← Portal

3DVR Control Plane

Access

Approval-based machine access, without SSH or passwords in chat.

3DVR Secrets Broker

Create 3DVR machine access

Checking the OVH control node and Bitwarden Secrets Manager backend…

Primary control node

Checking…

OVH is the authority for broker policy, approvals, and audit state.

Bitwarden backend

Checking…

Only the broker receives the Bitwarden machine credential. Agents receive bounded access through policy.

Audit chain

Checking…

Every broker decision is recorded without credential values.

Agent scopes

Checking…

Each machine identity gets named capabilities and explicit scopes.

Capability map

How Operator reaches your systems

Full registry →

Loading the machine-readable access map…

Registry status documents what exists. A real workflow still needs the appropriate health check: configured → reachable → operational → authenticated session.

Persistent sessions

Connect once, recover automatically

Verify before reconnectingCheck configured → reachable → operational → authenticated before asking for login, pairing, or MFA.
Preserve canonical sessionsUKG/Lighthouse and messaging stay on OVH persistent browser profiles; temporary profiles are never substitutes.
Repair the failing layerA stopped browser gets restarted with the same profile. Missing profile storage gets repaired before a new sign-in is requested.
One human checkpointIf a provider truly requires re-pairing, MFA, CAPTCHA, or owner approval, surface one concrete action and preserve everything else.

Persistent access runbook →

Owner vault

Save to 3DVR Secrets

Store a credential directly in the 3DVR Agent Bitwarden project through the OVH broker. Values are never echoed back or written to the audit log.

Machine access is not your Password Manager vault. The machine token only reaches credentials intentionally saved to Bitwarden Secrets Manager. Your Bitwarden master password stays outside the server path.

Bitwarden machine access runbook →

Owner recovery

3DVR Recovery Vault

Passkey-protected break-glass recovery for root credentials. AI can guide the ceremony but never receives the decrypted value.

Open Recovery Vault

Owner access

Sensitive approvals

Checking…

Loading approval queue…

Default rules

Safe autonomy

Trusted-owner autonomyRoutine credentials are available to your dedicated OVH browser agent automatically. Recovery, root, money-moving, and destructive actions stay gated.
Least privilegeCapability + scope must both match policy before access is possible.
Sensitive gates onlyApprovals are reserved for recovery, root access, money movement, destructive actions, and other genuinely high-impact operations.
AuditableA tamper-evident chain records who asked, what scope, the decision, and the outcome.

Broker architecture

3DVR Secrets Broker

  1. 1
    Persistent OVH controlDedicated broker process + local Unix socket
  2. 2
    Scoped agent identitiesCapabilities, scopes, token hashing, fail-closed policy
  3. 3
    Phone approval UISigned owner proof bound to each approval decision
  4. 4
    Rotation + auditBounded leases + tamper-evident HMAC audit chain

3DVR Secrets

Save securely

This value goes over HTTPS to OVH, then through the local broker into Bitwarden Secrets Manager.

The value stays ephemeral in this page and is cleared immediately after a successful save.

Bitwarden Secrets Manager

Set up machine access

Create a Bitwarden Secrets Manager machine account with access only to the 3DVR Agent project, then paste its access token here once.

This goes over HTTPS straight to the OVH control plane, is stored in the broker's root-only config, and is never echoed back. Do not paste it into chat.