Skip to contentWitnora
Menu
Witnora documentation / Updated 2026-09-06

Connect an Agent. Follow its evidence.

Start with one repository, choose an Action transport, and inspect the first recorded or independently checked result. Raw prompts and credentials stay local.

Start here

Authorize one repository with one command.

Create a Hosted project, run the command inside the agent repository, and approve once in the browser. Witnora saves a restricted connection, verifies the local path, then guides one real sandbox workflow into the first reviewable run.

Follow the quickstart
terminal
npx witnora@latest onboard --project your-project-id

One-time browser authorization

Restricted credential stored outside the repo

Synthetic receipt isolated from CURRENT

First real sandbox run reviewed separately

Two-hour covered-path path

Move from synthetic evidence to one isolated sandbox action.

Declare one action, keep write and read credentials separate, run the Gateway and customer-operated Probe, then verify the packet against a separately pinned trust root.

Open the design-partner guide
privacy boundary

Raw prompts and credentials stay local

Single-use grant binds the exact action

Customer-operated read path checks outcome

Offline verifier checks signatures and limits

Answer one assurance question

01What may this agent do?

Declare identity, capabilities, mandates, and controlled boundaries.

02Is this release still trusted?

Bind scope, run authoritative checks, and detect drift.

03Should this action proceed?

Evaluate policy, approval, execution grant, and observed outcome.

04Who can prove the result?

Inspect provenance, signatures, manifests, and evidence strength.