Skip to content

Security

How connect URLs, secrets and keys are protected, what runs where, and what we log.

Your box is yours

Each box is its own virtual machine, not a shared server. Your agent runs as root inside it, and nothing else of yours or anyone else's runs there. wack reaches the box only to do what you, your agents, your automations or your apps ask for, and to install the add-ons you turn on.

Connect URLs

A connect URL is the credential for wack's MCP tools. Your account's URL (https://api.wack.sh/mcp/wac_…) reaches every box you have and can make and delete boxes; a box's URL (https://api.wack.sh/mcp/wbx_…) reaches only that box. Each contains 32 random characters, and wack stores it hashed for lookups and encrypted so the dashboard can show it to you again.

  • Share your account's URL only with agents you trust with all your boxes. For an agent that should see one box, give it that box's URL instead.
  • Rotate URL replaces a URL: under Settings › Connection for your account's, in the box's Settings for a box's. The old URL stops working immediately and answers with "This connect URL is no longer valid."
  • Requests from web pages on other sites are refused, so a page you visit can't drive your box.

Accounts and secrets

Tokens and keys you add in Toolhouse (Claude, OpenAI, GitHub and your own environment variables) are encrypted at rest with AES-256-GCM. They are write-only: after saving, the dashboard shows only the last four characters.

These secrets go into your box only when an automation or a cloud session starts an agent there, as environment variables for that process. Agents connected over MCP don't receive them.

API keys, webhook URLs and device codes

  • API keys (wack_…) are shown once when created. wack stores a SHA-256 hash, so a lost key can't be recovered, only revoked and replaced. Keys work in the Authorization header only, never in a URL.
  • Webhook URLs contain a random token that is stored hashed and encrypted. Rotate one from the automation page at any time.
  • Device sign-in codes expire after 10 minutes and turn into an API key only after you click Allow while signed in.

Signing in

Sign-in is handled by Auth0. wack never sees or stores your password. The dashboard talks to the wack API on the server side with your session's access token. Your browser calls the API directly for one thing only, the live screen viewer described below.

The screen viewer

A box's screen is only reachable through wack. To show it, the dashboard asks for a ticket for that box while you're signed in, and your browser opens one connection to wack with it. A ticket works once and expires after a minute, and connections from other sites are refused. The viewer starts view-only, and no more than three viewers can watch a box at once.

What we log

The API writes one log line per request: time, request id, method, path, status, duration and your user id. Connect URL secrets, webhook tokens and similar values in URLs are masked before the line is written. Request and response bodies, command output and file contents are not logged.

Inside your box, wack keeps a history for you, not for us: your activity feed (commands with their exit codes, file transfers, wakes and sleeps) and the transcripts of automation runs and cloud sessions, which you can read on the dashboard.

Errors shown to you never include internal details. When something fails on our side, you get a reference id you can send us.

Deleting data

Deleting a box destroys the machine and its disk, along with its activity, runs and sessions. Deleting your account from Settings removes all of it, plus your secrets and keys, and cancels any subscription.

Reporting a problem

Found a vulnerability? Email hello@wack.sh. We'll reply and keep you posted on the fix.

Last updated