Agent-Fabric documentation
Agent-Fabric publishes the models, tools and agents already running on your own
hardware as private services your team — and your customers — can call. This is
the reference for the fabric CLI, the control-plane API and the SDKs.
Get running
Share access
Understand and fix
Reference
What the control plane can and cannot see
Section titled “What the control plane can and cannot see”Your agents, models and services run on your own machines. Agent-Fabric gives them a private encrypted mesh (WireGuard) and a control plane that brokers keys, device identity and policy.
The control plane sees names, health and usage counts. It does not see prompts, model outputs or any traffic between your machines — those are end-to-end encrypted, with a relay used only when two machines cannot reach each other directly, and the relay carries ciphertext it cannot read.
If you only read one more page, read How it works.