AI-native zero-trust access for local LLMs and applications.
Self-hosted, with secure API sharing, browser workspaces, and context-aware AI Agents.
English | 简体中文 | 日本語 | 한국어 | Español | Français | Deutsch
Website · Docs · Features · Install · Access protocols · Agent models · Product tour
- 🤖 Local LLM access — Share local models beyond your network through authenticated APIs and a browser Playground.
- 🔑 Controlled API sharing — Scope keys to models, set Token quotas, revoke access, and review usage and request records.
- ✨ AI in your workflow — Inspect terminal output, draft commands, and query databases with an Agent tied to your connection. Tool access follows user permissions; operations requiring approval wait for your confirmation.
- 💬 Ask about your resources — Find and inspect your connectors, devices, and applications from the home Agent. Resource visibility stays scoped to the signed-in user.
- 🔌 Outbound-only connectors — connect private networks without opening inbound ports on them.
- 🔐 Application access — publish TCP, HTTP, HTTPS, WebSocket, and SSH services with per-access controls.
- 🖥️ Browser workspaces — WebSSH, WebSFTP, WebRDP, WebVNC, MySQL, MariaDB, PostgreSQL, SQL Server, Oracle, ClickHouse, MongoDB, Elasticsearch, OpenSearch, Redis, and Memcached.
- 📁 Files and objects — Manage remote files with WebSFTP. Browse buckets, prefixes, and object metadata from S3-compatible services with WebS3 (currently read-only).
- 🔎 Application discovery — scan connector devices and register discovered services from the console.
- 👥 Identity and access management — organize users and resources, with Casbin-backed authorization.
- 🛡️ Firewall policies — restrict TCP and HTTP access by source IP and CIDR.
- 📋 Logs and audit — record management actions and supported application sessions in one place.
- 📦 Self-hosted deployment — run the complete control plane on your own Linux server.
Download the self-contained Docker bundle, extract it, and run the installer (Docker 20.10+ with Compose is required):
wget https://github.com/liaisonio/liaison/releases/download/v1.15.0-rc.1/liaison-1.15.0-rc.1-linux-amd64.tar.gz
tar -xzf liaison-1.15.0-rc.1-linux-amd64.tar.gz
cd liaison-1.15.0-rc.1-linux-amd64
./install.shOpen https://<server-address> after installation. The installer prints the initial sign-in credentials.
Access your existing private services through Liaison.
| SSH / SFTP | |
|---|---|
| Desktop | |
| SQL databases | |
| Data & search | |
| Cache | |
| Storage | |
| LLM upstream protocols | |
| Web / TCP |
LLM upstreams support OpenAI-compatible, Anthropic Messages, and Ollama. Clients use OpenAI-compatible endpoints; Anthropic upstreams also expose native Messages endpoints. Logos identify existing services you can access, not products bundled or deployed by Liaison. Database and desktop logos refer to browser workspaces, not native database/RDP/VNC server listeners.
Configure the model behind Liaison’s built-in Agent, independently of service access.
| Models |
|---|
Eight provider presets, plus custom OpenAI-compatible services.
Work in an audited browser terminal with an Agent that can inspect session output and help draft commands.
Access media servers and other internal web applications through Liaison.
Keep internal AI tools reachable without exposing the private network.
Browse schemas, run SQL, and ask the session Agent to query and explain results, with approval where required.
Explore collections and ask the session Agent to run approved queries and explain documents, without a local client.
Open a private VNC desktop in a managed browser session.
Connect to an RDP desktop from the same access workflow.
Bug reports, feature proposals, documentation improvements, and pull requests are welcome. Start with Issues or open a Pull Request.
Liaison is licensed under the GNU Affero General Public License v3.0.








