Select a document.
Create the first administrator
Retrieve the one-time bootstrap token from the server console. It is never stored by this browser.
ALWAYS-ON AGENT WORKSPACE
Immortal Agents
Sign in
Accept invitation
Create a password and configure TOTP to activate your account.
or
Recover account passkey
A host administrator authorized this one-use recovery. The new passkey will replace every old passkey and sign out all browser sessions for this account.
YOUR WORKSPACE
Stay in the loop, from anywhere.
Agent sessions keep working on the host when your laptop or browser goes offline.
WORKSPACES
Sessions
LIVE WORKSPACE
Console
Watch the agent, then take the keyboard when you need to intervene.
Keyboard control is off.
More keys
Session VPN
A private tunnel for this session only. Applying or removing it restarts a running session at a safe boundary.
Provider timeline
Replayable provider-neutral lifecycle, agent, tool, interaction, and usage metadata. Prompts, commands, paths, outputs, and provider payloads are excluded.
Observed agents
Provider-safe child identities, nesting, outcomes, and activity where the active adapter exposes them.
Recent tool activity
Provider-safe metadata only; commands, paths, inputs, outputs, and errors are not stored here.
Project workspace files
Browse, download, or delete permitted files generated in this session's project workspace. Provider credentials and Git internals are excluded.
Session exchange
Uploads appear at /exchange/inbox; agent results placed in /exchange/outbox can also be published here.
Text preview
Session memory
A provider-neutral Markdown vault shared by this session’s agents. Provider access is read-only; changes are validated and revisioned by Immortal.
Knowledge graph
Explore the linked memory as a living map. Drag notes, drag the empty canvas to pan, use the zoom controls or a mouse wheel, and select a note to open it. Rendering stays inside this browser.
Attachments and settings
Convert project Markdown or create a portable export
Preview first. Importing project Markdown never overwrites existing vault entries. Portable export converts wiki links back to standard Markdown links.
Reviewed skills
Provider-neutral instructions approved by an administrator and granted only to this session.
Project changes
Read-only running-worker diff; file previews remain available after stop.
Atomic snapshots
Stopped-session captures include safe tracked, ignored, binary, and archive files. Protected paths and Git internals are never captured.
Git status
Working-tree diff
Staged diff
Changed and untracked files
Project text preview
Autonomous jobs
Bounded turns run while this server is on. New jobs start disabled.
Save this in a private secret store if you will use signed webhooks. Never paste it in Git.
Jev decisions
Ask a bounded typed question without storing the submitted state. Results and a state digest remain in this session's audit history.
Recent decisions
Provider interactions
Normalize agent questions and approvals across providers. Jev advice fails closed; only allow-listed low-risk requests can be answered automatically.
Session access
Provider runtimes
See upstream releases first, then decide whether and where to apply a verified runtime.
Provider software updates
Read-only checks compare the selected verified runtime with each provider's upstream latest channel. Nothing is built, stopped, or changed by this check.
Checks run automatically every six hours; failed checks retry after fifteen minutes.
Upgrade provider runtimes
Update every provider that has a newer upstream release, then move all of its sessions at the next safe boundary.
Default: latest available releases · all matching sessions · drain safely.
Advanced upgrade options
Jev decision service
Check the personal Jev account used by your decisions and jobs.
Every user supplies a private TypeSafe API key in Keys & Tokens and consumes their own credits. The saved key is encrypted and can only be replaced or removed, never displayed. Jobs use their creator's credential.
Storage lifecycle
Apply bounded retention, reconcile deleted-session residue, and monitor private-disk and file-scanner health without touching active or retained data.
Calculating safe cleanup candidates…
Advanced storage maintenance
Checking private disk and file-scanner health…
Automatic reconciliation runs every six hours. Session residue waits 24 hours; completed upgrade snapshots wait seven days.
Managed-image audits
Automatic checks cover active and retained images; Recheck is not required for scheduled checks. Items needing attention stay visible below.
Advanced audit controls
Unreferenced build cache can be removed explicitly; manual recheck is normally unnecessary.
Reviewed skills
Your definitions are private by default. Share them with selected accounts or deliberately publish an approved version to the organization.
Private catalogue
Your skills, definitions explicitly shared with you, and organization skills remain separated.
Immortal Admin · Skill reviews
Review pending immutable definitions before they can be granted to sessions or published to the organization.
Review queue
Administrative review is kept separate from every user's private skill catalogue.
Import a stopped CLI session
Upload your private .iam bundle, validate it, then create a stopped session owned by your account. Starting remains a separate action.
Create a stopped session from a validated bundle
Recent imports
Immortal Admin · Users & access
Invite accounts, manage capacity and administrator responsibility, then grant only the sessions they need.
Account applications
Optional public requests with a CAPTCHA and administrator approval. Disabled by default.
This single-use link is shown once. Send it through a private channel.
User preferences
Manage sign-in methods, personal integrations, and connected clients.
Email, password, and TOTP
Loading sign-in methods…
- 1Account passwordConfirm the email and enter the new password twice.
- 2Authenticator appScan a QR code and verify a six-digit TOTP code.
Passkeys
Optional phishing-resistant sign-in. Keep independent passkeys on devices you control.
Fresh MFA verification is valid for five minutes on this browser session.
Connected terminal clients
Review and revoke native-client tokens associated with this account.
Keys & Tokens
Manage multiple named integrations without exposing secret material to an agent. Every token or key is permanently isolated to one session.
Personal Jev account
Use your own TypeSafe API key for interactive decisions, agent requests, and jobs.
Each account consumes its own Jev credits. The key is encrypted at rest and can only be replaced or removed; it is never displayed or returned.
Session credentials
Secrets are write-only and cannot be moved or shared between sessions. Delete each named credential individually when it is no longer needed.
Immortal terminal client
Attach a local macOS or Linux terminal to your remote sessions.
CURRENT SERVER RELEASE
Checking downloads…
The server verifies client/API compatibility before login and attachment.
Quick start
chmod 700 ./immortal-*
install -m 0755 ./immortal-* ~/.local/bin/immortal
immortal context add work --server https://immortal.example.invalid
immortal login
immortal sessions list
immortal console project/session
immortal skills list
immortal skills granted project/session
immortal files upload project/session
immortal workspace browse project/session
immortal workspace list project/session
immortal workspace download project/session build/result.pdf --output ./result.pdf
macOS: approve the unsigned client
The client has an Immortal Ed25519 release signature but is not code-signed or notarized by an Apple-certified developer, so macOS may block its first launch. Verify the SHA-256 and complete signing-key fingerprint shown above through an administrator-controlled channel, attempt to run immortal version, then open System Settings → Privacy & Security, select Open Anyway for Immortal, authenticate, and confirm Open. Do not disable Gatekeeper globally.
By default, Ctrl-C, Ctrl-D, or Ctrl-B then D detach safely
Ctrl-C, Ctrl-D, or Ctrl-B then D detach locally without stopping the provider. Use --control-keys forward only when you intentionally want those control bytes to reach the provider. Ctrl-B then F opens the local textual workspace browser. Dragging or pasting one local file path into the live native console asks before uploading it and requests an optional agent comment. The client preserves shared web/terminal geometry.
A version mismatch displays the installed and required releases and asks before installing the Ed25519-and-SHA-256-verified matching client. immortal update checks explicitly; immortal update --yes is available for deliberate non-interactive automation. Omit the local path from immortal files upload project/session to drag one file into its prompt. Credentials are revocable tokens stored in private JSON under ~/.immortal; passwords, TOTP secrets, recovery codes, and passkeys are never stored by the client.
Documentation
Search practical help for installation, operation, security, migration, APIs, and examples.