NVIDIA OpenShell

Open, secure runtime for AI agents.

Overview

Secure Runtime for Every Agent

NVIDIA OpenShell™ is an open, secure runtime for agents. It governs agent execution, access, and where inference goes. 

Security lives in the environment, not the model or the application. Nothing is permitted by default, permissions are granted based on policies, and enforcement happens outside the agent’s process, where it can’t be prompted away or bypassed. Every allow and deny is auditable.

Any model, any harness, any agent—across cloud, hybrid, on-prem, edge, and air-gapped infrastructure—under one policy layer.

NVIDIA Open Agent Safety Platform

NVIDIA Open Agent Safety Platform gives enterprises the controls to deploy and scale fleets of AI agents with confidence.

Add Runtime Controls to AI Agents With NVIDIA OpenShell

Learn how NVIDIA OpenShell adds enforceable controls outside an existing agent to protect credentials, restrict access, and review policy changes without rewriting its harness.

Benefits

Govern Your Agents

Run autonomous agents within boundaries you control, with consistent policy enforcement across models, harnesses, and deployment environments.

Agent-Native Infrastructure

OpenShell separates how agents work from how they interact with their environment and the rest of the world. The agent’s behavior is monitored and every action is governed.

Deployment Flexibility

Run open or closed models with your choice of agent and harness across cloud, hybrid, on-premises, and air-gapped infrastructure. Govern your agent fleet through one unified policy layer.

Deterministic Governance

Deny access by default and grant permissions based on intent. OpenShell enforces policy outside the agent process, independently of the agent’s reasoning or cooperation.

NVIDIA Open Agent Safety Platform

NVIDIA Open Agent Safety Platform is an open reference system design that combines the NVIDIA OpenShell secure runtime and NVIDIA Sentry with NVIDIA BlueField™-4 in-silicon security enforcement.

Architecture

OpenShell Components

Agent Sandboxes

Each agent runs in its own isolated sandbox with no direct network access. OpenShell runs the agent without privileges and limits the files it can reach. It monitors and filters the agent's system calls in the kernel, blocking unsafe calls and brokering the agent's requests to the supervisor through a single secured channel for approval.

Policy Prover

The policy prover is OpenShell’s policy verification engine. It uses formal verification to check whether policies stay within an allowed access boundary and whether proposed network rules add risky access compared with the sandbox’s current policy.

Gateway

The gateway is OpenShell's control plane. It authenticates users, manages the sandbox lifecycle, and delivers policies, settings, and credentials to each sandbox's supervisor. It decides who can do what and brokers all access to sandboxes.

Supervisor

The supervisor runs outside the sandbox, oversees the agent at runtime, and connects the sandbox to the gateway. It evaluates every network request against policy at the binary, destination, method, and path levels and supplies credentials only where policy allows. Policy updates apply live, and every “allow” and “deny” decision is logged for a full audit trail.

Ecosystem

AI and Security Leaders Adopt OpenShell

Leading AI labs, AI infrastructure providers, and critical infrastructure companies have adopted OpenShell.

NVIDIA AI Security Research

Explore NVIDIA research on securing AI systems and strengthening cyber defense, including runtime controls for autonomous agents with OpenShell. Through open research and contributions to the Open Secure AI Alliance, NVIDIA shares methods and technical artifacts that help security teams validate findings and build stronger defenses.

Resources

OpenShell and More

Explore the full NVIDIA Open Agent Safety Platform, agent harness design, governing agents in enterprise AI factories, and more in the blogs and videos below.

Blogs

Next Steps

Ready to Get Started?

Try OpenShell.

Build

Access the open source OpenShell repository on GitHub.

Documentation

Learn more about OpenShell by exploring the documentation.

FAQs

The immediate users are developers building autonomous agents, platform teams enabling those developers, and security or IT teams that need a safer way to govern agent execution.

For developers, OpenShell provides a safer runtime for agents that use tools, write files, call APIs, or run for long periods. For enterprise IT and security teams, it provides a path to enable agent development without handing every agent broad access to the host, network, credentials, or model endpoints.

Learn more about NVIDIA Cybersecurity and NVIDIA AI   Security Research.

OpenShell supports agent paths such as Claude Code, Codex, GitHub Copilot CLI, Hermes, LangChain Deep Agents, OpenClaw, OpenCode, and others. OpenShell is intended to be model-agnostic and harness-agnostic, so teams can also bring custom agents and custom sandbox images.

Developers and enterprises want the productivity of autonomous agents, but they need stronger controls over what those agents can access and change. OpenShell addresses that gap by putting policy enforcement, credential handling, sandboxing, and inference routing in a boundary outside of the agent.

No. OpenShell is not another agent framework. It is designed to sit underneath agent frameworks and harnesses, including Claude Code, Codex, OpenCode, OpenClaw, and custom agent stacks.

No. A sandbox isolates a process from the host for a bounded task. OpenShell is a runtime that governs agent actions across their lifetime.

That runtime includes sandboxing, but also gateway-brokered credentials, identity boundaries, policy-as-code, policy-enforced egress, inference routing, audit/state, and boundaries for multi-agent or sub-agent workflows. The distinction matters because autonomous agents need governance over time, not just one-time process isolation.

No. OpenShell integrates with the enterprise ecosystem rather than replacing it. Identity providers, secret stores, observability systems, security tooling, and governance platforms remain important surrounding systems.

OpenShell’s role is to provide the agent runtime boundary and enforce OpenShell policy consistently across the selected runtime.

Docker containers and Kubernetes pods are runtime substrates. OpenShell uses runtimes such as Docker, Podman, Kubernetes, and VM isolation, but adds agent-specific control: gateway coordination, sandbox supervision, policy-enforced egress, provider credential handling, inference routing, and logs.

The practical difference is that OpenShell is designed around the actions agents take, not just around starting a container or pod.

OpenShell is designed to run where developers run agents: local developer systems, on-prem environments, hybrid environments, and cloud infrastructure.

Supported compute paths include Docker, Podman, Kubernetes through Helm, and experimental VUM runtime.

Yes. OpenShell has a Helm chart that deploys the gateway into a Kubernetes cluster, and the Kubernetes runtime creates sandbox workloads through Kubernetes APIs.

Yes, via Podman, Docker, Kubernetes, or VM, OpenShell can run on NVIDIA DGX Spark™ or NVIDIA DGX Station™. DGX Spark and DGX Station are strong targets for local and private agent development because they let teams keep the agent runtime, data, and model access inside a controlled environment.

Yes. OpenShell includes a policy-aware inference router which forwards permitted requests to cloud model endpoints.