OneCLI connects AI agents to Fly.io so they can deploy and manage applications, Machines, volumes, and secrets. The gateway injects your API token into requests automatically.
Access is per agent: grant the connection to each agent that needs it, choosing per tool what runs freely, what needs human approval, and what stays blocked — a read-only agent is a single grant. Organization rules add guardrails on top, like rate limits and blanket blocks. Everything is checked before credential injection, so a blocked request never reaches Fly.io.