> ## Documentation Index
> Fetch the complete documentation index at: https://docs.glasswarp.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Safe agent sessions

> Simple checklist for running agents on real Windows PCs.

Glasswarp gives an agent **eyes and hands** on a Windows PC you own. You supply
the **brain**. Treat full desktop control as powerful — start small, watch it,
then open the throttle.

Glasswarp handles **session controls** (consent, on-screen indicator, kill
switch, audit, Live View). Your agent code handles **what it’s allowed to do**.

See also: [Safety and consent](/concepts/safety-and-consent) ·
[Live View](/guides/live-view)

## Checklist

### On the Glasswarp side

* [ ] Use a **dedicated rig** when you can — not your everyday PC
* [ ] Turn **API access** on only when you need it (Console → Rigs)
* [ ] Scope API keys to **one rig** when possible
* [ ] Keep **Live View** open on first runs; kill from Console if needed
* [ ] Always **`end_session`** when finished

### In your agent code

* [ ] **Ask a human** before delete, send, purchase, install, or security changes
* [ ] **Allowlist** apps the agent may launch
* [ ] Set a **max steps / max minutes** budget
* [ ] Don’t put **passwords or secrets** in prompts
* [ ] **Log** what the agent is about to do
* [ ] Never aim the agent at the **Glasswarp tray** (unpair / end session) or Windows security UI

### Human-only on the host (platform-enforced)

These are **not** agent API/MCP tools. The host also blocks remote input while the
tray confirmation dialogs are open, so an agent with hands cannot click **Yes**
for you.

| Action | Where | Notes |
| - | - | - |
| **End API session** | Tray → **End API session…**, or Console → Sessions | Owner kill switch |
| **Unpair this PC** | Tray (only when **no** API session) or Console → Rigs → Remove | End the session first, then unpair |
| **API access on/off** | Console → Rigs | Consent gate |

Agents **should** call `end_session` when their own work finishes — that is
cleanup, not the owner kill switch.

## Simple split

| Glasswarp | Your agent |
| - | - |
| Consent, indicator, kill, audit, Live View | Approvals, allowlists, budgets, prompts |
| Owner tray/console controls (input blocked during confirm) | Do not automate Glasswarp chrome |

You need both.

## Patterns

**Watch first.** Open [Live View](/guides/live-view) (or the
[`live_view_hitl`](/examples/templates) template) before full autonomy.

**Batch only when intermediate screens are predictable.** Actions inside a
batch execute without verification between them (MCP `send_actions` is capped
at 10; an invalid action is rejected during validation **before anything is
sent**, and the response names the failing action index — zero events reach the
machine). On a host running agent **≥ 0.2.21** (with `api_input_ack`), the owner
kill switch and session end abort an **in-flight** batch mid-sequence: the input
call returns **`410 aborted_by_owner`** with `executed` / `aborted` /
`kill_to_abort_ms` counts, and only the `executed` events landed. Older hosts are
fire-and-forget (the session ends but the current batch may finish) — upgrade the
host for guaranteed mid-batch abort.

**Confirm risky acts.**

```python theme={null}
def maybe_act(gw, sid, action):
    if action.get("risk") in ("delete", "send", "purchase", "install"):
        if not human_approved(action):
            return
    apply_action(gw, sid, action)
```

**Budget + always clean up.**

```python theme={null}
MAX_STEPS = 40
session = gw.create_session(rig_id=rig.id, mode="desktop")
sid = session.session_id
try:
    for step in range(MAX_STEPS):
        obs = gw.observe(sid, max_width=1280, mark=True)
        action = decide(obs)
        if action is None or action.get("type") == "done":
            break
        maybe_act(gw, sid, action)
finally:
    gw.end_session(sid)
```

## Console

| Action | Where |
| - | - |
| API access on/off | Console → Rigs |
| Keys | Console → API Keys |
| Watch / kill | Console → Sessions |

## In our examples

Helpers live in `sdk/python/examples/safe_session.py` (budgets, intent logs,
allowlist, optional `REQUIRE_CONFIRM=1`). Templates and demos use them. The
longer demos (Paint / Minesweeper) run unattended by default — set
`REQUIRE_CONFIRM=1` if you want prompts.

```bash theme={null}
export REQUIRE_CONFIRM=1
export MAX_STEPS=40
export ALLOWED_APPS=notepad.exe,mspaint.exe,chrome.exe
```

## Related

* [Safety and consent](/concepts/safety-and-consent)
* [Build an agent loop](/guides/agent-loop)
* [Templates](/examples/templates)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.