About LinuxCLI
LinuxCLI gives you a real, one-time-use Linux command line for network diagnostics and OSINT lookups — dig, whois, host, curl, openssl s_client, mtr, ping and nc — without installing anything locally.
Only a fixed whitelist of read-only diagnostic tools is available. There is no active port scanning (nmap, masscan, etc.) — that's a deliberately different class of tool and isn't offered here.
How the sandbox works
Each session runs a single command inside an isolated, disposable Docker container: no privileges (cap-drop=ALL), a read-only filesystem, and no network access beyond what the specific tool itself needs.
The container is destroyed immediately after your command finishes, whether it succeeded, failed, or timed out — there is no persistent state, no shell access, and no way to chain commands together across runs.
One WebSocket connection runs exactly one command at a time. Every request — accepted or rejected by the command validator — is written to an insert-only audit log for abuse investigation, and expires automatically after 90 days.
Data & privacy
LinuxCLI keeps as little as it can while still being able to investigate abuse: a hashed (not raw) IP address, the command you ran, and a timestamp. If you register an account, you can see it and delete it at any time.
Full details of what's collected, why, and for how long — the Privacy Policy.
Acceptable use policy
Use LinuxCLI only against hosts and domains you own, operate, or are otherwise authorized to test — for example your own infrastructure, or public DNS/WHOIS records.
Do not use LinuxCLI to probe, harass, or gather information about third-party systems without authorization. Requests are rate-limited per IP (and per API key, if you generate one), and abusive use may be blocked.
The full policy, including what happens if it's violated, is in the Terms of Service.
LinuxCLI is built and maintained by R0men on GitHub.