
Agent Tunnels
Secure shared sessions where AI agents from different companies collaborate with human oversight
Gallery
About Agent Tunnels
Agent Tunnels creates shared sessions where AI agents from different companies can collaborate without compromising security or bypassing human oversight. The product addresses a friction point that has emerged as coding agents become common across organizations. When a customer needs technical support from a vendor, the coordination currently happens through Slack or email, which devolves into a copy-paste mess of screenshots, code snippets, context files, and version confusion. Both parties might have their own AI agents, but those agents cannot talk to each other. Agent Tunnels provides a dedicated environment where they can, while humans retain approval authority over any actual changes.
The workflow follows five steps. First, a customer initiates contact through Slack or another channel. Second, one party shares an Agent Tunnel invite link. Third, both sides add their agents to the session. Fourth, the agents coordinate directly, reading shared context, proposing changes, and iterating on solutions together. Fifth, humans review what the agents produced and apply only the solutions they approve. The critical constraint is that nothing touches the customer's codebase without explicit sign-off. A vendor's agent can suggest a fix, walk through its reasoning, and even prepare the diff, but a human on the customer side must authorize it before anything gets applied. This approval layer is what makes cross-company agent collaboration practical for sensitive codebases.
Security architecture reflects this principle throughout. Code repositories remain isolated with the customer, and vendor access is limited to collaboration within the session itself. Vendor agents operate in a read-only posture by default. They can see what the customer shares, they can analyze it, they can propose edits, but they cannot push changes directly. The customer's agent retains write access to its own environment, and the customer's human retains veto power over any action. This lets companies bring in external expertise, whether from a SaaS vendor troubleshooting an integration, a contractor debugging a module, or a partner contributing to a joint project, without handing over the keys to the repository. The security model treats agent collaboration like a screenshare with guardrails rather than a merge request with full permissions.
Agent compatibility is broad. The platform supports agents built on Claude, Cursor, OpenAI, OpenCode, and OpenClaw. Development teams rarely standardize on a single model provider, and even within one team the frontend engineer might use Cursor while the backend engineer prefers Claude. A collaboration tool that requires everyone to switch to the same agent would create adoption friction that defeats the purpose. Agent Tunnels accommodates whatever agents the participants already use, so the tool slots into existing workflows rather than replacing them. You bring your agent, the other party brings theirs, and the tunnel handles the handshake.
The session itself is structured around a shared context space. Both agents can reference files, propose code, and discuss approaches. The interaction happens in a format both humans and agents can follow, so observers can track the reasoning as it unfolds. History is preserved for the duration of the tunnel, which means a session can span multiple days if the debugging takes time. For complex issues that require back and forth, this persistence avoids the loss of context that happens when conversations fragment across Slack threads and email chains. User history tracking within the platform lets participants return to previous sessions and pick up where they left off.
Agent Tunnels is currently in beta, which is visible in the sparse documentation and absence of published pricing. There's no cost yet. Users can sign up via email-based authentication, create tunnels through the dashboard at the new endpoint, and start sessions immediately. Support runs through a Crisp chat widget on the site, which suggests a small team handling feedback directly during the early access period. Published terms and a privacy policy are already in place, indicating the product is being positioned for serious use even during beta. This beta status also means the feature set may evolve, but the core functionality, shared sessions with approval-gated changes, is live and usable today.
The target audience is development teams that regularly coordinate with vendors, contractors, or partner organizations and want their agents to participate in that coordination without sacrificing control. It's a narrow use case, and that's by design. Not every team needs cross-company agent collaboration. But for teams deep in agent-assisted development workflows, the friction this removes is tangible. The alternative is the Slack copy-paste dance, which wastes time, loses context, and makes agents less useful than they could be. Agent Tunnels is essentially a secure meeting room for agents where nothing leaves without a human signature.
Key Features
- Shared agent sessions across organizations
- Human-in-the-loop approval for changes
- Read-only vendor agent access by default
- Support for Claude, Cursor, and OpenAI agents
- Slack integration for invitations
- Multi-agent collaboration in one tunnel
Pros & Cons
What we like
- Vendor agents cannot edit customer code without approval
- Supports multiple AI agent platforms in one session
- Replaces messy Slack copy-paste coordination
- Beta access is currently free to use
Room for improvement
- Currently in beta with no published pricing
- Narrow focus on cross-company agent workflows
- Requires both parties to adopt the platform
- Smaller community given early stage
Frequently Asked Questions
What is Agent Tunnels?
Is Agent Tunnels free?
Which AI agents does it support?
Can a vendor agent modify my code directly?
Best For
Featured in
Alternatives to Agent Tunnels
View all
Almanac
A hosted, source-cited wiki that turns your files into context your AI agents can use

Demi AI
Demi helps busy professionals eliminate repetitive admin work across their favorite tools.

Chariot
Elastic cloud infrastructure for deploying and scaling AI agent fleets with persistent storage

Meltbox
A personal workspace and inbox for your AI agents to reach you wherever they run
Reviews (0)
Badge builder
Add Agent Tunnels to your website
Choose a badge style and size, preview it here, then copy the generated HTML. Badge images are self-contained SVGs and do not require an external script.
<a href="https://toolindex.net/tools/agent-tunnels?ref=badge" target="_blank" rel="noopener">
<img src="https://toolindex.net/badge/agent-tunnels/medium.svg" alt="Agent Tunnels - Listed on Tool Index" width="180" height="50" />
</a> How to use the badge
- 1. Pick the style, size, and theme that fit your layout.
- 2. Copy the generated HTML from the code block.
- 3. Paste it into your footer, homepage, or press page.
Standard badge available
The standard listing badge is available now. Score and circle badges are limited to tools currently ranked in the top 10 of a category.
Badge clicks return visitors to this profile with a referral tag so the source remains identifiable.
Related Tools

OpenBenchmarks
Public, externally validated benchmarks that help agents pick SaaS APIs

Almanac
A hosted, source-cited wiki that turns your files into context your AI agents can use

Wizard
Self-extending Rust terminal AI agent that works with any model

Chariot
Elastic cloud infrastructure for deploying and scaling AI agent fleets with persistent storage
Work on Agent Tunnels? Request listing access or correction