How Pontia works
Pontia separates agent execution from remote access. Coding agents run on your device, alongside your development tools and project files. Pontia adds a local control plane and an optional encrypted path to the remote dashboard.
pontiadControl plane Agent client WorkspaceFiles and toolsThe local control plane
The pontiad service runs on your device. It coordinates agent sessions, communicates with supported agent clients such as pi and Codex, and serves the local dashboard and API.
The agent client executes commands and uses the files and tools installed on the device. Pontia does not move that execution environment to Pontia Cloud.
Local and remote dashboards
The local dashboard connects directly to pontiad, normally through its loopback address. It remains available without a Pontia Cloud account or remote access.
For remote access, the browser signs in through Pontia Cloud and receives authorization to connect to a registered device. The browser and device then establish an end-to-end encrypted session through the selected Edge. The Edge relays the encrypted traffic but cannot decrypt it.
Pontia Cloud and Edge
Pontia Cloud provides identity and coordination for remote access. It manages user sign-in, registered devices, connection authorization, and Edge discovery. It does not run coding agents or store project files.
An Edge provides connectivity between a remote browser and a device. You can use an official Edge or deploy your own. Self-hosting changes where encrypted traffic is relayed; Pontia Cloud continues to provide account, device registration, and authorization services.
Sessions and agent clients
A Session is Pontia’s persistent view of a unit of agent work. The selected agent client performs the work, while Pontia records enough state to display and control the Session from the dashboard.
This separation lets the dashboard create, observe, continue, and interrupt supported agent sessions without becoming the agent execution environment itself.
Data boundaries
| Component | Responsibility | Access to project files |
|---|---|---|
Your device and pontiad | Runs the local control plane and coordinates agents | Yes, within the workspaces exposed to Pontia |
| Agent client | Performs agent work with local tools | According to the client’s local permissions |
| Browser | Presents the dashboard and sends controls | No direct filesystem access; it displays data returned by the device |
| Edge | Relays end-to-end encrypted dashboard traffic | No |
| Pontia Cloud | Handles identity, device registration, and remote authorization | No |
To set up a device, continue with Getting started. To connect from another device, see Remote access.