Figaro is the Endpoint Action Layer — a single API that executes commands on Windows, macOS, Linux, and Android endpoints. Install the agent once on each device, then trigger any action forever: from your product, your backend, or your AI agents.
The problem
MDMs are platforms built to enrol, inventory, and govern devices at an IT level. That’s not what builders need. If your product needs to trigger an action on an endpoint, you shouldn’t have to adopt an entire platform to do it.
MDMs come with hundreds of features you’ll never use — and charge you for all of them. You can’t buy just the execution layer.
The platform decides how actions are triggered, sequenced, and reported. Your business logic lives inside someone else’s system.
No clean API. No programmable workflows. No way to plug device execution into your own product or agent without months of work.
Setup once, execute forever
There’s no MDM enrolment, no certificate authority, no fleet configuration wizard. You run a single install command on the target machine — and that endpoint is permanently reachable through the Figaro API.
One API call. Any action. Any time. Works for humans, automation scripts, and AI agents equally.
Run one command or push via your existing tooling. Takes under 60 seconds per endpoint.
The agent authenticates, establishes a secure channel, and confirms it’s ready for action.
Your product, agent, or automation triggers actions via the API. No re-enrolment. No drift.
Under the hood
Here’s exactly what happens between your API call and the signed result landing back in your system.
Who can trigger an action
What comes back — every time
"status": "completed", "exit_code": 0, "executed_at": "2026-04-21T09:12:03Z", "actor": "ai-agent", "execution_id":"fg_01HX92A3", "stdout": "credentials rotated", "audit": "attached"
Figaro Cloud — receipt
Auth & routing
Figaro Cloud → Endpoint
Encrypted delivery
Endpoint — local agent
OS-level execution
Figaro Cloud — close
Audit assembly & signed response
What you can build
Designed to fit into your stack, not replace it.
Windows, macOS, Linux, Android — one unified API surface. Platform differences are abstracted away from your application code entirely.
Figaro never assumes what you’re trying to build. You define every decision, trigger, and workflow. We execute exactly what you send — nothing more, nothing less.
Every action is timestamped, attributed, and stored. Who triggered it. What ran. What was the result. Full traceability — cryptographically signed, append-only — without building it yourself.
Use cases
Developers trust utility, not promises. Here’s what real teams ship.
SaaS Builders
Your SaaS needs to trigger something on a customer’s device — rotate credentials, push a config, restart a service. Without Figaro, that means adopting a full MDM platform, negotiating contracts, and building an integration that will outlive your sprint. With Figaro, it’s one API call. Your product stays in control of every decision. Figaro just executes it.
MSPs & IT Providers
Your clients don’t know and don’t need to know what’s underneath. Build your management dashboard, your automation workflows, your client-facing reports — on top of Figaro. You own the product. Figaro handles execution, delivery, and the audit trail across every client fleet you manage.
Internal Tools
An ops engineer needs to restart a service on a production server, push a config to a fleet of kiosks, or lock a device that was just reported lost. Today that’s a ticket, a handoff, and a wait. With Figaro embedded in your internal tooling, it’s a button click — with an approval gate, an actor log, and a signed result that nobody has to ask for later.
VR / XR
Push content, trigger scene loads, lock headsets between sessions, wipe remotely. XR devices run Android — Figaro already speaks that language.
Healthcare
Deploy APKs, lock tablets, manage clinical kiosks — embedded in your own product, not a third-party platform.
AI Agents
When your agent decides something needs to happen on a device, Figaro is the layer that makes it happen — with auth, retries, and a signed audit trail.
Leasing & Hardware
Provisioning, credential rotation, remote actions across large portfolios. Active endpoints only — idle hardware costs nothing.
Convinced? Start now.
Figaro is running in most stacks within a day. No sales process to start.
Security & compliance
“No MDM enrolment, no certificate authority” — we understand why that sounds alarming. Here’s exactly how Figaro handles every concern a security-conscious team will raise.
rotate_credentials cannot run wipe_device, regardless of what the agent requests. You define the blast radius at key creation. Figaro enforces it at execution.Pricing
Pay only for endpoints that executed something this month. Idle devices enrolled but dormant cost nothing.
As your fleet grows, cost per active endpoint drops automatically. No renegotiation, no annual surprise.
No seat minimums, no base subscription. You start small, we scale with you. Talk to us and we’ll model it for your exact fleet.
We’re inviting a small number of teams to get direct access to our roadmap, our engineering team, and pricing that reflects the early relationship.
Features you need get prioritised. You get them before general release — and your feedback shapes how they ship.
Direct line to our engineering team throughout integration. We build alongside you — not hand you a doc and disappear.
Rates locked at the founding tier for the life of your account. You won’t be repriced as the product matures.
Fewer than 10 spots per quarter.
Tell us what you’re building and your fleet size — we review every application personally and respond within 48h.
Start with the docs and have Figaro running in hours. If you’d rather talk through your use case first, we’re happy to map it together.