Nothing is shared by default. Only capabilities explicitly published by the Core user can enter a client Grant. Cloud models, Terminal, Secrets, browser control and host-side-effect Tools are not exportable. Shared Agent Sessions are isolated per Grant and cannot approve sensitive interactions remotely.
Cloud gateway federation
Share selected exports or connect a Parent Local through AI2Apps Cloud
Cloud NodeLinksUpstream links can receive a capability grant; downstream links use the credential stored only on that Local.
Local network access
Core controls whether other LAN devices can reach this Local
Full Local mode makes the login page, Shell and authorized App APIs reachable on your LAN. Account, Role and App permission checks remain active. Use this only on a trusted home or business network.
Publish capability
Explicitly select a model, Tool, Service, or Agent; all remain private by default
External API billing
This model uses an API Key stored on this device. Calls made by shared clients are billed to that Provider account. The Provider API Key is never sent to the client.
This model uses an API Key stored on this device. Calls made by shared clients are billed to that Provider account. The Provider API Key is never sent to the client.
Agent authority
Publishing an Agent permits it to run with its locally configured model and capability policy. Remote clients cannot approve pending sensitive interactions, and every Session remains bound to its client Grant.
Publishing an Agent permits it to run with its locally configured model and capability policy. Remote clients cannot approve pending sensitive interactions, and every Session remains bound to its client Grant.
Published capabilities
Select active exports when creating client access
Create client access
Credentials are displayed once and can be revoked independently
Client access
Usage metadata only; prompts and Tool arguments are not stored here
Parent Locals
Use selected models and MCP capabilities from a higher-level Local without opening its Apps
Nearby AI2Apps LocalsBonjour discovery reveals endpoints only. Access still requires a scoped QR from that Local's Core user.
The Share Token goes directly to this device's secure credential provider. Parent Node IDs and live ancestry are checked on every health probe to reject A → B → A loops. Parent Apps are never imported or opened.
Recent parent activityMetadata only. Prompts, responses and Tool arguments are not recorded.
Scan parent access QR
Point the camera at the one-time QR shown by the parent Local.