Home › Blog › More than an app: FrontierStack as the network admin agent for ChatGPT, Claude, Grok, OpenClaw, Hermes, Paperclip and more

More than an app: FrontierStack as the network admin agent for ChatGPT, Claude, Grok, OpenClaw, Hermes, Paperclip and more

Published 2026-09-26

FrontierStack started as a Mac app for looking after servers. It is now more than an app: it can be the network admin agent on your AI team. ChatGPT, Codex, Claude, Grok, Gemini, Cursor, OpenClaw, Hermes, Paperclip, Buzz and Amp can all hand it network and server work, and none of them ever receives a password, API key or SSH key.

This post explains what that means, the three ways FrontierStack plugs into an agent platform, and exactly how it works with each of the major ones.

What a network admin agent does

Agent teams are good at code and bad at the network. The moment something real breaks (a domain stops resolving, a certificate expires at 2 am, a firewall rule blocks a deploy, a server stops answering) the agent needs access to the machines that run your infrastructure. The usual answer is to paste credentials into the agent. Every one of those is permanent: once a secret has been in a prompt, it is out of your control.

FrontierStack takes a different role. It already holds your infrastructure credentials in the Mac's Keychain. The agent names a target and describes the job; FrontierStack looks up the credential at the moment of use, does the work, and returns the result with secrets removed. It covers DNS records and zones, TLS certificates, routers and firewalls (OPNsense, pfSense, UniFi and more), VPNs and overlay networks (Tailscale, ZeroTier, WireGuard), Mac, Linux and Windows servers, websites, databases, backups and the online accounts around them.

Three ways to plug in

  1. As an MCP tool server. Coding agents and desktop assistants connect over the Model Context Protocol through an owner-only bridge on the Mac. The bridge reads its credential from the Keychain, so no config file ever holds a token. FrontierStack writes the config for you: MCP Server › AI clients › Set Up Detected.
  2. As a worker that takes assignments. An orchestrator hires FrontierStack and hands it issues or tasks: Paperclip through its heartbeat, A2A 1.0 supervisors through delegated tasks. FrontierStack investigates, reports and, if you allow it, fixes.
  3. As a cloud connector. Cloud assistants that cannot reach your Mac use FrontierStack's gateway at https://frontierstack.app/plugin/mcp. You sign in with your FrontierStack account, and your Mac answers over an outbound connection: no inbound port, no tunnel to configure.

Agents that have a shell can also drive the frontierstack command-line tool: frontierstack discover, frontierstack call, and frontierstack run, which gives one command a stored secret without the agent ever reading it.

Platform by platform

ChatGPT and Codex (OpenAI)

The FrontierStack plugin for ChatGPT and Codex connects through the cloud gateway. Turn on MCP Server › ChatGPT access on each Mac it may reach, add FrontierStack in ChatGPT, and sign in with your FrontierStack account. It can list your Macs, read server health and your fleet map, check alert delivery problems, run read-only diagnostics, read secret-redacted logs, and check or restart a supported web service. Until the plugin appears in the ChatGPT app directory, add it as a custom connector with the gateway URL. The Codex CLI can also use the local bridge: Add to Codex.

Claude (Claude Code and Claude Desktop)

Add to Claude Desktop writes the local bridge into Claude Desktop's configuration; for Claude Code, FrontierStack shows the claude mcp add command to run. Give Claude Code the Fleet Skill as well: FrontierStack writes a map of your servers, roles and services to ~/.claude/skills/fleet/ and keeps it current, so Claude knows your network before it connects. Claude on the web can use the cloud gateway as a custom connector.

Grok (Grok Build and Grok Bot)

On the Mac, Add to Grok puts FrontierStack in ~/.grok/config.toml for Grok Build and its scheduled and autonomous jobs. A cloud Grok Bot adds FrontierStack as a custom connector with the gateway URL and signs in with your FrontierStack account. Either way, Grok plans the work and FrontierStack holds the keys.

OpenClaw

Add to OpenClaw registers FrontierStack with OpenClaw's own openclaw mcp add, and installs the FrontierStack skill in ~/.agents/skills, where OpenClaw finds it. Restart the gateway and openclaw mcp doctor frontierstack --probe confirms the connection.

Hermes Agent

Add to Hermes configures Hermes' main profile. Hermes Bot Mode profiles are isolated, so Set Up Existing Bots is a separate, explicit choice. Hermes marks FrontierStack as untrusted, and FrontierStack still applies its own read-only default and approvals. Hermes can also find the FrontierStack skills at www.frontierstack.app/.well-known/skills/.

Paperclip

Paperclip runs a team of agents as a company, with an org chart, budgets and goals. FrontierStack can join the company as its system engineer and network administrator. In FrontierStack's Paperclip pane, accept heartbeats, install the heartbeat command and Hire as DevOps agent. On each heartbeat FrontierStack checks out the issue assigned to it, investigates with its own tools, comments with the findings and marks the issue done, blocked or ready for review. A Paperclip approval never counts as a FrontierStack approval, and Paperclip never gets a shell or a credential.

Buzz

Buzz's agents run on your own machine through a harness such as Claude Code, Codex or goose. Connect that harness to FrontierStack as above, and put the FrontierStack skill in ~/.agents/skills (Add to OpenClaw does this, or export it from the MCP Server pane): Buzz's agents read skills from there.

Gemini CLI, Cursor, Amp and Xcode

Each has its own Add to … button under MCP Server › AI clients, all using the same credential-free bridge. In Xcode 26.3 and later, the Claude, Codex and Gemini agents inside Xcode can ask FrontierStack about the server, database or website your app talks to.

Supervisor agents and everything else

A coordinator that speaks A2A 1.0, such as a LangGraph manager or an OpenClaw or Hermes supervisor, can hand FrontierStack a durable task: turn on Accept delegated A2A tasks. Any other MCP client connects through the bridge, and any agent with a terminal can use the CLI. FrontierStack also exports credential-free setup kits for multi-agent teams, CI/CD and chat handoffs.

Even with the app closed

An agent team works at night; you don't have to leave FrontierStack open for it. A small background service can keep MCP and the command-line tool answering, run read-only checks itself, keep monitoring and alerting, and start FrontierStack hidden only when a job needs it. If your App Lock requires a hardware security key, you can let agents work only while that key is plugged in: unplug it and they stop.

Getting started

  1. Download FrontierStack from www.frontierstack.app and add the servers, routers and domains you look after.
  2. Turn on MCP Server and press Set Up Detected for the agents on your Mac, or turn on ChatGPT access for cloud assistants.
  3. Leave changes off for the first week. Diagnosis is where most of the value is, and it carries almost no risk.
  4. When you are ready, allow changes for one platform at a time, and approve them on your Mac or iPhone.

The manual has the full setup for each platform: Setting up FrontierStack for agent platforms. See also FrontierStack in agent teams and the agent integration guide.

FrontierStack is made by Enfour, Inc.; www.frontierstack.app

Run it from your Mac.

FrontierStack installs, monitors and secures services on this Mac and on linked servers.

Download FrontierStack

Apple notarized · Safe & secure · macOS 13 Ventura+