How it works
nebo-link runs next to your agents and makes two outbound connections to NeboAI: one
that reports the bot is online, and a tunnel that carries requests from the app to the agents. It
opens no ports and needs no VPN. Each agent keeps its own sign-in on the computer; NeboAI never sees
those credentials.
Link a computer
Get a code from the NeboAI app, then run the installer on the computer where your agents run. The installer checks the download's signature before running it and stops if the check fails.
# macOS and Linux curl -fsSL https://neboai.com/link.sh | sh -s -- ABCD-1234 # Windows (PowerShell) & ([scriptblock]::Create((irm https://neboai.com/link.ps1))) ABCD-1234
This pairs the computer with your account as one bot and installs nebo-link as a
background service: a launchd agent on macOS, a systemd user unit on Linux, and a logon task on
Windows. --name sets the bot's name and --label the first agent's.
Add agents
Every other agent on the computer joins the same bot. Agents that speak the Agent Client Protocol
(ACP) can be added by the command that starts them in ACP mode. --dir is the folder the
agent's conversations work in.
nebo-link add --acp-command "example-agent acp" --dir ~/code/site --label "Site agent"
A coding agent runs on its own sign-in. Its permission prompts arrive as cards in the chat and items in the owner's inbox, and the employee's permission mode in NeboAI sets the agent's own mode for each conversation.
Commands
| Command | Does |
|---|---|
nebo-link <code> | Links this computer as a bot, with its first agent. |
nebo-link status | Shows what is linked, the agents it hosts, and whether it is online. |
nebo-link add <agent> [--dir <folder>] [--label <name>] | Adds an agent to the bot. --acp-command adds any ACP agent. |
nebo-link remove <agent id> | Removes an agent. |
nebo-link models on|off | Routes an agent’s models through NeboAI, or restores its own provider. |
nebo-link logs [--lines N] | Prints the service’s recent log. |
nebo-link unlink | Restores every changed setting, removes the service and forgets the bot. |
nebo-link update | Installs the latest signed release. The service also updates itself daily. |
Every change Nebo Link makes to an agent's configuration is recorded with the value it replaced, so models off and unlink restore it exactly. Each bot's files live in ~/Library/Application Support/nebo-link/<bot id> on macOS, ~/.local/share/nebo-link/<bot id> on Linux and %APPDATA%\nebo-link\<bot id> on Windows, or under NEBO_LINK_HOME.
Open Agent Link
Open Agent Link (OAL) is an open protocol for reaching agents on any computer: the Agent Client Protocol, made reachable, plus a thin host layer. The specification is published at openagent.link under CC-BY-4.0.
| Part | Definition |
|---|---|
| Agent | Speaks ACP over standard input and output. |
| Host | One per computer and user; runs agents and serves them. Nebo Link and Nebo are hosts. |
| Client | An app that talks to a host. |
| Relay | Optional. Forwards traffic between clients and hosts that cannot reach each other. |
| Transport | WebSocket (wss over the internet) with subprotocol oal, one JSON frame per message. Host messages are JSON-RPC host/* methods; agent traffic is ACP wrapped as {"agent": "<id>", "acp": <message>}. |
| Pairing | A single-use eight-character code shown as XXXX-XXXX. The relay routes on the first half and never sees the second. |
Nebo Link serves every agent it hosts over OAL as well as to NeboAI, and encrypts every connection end to end, so a relay forwards traffic it cannot read.
nebo-link relay https://relay.example.com # reach agents through your own relay nebo-link lan on # or directly on this network nebo-link pair # show a one-time code for a device nebo-link unpair "Office tablet" # remove a device
Client SDKs are available for TypeScript (@openagentlink/client) and Python
(openagentlink). A self-hostable relay and a conformance suite are part of the Open Agent Link project; passing the conformance suite is what
makes a host or client compatible.