[Treliso For agents](https://treliso.com/)

# Build with an agent. Share what you make.

Help your agent take a project from an idea to a link you can share. Use SSH or the customer HTTP API; hosted MCP is available when enabled for your deployment.

## Start with a workspace

Complete SSH signup as a person first. Verify your email and approve your SSH key before giving an agent access to your workspace.

```sh
ssh treliso.dev
```

The [first-app guide](https://treliso.com/docs/) covers the guest environment, uploads, and HTTPS. An agent using your SSH client has the same privileges as that SSH session, so review the commands it runs.

## Connect with MCP

**Check availability first.**

MCP and guest control are deployment features that default to disabled. The endpoint and managed application tools are available only after the deployment operator enables them.

When enabled, Treliso hosts a remote MCP endpoint at:

```text
https://treliso.dev/mcp
```

Use an MCP client that supports remote Streamable HTTP and browser OAuth. Add the server URL to your client, then follow its browser authorization flow. Sign in, review the requested scopes, and approve only the access your task needs.

```
{
  "mcpServers": {
    "treliso": {
      "url": "https://treliso.dev/mcp"
    }
  }
}
```

This is an illustrative configuration shape. Your client may use a different format; use its remote-server setup instructions. Keep login credentials out of prompts and tool arguments.

### What an authorized agent can do

-   Inspect accounts, permissions, and VMs.
-   Request VM lifecycle changes and inspect asynchronous operations.
-   Work with supported guest commands, bounded file reads, and uploads when guest control is enabled.
-   Manage applications and domains with the scopes and account role the operation requires.

The server’s advertised tools are the source of truth for your deployment. Host administration and snapshot, restore, or clone operations are outside the customer MCP tool registry.

## Use the HTTP API

The HTTP and MCP interfaces share customer operations and validation. Existing API clients can use bearer authorization for the JSON endpoints.

[Open the API schema](https://treliso.dev/api/openapi.json)

Use the generated OpenAPI schema to inspect operation names, request fields, and authorization requirements. VM lifecycle changes are asynchronous: keep the returned operation ID and inspect completion before taking the next step.

## Know the boundaries

-   **A VM is an execution environment.** Guest commands run in the VM. SSH currently opens a root shell inside that guest.
-   **Permissions still apply.** An agent does not bypass account roles or the scopes approved during authorization.
-   **Runtime support is specific.** The current minimal Linux guest requires compatible executables; it has no package manager, dependency downloads, or container runtime.
-   **Public HTTPS needs app authentication.** Add your own login layer before exposing private information.

Ready to try a first app? [Follow the guide](https://treliso.com/docs/)

---

Source: https://treliso.com/agents/
