Describe the result
Ask in everyday language. You do not have to choose every tool or computer before you begin.
Hawkeye connects the AI tools you already use across enrolled computers. Give each task only the access it needs, inspect connected work and its privileged-action record, and bring in a person when the workflow exposes a real decision or handoff.
Ask in everyday language. You do not have to choose every tool or computer before you begin.
It brings together approved AI clients, connected tools, project context, browsers, and enrolled computers.
Inspect progress and authority, answer genuine requests, and step in where human judgment is required.
New to AI agents? An agent is an AI worker with a job and rules. A session is one running copy of that worker or tool. Hawkeye keeps their identity and authority explicit.
These scenarios explain the production interaction model. They do not execute work or represent connected customer systems.
Every card leads to a real public route or sign-in boundary. No usage totals, customer logos, certifications, or simulated success states are presented as evidence.
Turn one request into work across approved AI clients, connected tools, browsers, files, and enrolled computers.
Start with the tools you already use Connect your AIInspect connected machines, sessions, requests, and recorded privileged actions without presenting illustrative activity as live data.
Live organization data appears only after sign-in Open your workspaceWork from the web and desktop today, with every published download and mobile availability stated at its verified level.
Platform-specific availability and signatures See downloadsKeep credentials out of prompts and grant only the project, resource, subject, purpose, and time the work needs.
Concrete pairing, scope, and revocation facts Review securityRoute genuine approval and decision requests through configured channels while keeping duplicate responses from becoming duplicate actions.
Notification channels stay optional See how requests workReach shell, desktop, browser, and file tools through the machine's own outbound connection—nothing on the internet dials in to it.
Single-use enrollment links and outbound tunnels Add a computerMove approved files and instructions across connected machines and organizations with explicit authority and an attributable record.
Cross-organization work remains a request Read the documentationHawkeye is built for teams that want AI clients to do useful work while keeping tenant boundaries, access, revocation, and attribution concrete.
Explore the trust modelNo. Hawkeye connects the AI clients and tools you already use, gives them approved paths to your computers, and keeps identity, authority, requests, and privileged actions inspectable.
Not to the internet. Enrolled computers dial out to Hawkeye, the panel reaches them only back down that tunnel, and nothing needs port-forwarding or a firewall hole. Being exact: on the machine itself the agent does listen on port 8891 as a faster path for callers already on your own LAN or tailnet. It takes the same key as every other path, it is not internet-reachable, and XFER_PORT_DIRECT=0 turns it off. Enrollment links are single-use and expiring, and clients pair through an approval flow instead of receiving your Hawkeye password.
Credentials do not pass through the model. Hawkeye's protected-access model is designed around permission to use an approved credential for a bounded purpose, not copying its raw value into a prompt or request.
A real request can be routed to the channels you configured and the work can wait for a valid response. Per-action policy enforcement is not live yet, so this page does not claim every privileged action pauses for approval.
No. It is an illustrative workflow with no counters or production identifiers. Sign in to see authoritative data for your organization. Correlated Live map, cloud Computer provisioning, and generally published native phone apps are not presented here as available today.
Setup, platform availability, notification configuration, enrollment, policy enforcement, downloads, pricing, and legal routes remain stated at their current verified level.
Plain requests in chat — "free up disk on the machine that's full," "run the tests on the Linux machine." It works out which machine and does it.
Nothing joins without a link you minted, and no client pairs without you approving the device. Sensitive actions ask first, and everything is written to an audit trail.
Windows, Mac, Linux and your phone — shell, desktop control, browsers and file transfer, from one app or your existing AI client.
Get going
No keys to paste. The app signs you in, and each machine joins with a one-time link you mint.
Download Hawkeye for your computer. It signs in as you, runs quietly in the tray, and keeps that machine reachable.
Windows · macOS · LinuxMint a one-time link and run it on each computer. Nothing is added to your org without that link, and a machine that can't prove what it is waits for you on Machines.
one link per machine · single-useConnect Claude, ChatGPT/Codex, or use Hawkeye's own chat. Approve the pairing once, then just ask.
connect Claude, Codex, or just chatWhat you can actually ask it
One machine, or all of them at once — in your own words, not a command syntax to learn.
Everything it can reach
Six capabilities, once a machine is paired — each one is a tool your AI gets to use, not a control panel you have to learn.
Run a command on any enrolled machine — watched live, or fire-and-forget in the background.
See the real screen and drive it — click, type, grab a file, or fix something by hand.
A real, driveable browser on the machine: navigate, read pages, fill forms, screenshot.
Move a file between your machines directly — no email attachment, no USB stick.
Your agents on different machines talk to each other — hand off work, ask for a file, coordinate.
On Team and Enterprise, another org's agent can ask yours for something — and you can refuse it.
How it thinks
Three panels, in the order a stranger actually needs them — talk to it, see what runs it, know what happens with nothing installed yet.
Home is the one conversation — your machines, your live sessions and anything waiting for your approval sit around it. Sign in to see your own fleet; Home does not ask you to paste another API key.
Install the app and it runs Claude Code, Codex or Grok exactly as you already have them installed and signed in. You keep the Max, ChatGPT and SuperGrok logins in those apps — Hawkeye starts the session, it never touches or reuses the credential behind it.
Paste an OpenRouter, Anthropic, OpenAI or xAI API key during first-run and we stand up a cloud Computer for you instead of an installer. You will approve the spend and dangerous actions before the planned cloud Computer runs. (Provisioning is designed, not live yet. Today this step records what you'd want and tells you honestly it's on the way.)
Get a computer
The desktop app pairs with your account — you approve it in the browser, it keeps the daemon running quietly, and it sits in your system tray. No key to copy, no terminal to keep open.
Windows
Hawkeye-Setup-0.1.31.exe
— 207 MB installer.
Code-signed (Azure Trusted Signing). A fresh publisher
can still see a brief SmartScreen notice while download reputation
builds -- if so, choose More info → Run anyway. Check the hash first
if you would rather not take our word for it.
Linux
Hawkeye-0.1.31.AppImage
(255 MB) or
.deb (208 MB).
Unsigned — Linux has no equivalent gate. AppImage:
chmod +x then run it — needs libfuse2, which
Ubuntu 22.04+ does not install by default (sudo apt install
libfuse2, or run with --appimage-extract and launch
squashfs-root/AppRun if you would rather not install
anything). .deb: sudo apt install
./hawkeye-desktop_0.1.31_amd64.deb resolves its dependencies for
you — plain dpkg -i will leave it unconfigured.
macOS
Apple Silicon .dmg
(253 MB) ·
Intel .dmg (257 MB).
Code-signed and notarized (Developer ID). Opens with a plain
double-click; no right-click workaround needed. Apple Silicon: also install the
permission-service .pkg
(336 MB) afterward so Screen Recording/Accessibility Request buttons in the
app actually work — it does not install the app itself, only the native permission service the app above needs.
Phone
The native iOS and Android apps are in active development and not yet published for general download. This page will not claim otherwise. Until then, sign in to this site from your phone's browser; your machines, your agent and your approvals all work there too.
Verify what you downloaded:
SHA256SUMS.txt, or check the
signature yourself — signtool verify /pa /v on Windows,
spctl -a -vvv -t open on macOS.
How it works
Enrolment is deliberate at every step: the link is minted by a person, for one machine, and a machine that cannot prove what it is waits for a human before it joins.
Your org is a hard tenant boundary. The machines, tokens and policies inside it are yours; a resource in someone else's org is a request they get to refuse, never a command you can issue.
Mint a single-use, expiring install token and run it on the machine. The agent dials out to Hawkeye — nothing on the internet dials in, and no router or firewall has to be opened for it.
An authenticated admin mints the link — single-use, expiring, for one machine — and approves which AI client gets paired, with the scopes it asked for shown before you agree. A machine that enrols on that link and attests strongly joins on the link's authority; one that cannot attest waits for a person on Machines. Per-action approval is not enforced yet — the policy is evaluated and logged, not applied. We would rather say that here than let you find out later.
In-app, email or Slack — every channel optional and off until you turn it on. You decide which events are worth a ping and where it lands.
Adding a machine — where to start
$ curl -fsSL https://app.gethawkeye.app/install | sh
This tells you how to get YOUR install link; it does not enrol anything on its own. Every link belongs to one org, is single-use and expires — so a machine can never be added by a command someone copied off a website.
Built so you stay in charge
The same discipline at every boundary the product actually holds: who joins, which client is paired, which org may ask, and how wide a grant goes. Enrollment and client pairing require approval; individual actions after pairing do not.
Each org is its own tenant. A machine in another org is not a filter you can widen to reach — it is not addressable at all. Crossing the boundary is a request the other side must grant, never a command.
Enrol a machine with one line. Every join token is single-use, time-limited and revocable on its own, so a leaked token costs you one token, not the fleet.
In-app, email or Slack. Every channel is optional and off by default — route what matters to wherever you actually are.
Who asked, what ran, when, on which machine, under whose authority — recorded for every privileged action. Approving an enrolment from a Slack card and from the panel share one code path and one trail. The record is what you get today; a gate in front of each action is not built yet.
Your machines dial out to Hawkeye; Hawkeye never dials in. The panel reaches a machine
only back down that machine's own outbound tunnel — nothing to
port-forward, nothing on the public internet to scan. The agent does keep one listener
of its own, on 8891, as a faster path for callers already on your LAN or
tailnet: same bearer key, on by default, and gone with
XFER_PORT_DIRECT=0.
Built for audit
Every output is traceable to what ran, when, which version, on whose authority, with what inputs. Sessions are server-side, credentials never pass through the model, and a human stands at every boundary — what joins the org, what gets paired, which org may ask. When someone asks "who let the AI do that?", the answer is a row, not a shrug.
Authority boundary today (observe_only). Enrollment and client pairing require approval. After pairing, allowed actions execute without per-action approval: each machine's policy is evaluated and written to the audit trail in observe mode (XFER_POLICY_MODE defaults to observe, deliberately) rather than applied. A connected AI client can still raise an explicit human request when it creates one, and cross-org access is still a request the other side grants. What that gives you between those boundaries is a record of what was done, not a gate in front of it. Read it as evidence after the fact, not as a control that stops something first. One caller stands outside even the record's attribution: the shared fleet key is a break-glass credential, accepted without an identity chain, so its actions are attributable to the key rather than to a person, and the policy that is being observed is not evaluated for it at all. Its uses are counted and the recent ones kept, which is how a machine can show you how often break-glass was reached for. Narrowing it is open work, not a shipped property — treat possession of that key as possession of the fleet.
Pricing
Hawkeye is invite-only right now and free to use — no card, real limits (5 machines and 3 people per org on Free today, and both are refused at the line, not merely counted), not a timed trial. Team and Enterprise pricing isn't finalized yet; when it is, it will be one flat monthly price per org, not per seat, stated on the pricing page the same way the limits above are — read off the plan the product enforces, not guessed.
Create or request an account, connect an AI client you already use, and add the first computer with a single-use enrollment link.
Current-boundary note: per-action policy is evaluated and logged rather than enforced. Cloud Computer provisioning and generally published native phone apps are not live. The workflow illustration above contains no customer data or simulated counters.