OpsAgents CLI Gateway is a remote, secured command layer. Claude runs gcloud, gh, firebase, trello, shopify, bq and 20+ more over MCP — no local installs, no key sprawl, every call governed by SOSA.
No local toolchain, no copy-pasted credentials. Claude invokes an MCP tool; the gateway executes the authenticated binary on Cloud Run and streams the result back.
Calls <cli>_exec with an args array
Cloud Run · secrets mounted · SOSA deny-list
gcloud / gh / firebase / trello… authed, executed
Give an agent real hands on your stack — safely, auditable, and without handing it a laptop full of secrets.
gcloud, bq, gh, firebase, shopify, trello, notion, netlify, az, aws, paypal, gws, toggl & more — already logged in.
Zero local installs or version drift. Dual-region, always current, scales to zero.
Each CLI is an MCP tool Claude calls directly — args in, structured output back.
Narrow per-CLI deny-list blocks the truly destructive verbs (project delete, key revoke). Everything logged.
Credentials live in Secret Manager, never in the prompt or the agent's context.
cli_status / cli_health_check report auth + version for every CLI at a glance.
SOSA — Supervised, Orchestrated, Secured, Auditable. The gateway is the enforcement point.
Per-CLI blocks on the highest-impact verbs — projects delete, auth revoke, s3 rb, and more.
Exit codes, args, and timing captured — a full trail of what the agent ran.
Scoped service accounts and per-route tokens, not a god-mode key.
Serverless under the hood, so pricing stays simple and fair-use limits keep it fast for everyone.
Usage-metered with fair-use limits per tier. SOSA-governed · add-ons via PayPal · subscriptions via Shopify.
Book a walkthrough of OpsAgents CLI Gateway on your stack.