Frequently asked questions
Short answers about nfltr orch on nfltr.xyz, each with a link to the page that explains it in full.
- What is nfltr orch?
- Who is it for, and when don't I need it?
- How is it different from SSH, Tailscale, ZeroTier or NetBird?
- How is it different from Claude Code subagents or agent teams?
- Can I run the relay on my own network?
- Does my code or data go through nfltr.xyz? What can the relay see?
- Whose Claude account is used, and does nfltr see my Claude credentials?
- What can an agent do on my machine?
- What about prompt injection?
- What happens if a machine, the relay or the hub goes down?
- Which agents and platforms are supported?
- Is nfltr open source?
- What does it cost?
- How is the download verified?
- How do I give feedback or report a problem?
- Where do I start?
What is nfltr orch?
nfltr orch runs Claude Code agents on machines you join. The hub is a Claude Code session, started with nfltr orch "<goal>" or in your own Claude Code with the hub tools; it decides which agents to start, where, and when the goal is done. Nodes are your laptops, VMs and servers, each joined once with nfltr node join, and agents are Claude Code processes a node starts on demand. The relay (nfltr.xyz, or one you run) carries messages between them and runs no model.
More: Agent Orchestration
Who is it for, and when don't I need it?
It is for work that needs more than one machine: data or a service only one machine can reach, a backlog spread over several machines, or agents that must keep running after your terminal closes. If you work on one laptop with small tasks, Claude Code alone is simpler, and Claude Code agent teams run several agents on one machine with one environment variable of setup. When we ran the same eight coding tasks both ways, neither was reliably faster on one machine, and nfltr took more setup.
More: Claude Code agent teams and nfltr orch, measured · When to use NFLTR
How is it different from SSH, Tailscale, ZeroTier or NetBird?
Those connect machines; nfltr runs agents on them. With SSH or a VPN, one Claude Code session drives every machine remotely, and a dropped connection ends the running command. With nfltr each machine runs its own agents: they keep running if the hub dies, and a hub started again with the same hub id receives every result exactly once. Each machine's owner sets what its agents may do (repositories, tools, approvals, how many at once), the hub can cap spend, and every agent shows in nfltr orch task list and the dashboard. If your machines already share a private network, you can run the nfltr relay on it.
More: nfltr vs. Claude Code over SSH or a VPN · Run your own relay (beta)
How is it different from Claude Code subagents or agent teams?
Subagents run inside one Claude Code session, and an agent team's teammates are started by one interactive lead session; both stay on the machine where that session runs. nfltr orch runs agents on any machine you join, and they keep running without the hub's process. In our published restart test, a hub killed mid-run and started again with the same hub id got both results from its first wait and answered within 8 s; a restarted agent-teams lead recovered 0 of 2 teammate results. The two combine: a team lead can have the hub tools too, with teammates on your machine and agents on your nodes.
Can I run the relay on my own network?
Yes, in beta: nfltr relay serve runs the relay on a Linux VM or machine of yours, with your TLS certificate or a self-signed one your machines pin, and nfltr config set-relay points each machine at it. Nodes, nfltr orch, the hub in your own Claude Code, messages, notifications and nfltr p2p work on it. Not in the beta: the dashboard, share links, TCP and SSH tunnels, WireGuard, several accounts or keys, and failover (it is one process on one machine). With your own relay, nfltr contacts nothing but that relay on its own; your git host, your model provider and any STUN or TURN server you name are contacted because you set them up.
Does my code or data go through nfltr.xyz? What can the relay see?
Your code and data stay on your machines: agents run there, their git traffic goes to your git host, and Claude Code calls the model provider directly. Messages between the hub, nodes and agents are encrypted end to end by default, and the hub's dashboard summary carries only status (ids, state, machine, timing, token counts and cost) unless you choose --dashboard-digest full. Answers from a device paired with the hub, and nfltr p2p files, chats and calls, are end-to-end encrypted too. The relay can read share links and ordinary HTTP tunnels, where TLS ends at the relay, and raw TCP tunnels unless the protocol inside is encrypted (SSH is). It always sees metadata: which machines connect to which, when, and how much data flows.
Whose Claude account is used, and does nfltr see my Claude credentials?
Yours. Every agent is Claude Code on one of your machines, running with the Claude token you put in that node's environment (CLAUDE_CODE_OAUTH_TOKEN from claude setup-token, or ANTHROPIC_API_KEY), and it calls the model provider directly from that machine. The token stays on the machine: the relay never receives it. The hub is a Claude Code session on the machine where you start it.
What can an agent do on my machine?
Only what that machine's node allows. Without --allow-all-tools agents can edit files but shell commands are refused; --allow-repo lists the repositories they may work on, and the git credentials the node hands them answer only for those; --tool-policy-file denies commands you name, and with --approval-public-key the rules you mark are lifted only for a turn carrying your signed approval of exactly its prompt. --max-agents caps how many run at once, --serve-hubs and --require-pin limit which work the machine takes, and agents run with a clean Claude config, without the machine's Claude settings, hooks, memory, plugins or MCP servers. Agents commit with the git identity configured for the node's user, or none; the node never invents one. An agent still runs as the node's OS user and can read what that user can, so run the node as a dedicated user or in a container for a hard boundary.
More: What agents can reach
What about prompt injection?
It is a real risk for any agent that reads text it did not write, and nfltr does not make the model immune to it. The hub receives what agents, nodes and monitors return marked as untrusted data, not instructions, but the containment is what each machine allows: shell commands off unless you opt in, deny rules in a tool policy, repositories and git credentials limited to an allow-list, and changes gated on your signed approval, which an agent cannot make. In our incident run, text in an alert, a pod log and a PR telling agents to delete namespaces was ignored and reported to the owner; that is one run, not a guarantee. --agent-relay-access gives every agent, and anything that prompt-injects it, your account key's full power, so it is off by default.
More: Untrusted content · A shared machine · What nfltr orch is useful for, measured
What happens if a machine, the relay or the hub goes down?
Agents run on the nodes, so a hub that dies or a terminal that closes does not stop them: start the hub again with the same hub id, or reopen the project, and it receives every result it missed, exactly once. A node stopped with Ctrl-C or SIGTERM reports its running agents as lost (node_lost) right away; for a node that loses its connection and is not back within 30 seconds, they are reported about 30 seconds after it left, and the hub decides whether to run the work again. When the relay restarts, nodes, agents and hubs reconnect by themselves and running agents keep working. nfltr.xyz runs on one VM, so a deploy briefly interrupts it; clients ride out the gap for up to 2 minutes.
More: Join machines as nodes · What the relay does, and doesn't
Which agents and platforms are supported?
Claude Code: the hub is a Claude Code session and every agent is a Claude Code process. A node can also offer the Codex CLI, but the tool policy, approvals and clean Claude config apply only to Claude Code agents. Nodes and hubs run on macOS and Linux, amd64 and arm64, and in containers (start one with docker run --init). The install page also has Windows builds of the CLI.
More: Getting Started · Install
Is nfltr open source?
No, nfltr is closed source. The relay you can run on your own network is the same closed-source nfltr binary you install on your machines.
What does it cost?
Pricing isn't published yet; ask us via the contact page. Your agents' model usage runs under the Claude account whose token each machine uses, and the hub reports each agent's cost.
More: Contact
How is the download verified?
Releases are signed. The install script checks the signature on the release's SHA256SUMS file and the binary's SHA-256 against it, and refuses the binary on a missing or bad signature or a mismatch; nfltr update --apply checks the signature and checksum itself. The release public key is in the install script, https://nfltr.xyz/install.sh. On Windows, compare the binary with certutil -hashfile against the signed SHA256SUMS in its release folder.
More: Install
How do I give feedback or report a problem?
Write to us on the contact page: feedback, a bug, a question, or what you ran nfltr on. A person reads every message; leave your email if you want a reply.
More: Contact
Where do I start?
Start with Getting Started. Install the CLI and Claude Code on each machine, sign in with nfltr config login, put the Claude token in the environment, and join each machine with nfltr node join --max-agents 2 --allow-all-tools. Then check readiness with nfltr orch doctor and give the hub a small goal with nfltr orch "<goal>", or add the hub to your own Claude Code with claude mcp add nfltr -- nfltr mcp --toolset hub.