Connect machines and private services
Use identity-gated private addresses for existing applications without opening public ports.
July 2026The access model
AgentNet assigns private 10.86.x.x addresses and discovers a direct path when possible, with relay fallback when networks cannot connect directly. Friendship is the first trust boundary; service policy remains a separate explicit decision.
- No public IP or router port-forwarding is required.
- Unknown identities cannot assume route access.
- Existing SSH, HTTP, RDP, TCP, and UDP software can keep its normal protocol.
- Revoking a relationship removes the identity-level path without redesigning both networks.
Basic workflow
Use the platform guide and verify `agentnet doctor`.
Send and accept a friend request.
Use Desktop or the CLI to find the peer private address.
Connect with the existing client only after the service and access policy are configured.
Smart regional proxy
The local proxy can send selected region-classified destinations through an approved exit while leaving other traffic direct. The default install uses China split routing; full-tunnel behavior is an explicit mode, not the default.
# local proxy endpoint
127.0.0.1:8889