← Portal

3DVR Control Plane

Access

Your devices and accounts, without SSH or passwords in chat.

Your approval

Create 3DVR machine access

Use a Bitwarden Secrets Manager machine account with a scoped access token. Your master password never needs to live on the server.

Primary control node

Configured

Remote control is configured through Desktop Commander. Routine work should not require you to learn SSH or server administration.

Browser control

Guarded

Persistent business, Encore, and messaging lanes use one-writer control to protect sessions.

Secrets Manager

Setup needed

The machine CLI is prepared. The remaining step is a dedicated machine account with access only to agent-approved secrets.

Remote desktop

Internal

The desktop is running on OVH. A protected phone link is the next transport improvement.

Default rules

Safe autonomy

Approve onceHuman approval only when a provider truly requires it.
Least privilegeAgents get only the secret or account scope needed for the job.
Secrets stay localNo passwords copied into chat, logs, prompts, or source control.
One browser writerOne controller owns each persistent browser session at a time.

Next

3DVR Secrets Broker

  1. 1
    Persistent OVH controlDesktop Commander + guarded browser lanes
  2. 2
    Bitwarden machine accessScoped machine account + access token
  3. 3
    Phone approval UIApprove new devices and permissions from this page
  4. 4
    Rotation + auditChange credentials safely and record who used what

One-time step

Set up machine access

In Bitwarden Secrets Manager, create a project for 3DVR Agent, create a machine account, and give it only the permissions that project needs.

Create an access token for that machine account. Do not paste the token into chat; the next step is a private one-time handoff into the server.