Odel
Sandbox as a Service

Sandbox as a Service

Local
@fstandhartingerJavaScriptMITUpdated 6 days ago

Give an agent a real Linux VM: run commands, move files, expose a preview URL, destroy it.

sandbox-as-a-service-mcp

An MCP server that gives an agent a real Linux virtual machine it can break.

Eleven tools: create a sandbox, run shell commands in it, write and read files, list what a run produced, expose a port on a public preview URL, extend the lifetime, destroy it, and check what it all cost.

Each sandbox is a dedicated VM with its own kernel — not a container sharing a host with other people's code. It is never reused between accounts and is destroyed when it expires, whether or not anything remembered to ask.

Use it

AAS_API_KEY=aas_sk_... npx -y https://sandbox-as-a-service.com/mcp.tgz

Get a key at sandbox-as-a-service.com — new accounts start with free credit and no card.

Claude Desktop / Claude Code

{
  "mcpServers": {
    "sandbox": {
      "command": "npx",
      "args": ["-y", "https://sandbox-as-a-service.com/mcp.tgz"],
      "env": { "AAS_API_KEY": "aas_sk_..." }
    }
  }
}

The tools

ToolWhat it does
create_sandboxCreates a VM and returns its id once it is ready.
run_commandRuns a shell command as an unprivileged user. Returns stdout, stderr, exit code.
write_fileWrites a file. Content travels out of band, so quotes and binary survive.
read_fileReads a file back — how an agent gets at what its code produced.
list_filesLists a directory tree, so an agent can find what a run produced.
expose_portGives a server inside the sandbox a public https URL to share.
get_sandboxStatus, size and expiry.
list_sandboxesEverything on the account, newest first — useful for finding strays.
extend_sandboxPushes the expiry out when a job outgrows its timeout.
destroy_sandboxDestroys it and stops billing.
get_usageRemaining credit and recent usage.

Notes for agents

  • Code runs as an unprivileged user. There is no sudo, so apt-get will not work; use pip install --user --break-system-packages or npm install, both of which do.
  • run_command waits for the command to finish. Start a server with & or it will hold the call open until the timeout.
  • A sandbox is destroyed when its timeout expires whether or not destroy_sandbox is called, so a forgotten sandbox costs minutes, not money forever. Calling it anyway returns the minutes you were not going to use.

Environment

Variable
AAS_API_KEYRequired. Your API key.
AAS_BASE_URLOptional. Defaults to https://sandbox-as-a-service.com/v1.

MIT licensed. The service it talks to is at sandbox-as-a-service.com; docs.