Logins and keys never move
A CLI subscription login or an API key is used only on the Brain device that owns it. It is not migrated, not held on your behalf and not relayed through the cloud.
Matrix Team · Hand–brain separation
A Brain is an AI resource together with its credentials: a CLI subscription login or an API key on a device. A Hand is a device that holds a real workspace: files, an uncommitted worktree, local processes, including headless servers. They can be the same machine. They do not have to be.
Matrix leases Brains to Tasks on Hands, relays signed tool calls between them, and keeps the permissions, the audit trail and the usage in one place.
Your best AI subscriptions live on personal laptops. Your real workspaces live on servers and company machines. Hand–brain separation lets the one work on the other without copying a credential or giving up control of a file.
A CLI subscription login or an API key is used only on the Brain device that owns it. It is not migrated, not held on your behalf and not relayed through the cloud.
The device that holds the workspace keeps ownership of its content, secrets and local policy. Each lease is bound to one workspace root; paths outside it are refused with a clear error.
The executing side signs what it did. Usage and accounting follow the lease, claim and epoch receipts, not whoever happens to be logged in.
If a Hand is offline, a lease was revoked or a provider refuses, the run says so. Matrix does not retry on another device, swap models or invent a success.
The same path serves a CLI agent, an ACP-connected agent runtime or an API model. Browser and desktop automation reach the Hand through its MCP gateway on the same signed channel.
Matrix issues a BrainLease with an intent, a claim, a fencing epoch and a workspace scope. Starting a round reserves capacity only when there is real work.
The AI process on the Brain emits a signed tool-call envelope carrying the lease id, epoch and a monotonic sequence number.
The Hand verifies lease, device, workspace, capability and sequence, persists a replay fence, then lists, reads, writes or runs inside the scoped root and returns a signed receipt.
The result re-enters the model. When the round finishes, capacity returns automatically. Revoking the lease or raising the epoch fences every later call.
The same objects serve both: accounts and organizations, Devices and Workspaces, Brains, Hands and Tasks. Using a model resource and accessing the files on the device that hosts it are two separate permissions.
Organization Owners and Admins manage members, teams, resources and devices in Settings. Nothing is enrolled by accident.
Connect the CLIs and API keys on each of your machines, then drive them from any browser.
A run reports waiting, verifying, running, failed or delivered with its reason. A model answer never counts as a file written or a test passed.