Skip to main content
Glama
fstandhartinger

sandbox-as-a-service-mcp

sandbox-as-a-service-mcp

An MCP server that gives an agent a real Linux virtual machine it can break.

Eleven tools: create a sandbox, run shell commands in it, write and read files, list what a run produced, expose a port on a public preview URL, extend the lifetime, destroy it, and check what it all cost.

Each sandbox is a dedicated VM with its own kernel — not a container sharing a host with other people's code. It is never reused between accounts and is destroyed when it expires, whether or not anything remembered to ask.

Use it

AAS_API_KEY=aas_sk_... npx -y https://sandbox-as-a-service.com/mcp.tgz

Get a key at sandbox-as-a-service.com — new accounts start with free credit and no card.

Claude Desktop / Claude Code

{
  "mcpServers": {
    "sandbox": {
      "command": "npx",
      "args": ["-y", "https://sandbox-as-a-service.com/mcp.tgz"],
      "env": { "AAS_API_KEY": "aas_sk_..." }
    }
  }
}

Related MCP server: microsandbox-mcp

The tools

Tool

What it does

create_sandbox

Creates a VM and returns its id once it is ready.

run_command

Runs a shell command as an unprivileged user. Returns stdout, stderr, exit code.

write_file

Writes a file. Content travels out of band, so quotes and binary survive.

read_file

Reads a file back — how an agent gets at what its code produced.

list_files

Lists a directory tree, so an agent can find what a run produced.

expose_port

Gives a server inside the sandbox a public https URL to share.

get_sandbox

Status, size and expiry.

list_sandboxes

Everything on the account, newest first — useful for finding strays.

extend_sandbox

Pushes the expiry out when a job outgrows its timeout.

destroy_sandbox

Destroys it and stops billing.

get_usage

Remaining credit and recent usage.

Notes for agents

  • Code runs as an unprivileged user. There is no sudo, so apt-get will not work; use pip install --user --break-system-packages or npm install, both of which do.

  • run_command waits for the command to finish. Start a server with & or it will hold the call open until the timeout.

  • A sandbox is destroyed when its timeout expires whether or not destroy_sandbox is called, so a forgotten sandbox costs minutes, not money forever. Calling it anyway returns the minutes you were not going to use.

Environment

Variable

AAS_API_KEY

Required. Your API key.

AAS_BASE_URL

Optional. Defaults to https://sandbox-as-a-service.com/v1.

MIT licensed. The service it talks to is at sandbox-as-a-service.com; docs.

A
license - permissive license
Not graded
quality - not tested
B
maintenance

Maintenance

Maintainers
Response time
Release cycle
1Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

View all related MCP servers

Related MCP Connectors

  • Operate Linux, macOS and Windows from your LLM. Every action runs through an auditable allowlist.

  • Persistent cloud development environments that coding agents create, run and test software in.

  • The agent-native cloud: database, functions, AI, storage, computers. 50 tools, one API key.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/fstandhartinger/sandbox-as-a-service-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server