The control plane for Orbio-powered agents

Connect Orbio.
Control every
agent.

Every user connects an isolated Orbio account. Every agent gets its own identity, budget, model rules, and kill switch. Gateway keys stay encrypted; prompts and responses stay out of the ledger.

Your Orbio 1 encrypted tenant
A1research
A2coding
A3ops
Guard
active
430Orbio models governed by Guard
73automated checks passing
HTTP 200live Codex + tool round trips
0prompts or secrets logged

The missing layer

Orbio powers the agent.
Guard makes it operable.

Cloudflare Access identifies the user. OAuth connects their own Orbio account. A private Durable Object isolates their keys, agents, budgets, and metadata-only activity.

01

Connect

Sign in, approve Orbio OAuth, and encrypt the gateway key inside your isolated tenant.

02

Issue

Create separate agent tokens with daily budgets, request ceilings, and model policies.

03

Run

Use Codex, Claude Code, or an SDK while Guard reserves and reconciles real Orbio spend.

Built and verified on Orbio

Not another agent wrapper.
Control for text and tool agents.

live verification · secrets removed
$ codex exec "Use pwd, then report the directory"

model: gpt-5.6-sol
provider: orbio_guard

exec  /bin/zsh -lc pwd
✓ /Users/developer/project

Codex: /Users/developer/project

Real Codex. GPT-5.6 Sol text and shell-tool turns completed through Guard.

Real accounting. Provider cost replaces the atomic reservation after inference.

Real isolation. One encrypted Orbio connection and Durable Object per authenticated user.

Real enforcement. Model, request, budget, pause, and disable decisions happen before gateway forwarding.

Built on Orbio MCP

Orbio provides the intelligence.
Guard makes fleets safe.

Connect Orbio