Getting started
Introduction
What Temper gives your product, and the handful of objects you work with through the API and SDKs.
Temper gives each end user of your product their own long-lived cloud computer: a microVM with a persistent data disk, where your AI agent runs on that user's behalf. You drive it from your backend with an API key, through the REST API or the TypeScript, Python and Go SDKs. Temper keeps the user's real credentials out of the VM, limits where the VM can connect to, asks the user before risky actions, and records what happened in a tamper-evident audit log.
You bring the agent. Temper runs it, keeps its files across suspends and upgrades, and puts the guardrails around it.
Core objects
Environment
An environment is one end user's computer: a microVM plus a data disk. Each end user has at most one
environment that has not been destroyed. Your agent runs inside it as the agent user, and your backend can run commands, read and
write files, and start background processes in it. An idle environment is suspended and later stopped on its own; the next call
wakes it up again. Suspending, waking and upgrading the agent never lose data on the disk. See
data and upgrades.
Connection
A connection is an end user's authorization for a service such as Gmail, Google Calendar or Slack. The user approves access once
on the provider's consent screen. The real OAuth tokens are stored encrypted in the control plane and used only by the credential
gateway on the host; they never enter the VM. The agent uses built-in tools (temper-gmail, temper-gcal, temper-slack) that
reach the provider through that gateway. See credentials.
Secret
A secret is a credential of your own, such as a model API key or a token for an internal service. Like connection tokens, the real value stays in the control plane and the credential gateway. The VM only sees a stand-in token, and the gateway swaps it for the real value only on requests to the hosts you list. Together with each environment's egress allowlist, this means a prompt-injected agent has nothing useful to exfiltrate.
Policy and approval
Every action the agent takes through a connection or secret has a category (read, write, send, pay, delete,
change_permission, and so on). Your policy decides, per connector and category, whether the action is
allowed, denied, or needs the end user's approval. High-risk categories (send, pay, delete, change_permission) can never be
set to allow. When an action needs approval, Temper sends an approval.requested webhook to your backend; you show it to the user
and send back their decision.
Audit
Each environment has an append-only, hash-chained audit log of outbound connections, credential use, approvals and browser actions. You can query it, check that the chains are intact, and export the raw records to verify them offline.
Also available
- Browser: browser VMs with saved sign-in state, leased to an environment, and a takeover mode where the end user signs in or solves a challenge themselves.
- Usage and limits: per-environment usage and monthly limits you set.
- Team and keys: members, API keys and the webhook endpoint, managed in the console.
Where to go next
- Quickstart: create an environment, store a model key, connect Gmail, approve an action and read the audit log, in TypeScript, Python or Go.
- SDKs: installation, configuration, errors, pagination and webhook verification.
- Security: what Temper protects against and how.
- The API reference, generated from the OpenAPI specification.