~/warp terminal --live

A real shell. Zero open ports.

Open a full interactive PowerShell on any online device, right in the browser. It streams over the encrypted connection the agent already holds, so it is fast, and it is locked down so tightly that the agent will not even start the shell until it has checked a signature.

ACME-FS01 — PowerShell · Warp RMMLIVE
[warp] opening terminal on ACME-FS01 · Acme Dental › Calgary office[warp] session grant signed ✓  ECDSA P-256 · bound to session + device · short-lived[warp] agent verified grant against its pinned key ✓[warp] ConPTY attached over the agent's outbound WebSocket · 0 inbound ports[warp] heads-up: production server · running as NT AUTHORITY\SYSTEM · session recordedPS C:\Windows\system32> Get-PhysicalDisk | ft FriendlyName, MediaType, BusType, HealthStatusFriendlyName              MediaType BusType HealthStatus------------              --------- ------- ------------Samsung SSD 990 PRO 2TB   SSD       NVMe    HealthySamsung SSD 990 PRO 2TB   SSD       NVMe    HealthyPS C:\Windows\system32> Restart-Service Spooler -PassThru | select Name, StatusName    Status----    ------Spooler RunningPS C:\Windows\system32> 
// 01 How it works

Three hops. One signature. No exposure.

TechnicianBrowser consoleMicrosoft 365 + MFAper-area permission
Warp serverSigns a session grantbound to session + devicerecords the transcript
Endpoint agentVerifies grant vs pinned keyspawns ConPTY PowerShellno inbound port, no WinRM
  1. You press Connect. The console checks your Microsoft 365 session, your permission for that device's area and the browser's origin before upgrading to a WebSocket.
  2. Warp signs a session grant. An ECDSA P-256 signature under its own domain label, bound to this session, this device, this mode and a short expiry, so it cannot be replayed as a job, an update or another session.
  3. The agent checks the grant. Against the key pinned at install. Only then does it create a Windows pseudo-console (ConPTY) and start PowerShell.
  4. Bytes stream both ways. On a dedicated, ordered, back-pressured lane inside the agent's existing connection, so nothing is dropped and telemetry never gets in the way.
  5. You close it, or it closes itself. Idle sessions end after 15 minutes. The transcript is saved and the close is written to the audit log.
// 02 Why it is faster

Nothing to set up means nothing to wait for.

Already connected

The agent holds one outbound WebSocket to Warp at all times. A terminal is just another stream on it, not a new connection to negotiate.

No relays to rent

No third-party session broker, no jump box, no VPN client on the tech's laptop.

A proper console

ConPTY gives you colours, line editing, resizing, tab completion and full-screen tools, not a one-shot command box that returns text after the fact.

// 03 Why it is safer

Power, with the safety catch on.

  • No inbound port, no WinRM, no RDP, nothing listening on the endpoint
  • Signed, short-lived grant verified on the endpoint before any process starts
  • Operators only, per area, and only within their own MSP and permitted clients
  • Context banner on every session: client, host, OS, role and who the shell runs as
  • A red warning before you type on production servers, domain controllers and hypervisors
  • Capped transcript of every session, opens and closes in the append-only audit log
  • At most five concurrent sessions per device and a 15-minute idle timeout
Does it need ScreenConnect, a VPN or an open port?

No. The terminal travels inside the agent's own outbound connection. Nothing on the endpoint listens for inbound traffic.

Who does the shell run as?

Today, the agent's service identity (NT AUTHORITY\SYSTEM), and the console says so on every session. Running as the signed-in user is on the roadmap.

Is what I type recorded?

Yes. A capped transcript is saved with each session, and opening and closing are written to the append-only audit log.

Can someone replay a captured session grant?

No. Grants are bound to one session, one device and one mode, carry a signed expiry and use their own signature domain, so they are useless for anything else.

Open your first shell in under a minute.

Enroll a test machine, press Connect, and you are in.