microsandbox
Supports Git operations within sandbox environments for source control management
Offers Node.js execution in isolated microVMs for secure running of untrusted JavaScript code
Enables AI to process data using NumPy in a secure sandbox environment
Allows data analysis with Pandas in a secure sandbox environment for processing spreadsheets and datasets
Provides a secure Python execution environment in isolated microVMs, with support for NumPy, Pandas, and other data analysis libraries
Supports running Rust code in isolated microVMs with SDK integration for secure execution
Provides access to TensorFlow for AI model training and inference within a secure sandbox
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@microsandboxrun python code to calculate fibonacci sequence"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Microsandbox runs untrusted workloads inside fast, local microVMs: AI agents, user code, plugins, CI jobs, dev environments, scrapers, and automation.
Hardware Isolation: Hardware-level isolation with tiny virtual machines.
Branch & Snapshot: Fork live sandboxes. Save running sandbox state and restore later.
Cross Platform: Runs on Linux, macOS, and Windows.
OCI Compatible: Runs standard container images from Docker Hub, GHCR, or any OCI registry.
Docker-Like Workflows: Familiar image, command, shell, and volume workflows.
Instant Startup: Average boot timesboot-time under 100 milliseconds.
Embeddable: Spawn VMs right within your code. No setup server. No long-running daemon.
Secrets That Can't Leak: Unexploitable secret keys that never enter the VM.
Long-Running: Sandboxes can run in detached mode. Great for long-lived sessions.
Agent-Ready: Your agents can create their own sandboxes with our Agent Skills and MCP server.
Related MCP server: container-mcp
Getting Started
Install the CLI
curl -fsSL https://install.microsandbox.dev | sh # π macOS / π§ Linuxirm https://install.microsandbox.dev/windows | iex # πͺ Windowsbrew install superradcompany/tap/microsandboxnpm i -g microsandboxuv tool install microsandboxcargo install microsandboxStart creating sandboxes once installed:
msb run ubuntu
Install the SDK
npm i microsandbox # π¦ TypeScriptcargo add microsandbox # π¦ Rustuv add microsandbox # π Pythongo get github.com/superradcompany/microsandbox/sdk/go # πΉ Go
Requirements:
macOS: Apple Silicon.
Linux: KVM enabled.
Windows: WHP enabled.
Warning: Microsandbox is still beta software. Expect breaking changes, missing features, and rough edges.
CLI
The msb CLI provides a complete interface for managing sandboxes, snapshots, images, and volumes.
Run a Command
msb run python -- python3 -c "print('Hello from a microVM!')"
Named Sandboxes
# Create and start a named sandbox msb create --name app python# Execute commands msb exec app -- python -c "import this" msb exec app -- curl https://example.com# Fork a running sandbox. msb branch app --name experiment msb exec experiment -- python -c "print('An independent copy!')"# Save now, resume later msb snapshot create --from-sandbox app --full -o saved.msb msb restore saved.msb --name restored# Lifecycle msb stop app msb start app msb rm app
Image Management
msb pull python # Pull an image msb image ls # List cached images msb image rm python # Remove an image
Configuration File
msb run --conf sandbox.yaml -- octocat# sandbox.yaml image: python:3.12 memory: 64M network: allow: - api.github.com scripts: octocat: | python - <<'PY' import urllib.request request = urllib.request.Request( "https://api.github.com/octocat", headers={"User-Agent": "microsandbox-example"}, ) with urllib.request.urlopen(request) as response: print(response.read().decode()) PY
Install & Uninstall Sandboxes
msb install ubuntu # Install ubuntu sandbox as 'ubuntu' command ubuntu # Opens Ubuntu in a microVM msb uninstall ubuntu # Uninstall the ubuntu sandbox
Status & Inspection
msb ls # List all sandboxes msb ps app # Show sandbox status msb inspect app # Detailed sandbox info msb metrics app # Live CPU/memory/network stats
Run:
Β· msb --help for quick help menu.
Β· msb --tree for complete command hierarchy and descriptions.
Β· msb <command> --tree for a specific command tree.
SDK
The SDK lets you create and control sandboxes directly from your application. Sandbox.builder("...").create() boots a microVM as a child process. No infrastructure required.
Run Code in a Sandbox
import { Sandbox } from "microsandbox"; await using sandbox = await Sandbox.builder("my-sandbox") .image("python") .cpus(1) .memory(512) .create(); const output = await sandbox.exec("python", [ "-c", "print('Hello from a microVM!')", ]); console.log(output.stdout());use microsandbox::Sandbox; #[tokio::main] async fn main() -> Result<(), Box<dyn std::error::Error>> { let sandbox = Sandbox::builder("my-sandbox") .image("python") .cpus(1) .memory(512) .create() .await?; let output = sandbox .exec("python", ["-c", "print('Hello from a microVM!')"]) .await?; println!("{}", output.stdout()?); sandbox.stop().await?; Ok(()) }import asyncio from microsandbox import Sandbox async def main(): sandbox = await Sandbox.create( "my-sandbox", image="python", cpus=1, memory=512, ) output = await sandbox.exec("python", ["-c", "print('Hello from a microVM!')"]) print(output.stdout_text) await sandbox.stop() asyncio.run(main())require "microsandbox" sandbox = Microsandbox::Sandbox.create( "my-sandbox", image: "python", cpus: 1, memory: 512, network: { allowed_hosts: ["api.openai.com"], allowed_ports: [443] }, secrets: [{ env: "OPENAI_API_KEY", value: ENV.fetch("OPENAI_API_KEY"), allowed_host: "api.openai.com" }] ) output = sandbox.exec("python", ["-c", "print('Hello from a microVM!')"]) puts output.stdout sandbox.stopSee the Ruby SDK guide for installation, lifecycle, networking, and backend details.
package main import ( "context" "fmt" "log" microsandbox "github.com/superradcompany/microsandbox/sdk/go" ) func main() { ctx := context.Background() // Downloads the microsandbox runtime to ~/.microsandbox/ on first run. if _, err := microsandbox.EnsureRuntime(ctx, microsandbox.RuntimeConfig{}, microsandbox.InstallOptions{}); err != nil { log.Fatal(err) } sandbox, err := microsandbox.CreateSandbox(ctx, "my-sandbox", microsandbox.WithImage("python"), microsandbox.WithCPUs(1), microsandbox.WithMemory(512), ) if err != nil { log.Fatal(err) } defer sandbox.Stop(ctx) output, err := sandbox.Exec(ctx, "python", []string{"-c", "print('Hello from a microVM!')"}) if err != nil { log.Fatal(err) } fmt.Println(output.Stdout()) }
The first call to
create()pulls the image if it isn't cached locally, so it may take longer depending on your connection. Subsequent runs reuse the cache.
Examples
Practical ways to put microsandbox to work:
β’ Docker in a Sandbox: Run Docker without touching the host daemon. β’ OpenCode: Give a coding agent an isolated project workspace. β’ Browser Use: Run an AI browser agent inside a microVM. β’ Playwright: Run headless browser jobs inside a microVM. β’ Warm Workers: Snapshot a toolchain and launch clean workers. β’ Migration Rehearsal: Test a database migration, then restore the baseline. β’ GitHub Actions Runner: Run each self-hosted job in a disposable microVM. β’ Documents to PDF: Convert untrusted documents in a fresh offline worker.
Community Showcase
Agent frameworks & runtimes
β’ Eve by Vercel: Agent framework that ships microsandbox as a sandbox backend. β’ Agentic Coding Quickstart by U.S. GSA: From zero to a running AI coding agent with USAi in minutes. β’ Condukt and Once by Tuist: Elixir agentic engine, and cacheable actions that run in fresh sandboxes. β’ langchain-microsandbox by kenwoodjw: Microsandbox integration for LangChain Deep Agents. β’ Smithers by Smithers: Agent workflows with full observability, rewind, fork, and replay. β’ AgentConnect: Bring multiple AI agents into your team's chats, issues, and pull requests. β’ wrap by Tobi LΓΌtke: Run coding agents and project commands in isolated Arch Linux microVMs. β’ Agent VM by Wiren Board: Run AI agents in safe VMs scoped to a local folder.
Tools & infrastructure
β’ h5i by h5i: Secure, auditable browser for AI agents, written in pure Rust. β’ Devsy by Devsy: Deploy devcontainers onto any cloud, Kubernetes cluster, or Docker host. β’ OpenWork by Different AI: Open-source Claude Cowork alternative with a microsandbox image.
Guides & showcases
β’ Awesome Microsandbox by ya-luotao: Curated list of SDKs, integrations, tools, and resources. β’ msb-omarchy by ya-luotao: Omarchy desktop with graphics inside a microVM on Apple Silicon.
AI Agents
Agent Skills
Teach any AI coding agent how to use microsandbox by installing the Agent Skills. Works with Claude Code, Cursor, Codex, Gemini CLI, GitHub Copilot, and more.
npx skills add superradcompany/skills
MCP Server
Connect any MCP-compatible agent to microsandbox with the MCP server. Provides structured tool calls for sandbox lifecycle, command execution, filesystem access, volumes, and monitoring.
# Claude Code claude mcp add --transport stdio microsandbox -- npx -y microsandbox-mcp
Documentation
For guides, API references, and examples, visit the microsandbox documentation.
Contributing
Interested in contributing to microsandbox? Check out our CONTRIBUTING.md for guidelines and DEVELOPMENT.md for build, test, and release instructions.
License
This project is licensed under the Apache License 2.0.
Acknowledgements
Special thanks to all our contributors, testers, and community members who help make microsandbox better every day! We'd like to thank the following projects and communities that made microsandbox possible: libkrun and smoltcp
Boot time refers to guest boot on an M1 machine.
β©
This server cannot be deployed
Maintenance
Related MCP Connectors
Persistent Linux microVMs for agents: root, internet, sub-second resume and a public URL.
MCP server for Superserve sandboxes: create, exec, and manage Firecracker microVMs
Manage Sprites: sandboxed compute environments with exec, services, and checkpoints.
- mcp-serverOAuthai.cdbx
Build Apps and run code in 30 languages β sandboxed, with persistent sessions for agent loops.
Related MCP Servers
- AlicenseAqualityDmaintenanceProvides a local, isolated Linux VM sandbox for AI agents using Apple's Virtualization.framework, enabling fast command execution (~60ms) and package management without cloud costs.351MIT
- AlicenseAqualityDmaintenanceRun AI agents in VM-isolated sandboxes on your Mac.151MIT
- AlicenseAqualityCmaintenanceEphemeral MicroVM-isolated code execution for AI agents. Run Python, Node, or bash β fresh hardware-isolated VM per call, hard-purged after. No state persists between calls.133 npmMIT
- FlicenseNot gradedqualityDmaintenanceEnables secure execution of bash, Python, and Node.js code in isolated Firecracker microVMs with configurable timeouts and no network access.-