Connect with your coding agent
A guided plan, private local credentials and one browser approval connect your agent to your account.
On this page
Local software detection
leash detect --json runs a small local CART classifier on six boolean environment markers: active Codex/Claude context and executable/config presence. Its original training and evaluation use synthetic marker fixtures, not user conversations. No credential value, context identifier or source file goes into the model or cloud.
Explicit setup choices override classification. A model prediction must agree with independently observed adapter evidence; ambiguous or absent software requires an explicit --agent choice. This software classifier does not decide task quality or replace Leash's explicitly configured request-model policy.
Approve once, in your own browser
Open Connect an agent in your dashboard. A five-step conversation asks about your goal, agent, local or managed runtime, session/day caps and model policy. A live plan updates alongside your answers. Save it to your account, then copy or download the personalized installation prompt.
Your saved setup is private to your user and workspace. The prompt contains a setup identifier, not an access token. After browser approval, leash connect --setup fetches that plan, installs the adapter, and applies local settings without raising stricter caps or clearing kill state. A saved plan is not a connected device; use Check connection and leash status to verify installation.
The agent must show you the verification URL and code. You approve it in your own signed-in browser. That account and workspace are the authority; a workspace name in a prompt cannot grant access.
leash connect --agent codex --api https://useleash.dev --no-browser
leash whoami
leash doctor
leash run -- codexNo repeated provider-key entry
Device transport is the default. Import an existing provider key from your own shell with leash secrets import. The authenticated-encrypted vault stays on this machine, with macOS Keychain preferred for its master key and an explicitly identified private-file backend elsewhere. The install prompt never asks you to paste a secret.
The agent receives a harmless placeholder, and the authenticated local proxy injects the real credential only at the official provider endpoint. A normal host process still shares your OS permissions; use the managed runtime to isolate it from the host vault. Neither the provider key nor the code index is uploaded during device sync.
An optional, explicit --mode gateway can use an administrator-approved encrypted workspace connection and a scoped per-user virtual key. This is separate from the local default. Leash never extracts OAuth sessions or assumes signup grants provider access; missing and untested credentials are reported honestly.
Managed network and memory controls
A host process is not a sandbox. To enforce destination allowlists and adaptive memory limits, run the command inside the Docker-managed runtime. This requires a supported Docker engine and a suitable agent image.
leash sandbox run --help
leash xray