Agents Don't Just Read Your Tools. They Act.
Create branches, open PRs, monitor CI, analyze customer feedback, generate documents. All with full audit trail.
Bring your own MCP servers, your own models and your own machine. Included on every plan.
If it speaks MCP, it's already connected.
Point Neuphlo at any remote MCP server and its tools appear to your agents next to the built-in ones. Your internal systems, a vendor's server, something your team wrote last week. No waiting for us to build a connector.
You decide which agents get which tools, and every external tool call stops for your approval before it runs.
Connect in one paste
Add a server URL over HTTP or SSE, or paste a standard mcpServers JSON config and import every server in it at once. Tools are discovered on connect and re-checked whenever you test the connection.
Namespaced per server
Each server gets its own prefix, so two servers can expose a tool with the same name without colliding, and an agent's tool list always says where a tool came from.
Scoped per agent
Pick exactly which tools each agent can call. Restrict an agent to a handful, or allow all. Anything outside the scope is not in the model's tool list at all, so it cannot be talked into using it.
Approval before it runs
Every external MCP tool call surfaces as an approval before it executes. Read or write, the gate is the same.
Credentials stay on the server
Tokens and headers are stored with the server record, never returned to the browser, and never placed in a model prompt. They are attached to the outbound request and nowhere else.
Your network, your rules
On cloud, servers are reached over public HTTPS and private address ranges are blocked. Self-host and your agents reach the MCP servers already running inside your network.
Remote HTTP and SSE servers. Local stdio servers that launch a command on the host are not supported.
Give your agents a machine of their own.
Most tools hand an agent a list of things it is allowed to click. Point the Neuphlo runner at a project on your own machine and your agents work in it: reading and changing files, running commands, running the test suite, using the same developer tooling your team already has installed.
Your code never leaves the machine it is on. Neuphlo sends the work and gets back the result, and every step lands in the same audit trail as the rest of your workspace.
One command, one directory
npx @neuphlo/runner in the project you want worked on. Claude Code, Codex, Gemini CLI or Cursor, whichever your team already uses. Run several at once on different ports for different projects.
Signed in the way you already sign in
The runner uses whatever your CLI is authenticated with, subscription login or API key, whichever you set up. You do not hand Neuphlo a model credential at all. Or skip the runner and connect Anthropic, OpenAI, Gemini, OpenRouter, Ollama or any OpenAI-compatible endpoint directly.
Real work, not a sandboxed tool call
Files get edited, builds get run, tests get run, output comes back. When something has no API, the agent uses the command line the way a person would.
Workspace actions stay on Neuphlo
Creating a task, updating a page, sending an email: those execute on Neuphlo under the workspace identity of whoever started the run, with the same permissions they have in the app. The runner cannot widen its own access.
Isolated per request
Each CLI is launched into a throwaway home directory containing only Neuphlo's callback bridge, and calls back signed with a token that expires in fifteen minutes. A runner cannot act against a workspace that did not call it.
Runs where you run
The same providers and the same runner on cloud or fully self-hosted. Air-gapped installs default to a local model with nothing leaving the network.
And the ones we already wired up
Common tools, connected and ready, with the same scoping, approvals and audit trail as everything else.
Access you can hand to your security team.
Connecting a tool is the easy part. What matters afterwards is who acted, under whose permissions, and what you can undo.
Runs under a real identity
Every action an agent takes resolves to the person or token it is acting for, with their workspace permissions, not a shared service account.
Tamper-evident log
Agent actions are written to a hash-chained audit log where each entry seals the one before it. Editing history breaks the chain and verification says so.
One-click rollback
Changes agents make to your tasks, pages, courses and question banks are snapshotted before and after, and revert in a click. The rollback is logged too.
Included on every plan
Every integration, MCP servers, your own models and self-hosting are on all plans. No connector tiers, no per-integration pricing.
Ready to Connect Your Tools?
Start free, no credit card. Bring your own MCP servers and your own models from day one.
