Your agent reads email, posts to Slack, updates JIRA — one CLI.
Run agentic workflows against Gmail, Slack, JIRA, Dropbox, Revolut, and more — on your machine, in GitHub Actions, or on agent machines that fetch credentials from your own vault hub. One binary, encrypted vault, no third-party servers.
One line
macOS / Linux
curl -LsSf https://agentio.houlahop.com/install | sh
Windows
iwr -useb https://agentio.houlahop.com/install.ps1 | iex
Update later with agentio update.
Built for agents, not humans
Output shaped for LLMs
Every command emits structured, parseable output. JSON when you need it; predictable text otherwise.
Encrypted vault, multi-profile
Credentials are AES-256-GCM-encrypted in ~/.config/agentio/vault.enc, with a key derived from your passphrase. One binary, many identities per service.
CLI + GitHub Actions
Same binary runs as a local CLI and unchanged inside GitHub Actions — your workflows use a copy of your vault.
Connect once, automate everywhere
Read, search, send, label, and export email at scale.
Post to channels via incoming webhooks.
Send and read messages from a linked WhatsApp account.
Post to spaces and read messages from authorized rooms.
Search issues with JQL, comment, transition.
Read and write Confluence pages.
Install agentio secrets to a repo for GitHub Actions runs.
Read forum topics and categories.
Publish Markdown and HTML as private web pages, share them, and answer comments.
Read, search and write Apple Notes on your Mac from anywhere.
Send push notifications to your phone when an agent needs you.
Page yourself on your iPhone and Mac when an agent needs you.
Parse arbitrary RSS / Atom feeds.
Run queries against PostgreSQL or MySQL databases.
Read, create and update Docs as Markdown.
List, search, download, and upload files.
Browse, search, transfer, and share files across your whole Dropbox.
Read and write spreadsheet ranges.
Read and update presentation content.
Manage your task lists.
Read and create calendar events.
Manage and run Apps Script projects.
Accounts, transactions, expenses and receipts, and payment drafts.
Search the catalog, manage playlists and your library, and control playback.
Inbound Peppol documents and outbound billing documents.
One vault, many agent machines
Run agentio daemon start in the Docker image on a server you control. Agent machines then get credentials from it over HTTPS, and never hold a vault or a passphrase themselves.
Starts locked
The hub never reads a passphrase file. You unlock it in the admin UI at /ui, or at boot with AGENTIO_PASSPHRASE. Lock drops every session.
A scoped key per agent
Each key reaches only the profiles you choose. Keys can be read-only, and can be allowed to add, rename and remove profiles. Rotate or revoke a key from the UI or with agentio key.
Nothing to refresh on the agent
The hub refreshes tokens before it hands them out and strips the refresh material. Once a week it also refreshes idle profiles, so their tokens do not expire from lack of use.
On the agent machine:
agentio login https://vault.example.com
# Your code: WDJB-MJHT
# Approve it at https://vault.example.com/ui#authorize=WDJB-MJHT within 10 minutes.
# Waiting for approval…
agentio gmail list --limit 5 # credentials come from the hub
You don't need a browser on the agent machine, so login works over SSH. Open the link on any device, check the code matches the terminal, choose what the key can reach, and approve it. In CI, put a key in the AGENTIO_TOKEN secret instead of a vault copy. Deployment guide: running the vault hub on a VPS.
Common questions
Is agentio free?
Yes — MIT-licensed, self-hosted. No accounts, no telemetry.
Where are my credentials stored?
In an encrypted vault at ~/.config/agentio/vault.enc, AES-256-GCM, with a key derived from your passphrase. The passphrase is kept in ~/.config/agentio/vault.passphrase (mode 0600) or read from AGENTIO_PASSPHRASE. You can sync the vault file between machines, but keep the passphrase off anything that syncs.
Do I need the daemon?
Only if you want a vault hub that serves credentials to other machines. On a single machine, every command is a one-shot CLI call against your local vault.
Can I use it without an LLM?
Yes. It's a regular CLI — pipe its output into anything.
How is this different from Zapier?
You own the credentials and the workflow definitions. Runs in your CI or on your machine; no third-party servers in the path.