How Pontia works

Pontia separates agent execution from remote access. Coding agents run on your device, alongside your development tools and project files. Pontia adds a local control plane and an optional encrypted path to the remote dashboard.

The local control plane

The pontiad service runs on your device. It coordinates agent sessions, communicates with supported agent clients such as pi and Codex, and serves the local dashboard and API.

The agent client executes commands and uses the files and tools installed on the device. Pontia does not move that execution environment to Pontia Cloud.

Local and remote dashboards

The local dashboard connects directly to pontiad, normally through its loopback address. It remains available without a Pontia Cloud account or remote access.

For remote access, the browser signs in through Pontia Cloud and receives authorization to connect to a registered device. The browser and device then establish an end-to-end encrypted session through the selected Edge. The Edge relays the encrypted traffic but cannot decrypt it.

Pontia Cloud and Edge

Pontia Cloud provides identity and coordination for remote access. It manages user sign-in, registered devices, connection authorization, and Edge discovery. It does not run coding agents or store project files.

An Edge provides connectivity between a remote browser and a device. You can use an official Edge or deploy your own. Self-hosting changes where encrypted traffic is relayed; Pontia Cloud continues to provide account, device registration, and authorization services.

Sessions and agent clients

A Session is Pontia’s persistent view of a unit of agent work. The selected agent client performs the work, while Pontia records enough state to display and control the Session from the dashboard.

This separation lets the dashboard create, observe, continue, and interrupt supported agent sessions without becoming the agent execution environment itself.

Data boundaries

ComponentResponsibilityAccess to project files
Your device and pontiadRuns the local control plane and coordinates agentsYes, within the workspaces exposed to Pontia
Agent clientPerforms agent work with local toolsAccording to the client’s local permissions
BrowserPresents the dashboard and sends controlsNo direct filesystem access; it displays data returned by the device
EdgeRelays end-to-end encrypted dashboard trafficNo
Pontia CloudHandles identity, device registration, and remote authorizationNo

To set up a device, continue with Getting started. To connect from another device, see Remote access.