instead of getting flagged.

06 · ROUTE

Residential egress, by choice

Route an identity through a residential exit node so a workspace's accounts don't all originate from one address. Run your own, or draw from the pool.

The verdict is the interface

Every action gets one of three answers.

Guardrails run before anything leaves. The decision is the whole point, so it is the whole color language. Refusing to post is a feature.

Allow

decision: allow

Low risk, in policy, a genuinely useful reply. Send it.

Hold

decision: approval_required

A first post, a promo link from a young account, a sensitive DM. A human approves.

Stop

decision: block

Fake-customer testimony, ban evasion, spam. Refused, with a reason.

09:41:22u/plane-mbreply_posted · r/nodeposted
09:43:05u/plane-mbpost · promo linkapproval_required
09:44:18u/plane-mbcomment · r/dealsblocked
09:46:51support@youemail_sent · threadedposted
How it works

From login to governed autonomy in four steps.

1

Tunnel in

Open a relayed browser or paste a session. You log in; it's captured and encrypted.

2

Gate it

Guardrails score every proposed action against identity, limits, links and disclosure.

3

Approve

Risky actions land in a human queue. The arm switch is off by default.

4

Log

Every action and verdict is written to an audit ledger with evidence.

For agents

One key. Your agent runs the loop, governed.

Connect Claude Code or any agent over MCP or REST. It can reply, post, DM, vote and email, and every action still passes through guardrails, approval, and the arm switch. Programmatic never means ungoverned.

MCP · one line
# add the governed toolset to your agent
claude mcp add tunneler \
  -e TUNNELER_API_KEY=tnl_sk_… \
  -- npx tunneler-mcp
REST · propose a post
curl -X POST https://api.tunneler.ai/api/actions/propose \
  -H "Authorization: Bearer tnl_sk_…" \
  -d '{"identityId":"reddit-me",
       "actionType":"post",
       "subreddit":"test",
       "title":"Hello",
       "content":"Body"}'
Pricing

Start free. Add identities as you grow.

Self-host the core or let us host the tunnels. Plans set how many identities you run and whether you draw from the egress pool.

Free
$0
  • 1 identity
  • All guardrails
  • Approvals & audit log
  • Paste or upload sessions
Get started
Popular
Developer
$29/mo
  • 3 identities
  • One-click relay login
  • Egress pool access
  • Email support
Start Developer
Team
$99/mo
  • 15 identities
  • Shared approvals
  • Per-account limits
  • Priority support
Start Team
Growth
$499/mo
  • 60 identities
  • Audit export
  • Priority egress
  • SSO & SLA (soon)
Talk to us
FAQ

The honest answers.

Is this a bot army?

No, the opposite. Tunneler is for owned, transparent identities you control. It refuses spam, mass DMs, fake reviews, ban evasion and impersonation. This is governance, not growth hacking.

Where are my sessions stored?

Captured cookies and email credentials are encrypted at rest with AES-256-GCM and scoped to your workspace with row-level isolation. We reference your session, we never expose it, and you can disconnect any time.

Will anything send by accident?

No. A send requires both an allowing verdict (or a human approval) and the master arm switch on. It's off by default, so every run is a safe dry-run that shows exactly what would be sent.

Can a node operator see my traffic?

No content. Traffic is TLS end-to-end and we validate the platform's certificate, so a node can't decrypt or intercept it, and it can only ever reach our supported platforms. It just relays encrypted bytes.

Can I self-host?

Yes. The engine, API and browser worker run as containers. Host the tunnels on your own infrastructure for a stable, consistent egress, with the same guardrails, approvals and audit log.

Give your agents a passport to the internet.

Governed identities, a verdict before every action, a full audit trail.