Back to the catalog

Sandbox as a Service

Give an agent a real Linux VM: run commands, move files, expose a preview URL, destroy it.

Open source Open in the app JSON README (API)

About

Give an agent a real Linux VM: run commands, move files, expose a preview URL, destroy it.

Details

Kind
MCP servers
Topic
Developer tools
Publisher
com.sandbox-as-a-service
Origin
official
Category
ferramentas
Transport
local
Version
1.1.0
Last push
2026-09-08T00:10:08Z
Repository state
ativo
Language
JavaScript
License
MIT
Added
2026-08-29 03:01:21
Updated
2026-08-29 03:01:21
Origin id
com.sandbox-as-a-service/mcp

README

# sandbox-as-a-service-mcp

An [MCP](https://modelcontextprotocol.io) server that gives an agent a real Linux virtual machine it
can break.

Eleven tools: create a sandbox, run shell commands in it, write and read files, list what a run
produced, expose a port on a public preview URL, extend the lifetime, destroy it, and check what it
all cost.

Each sandbox is a dedicated VM with its own kernel — not a container sharing a host with other
people's code. It is never reused between accounts and is destroyed when it expires, whether or not
anything remembered to ask.

## Use it

Maintained by the operator of [Sandbox as a Service](https://sandbox-as-a-service.com).

### Hosted MCP (no local package)

For a client that supports Streamable HTTP, connect to:

```text
https://sandbox-as-a-service.com/v1/mcp
```

Send your own API key on each request as `Authorization: Bearer <your-api-key>`
or `x-api-key: <your-api-key>`. Get it at
[Dashboard → API keys](https://sandbox-as-a-service.com/dashboard/keys).
Never put an API key in the URL or share one through a registry.

The hosted server exposes **12 tools**: the eleven account/execution tools below
plus `get_service_info`. Anonymous `initialize`, `tools/list`, and
`get_service_info` work for free hosted discovery; account and execution calls
still require your key. The local stdio server (including the current downloadable
`mcp.tgz` v1.1.0) exposes the eleven account/execution tools. Use the hosted endpoint
for keyless service information. A GET-only check is not a connection test: this
endpoint uses MCP POST requests and SSE responses.

On [Smithery](https://smithery.ai/servers/florian-standhartinger/sandbox-as-a-service),
set `apiKey` to your own raw key; it maps to the `x-api-key` header.
[Connection documentation](https://sandbox-as-a-service.com/docs/mcp).

### Local stdio (current hosted package)

```bash
AAS_API_KEY=aas_sk_... npx -y https://sandbox-as-a-service.com/mcp.tgz
```

Get a key at [sandbox-as-a-service.com](https://sandbox-as-a-service.com) — new accounts start with
free credit and no card.

### Claude Desktop / Claude Code

```json
{
  "mcpServers": {
    "sandbox": {
      "command": "npx",
      "args": ["-y", "https://sandbox-as-a-service.com/mcp.tgz"],
      "env": { "AAS_API_KEY": "aas_sk_..." }
    }
  }
}
```

## The tools

| Tool | What it does |
|---|---|
| `create_sandbox` | Creates a VM and returns its id once it is ready. |
| `run_command` | Runs a shell command as an unprivileged user. Returns stdout, stderr, exit code. |
| `write_file` | Writes a file. Content travels out of band, so quotes and binary survive. |
| `read_file` | Reads a file back — how an agent gets at what its code produced. |
| `list_files` | Lists a directory tree, so an agent can find what a run produced. |
| `expose_port` | Gives a server inside the sandbox a public https URL to share. |
| `get_sandbox` | Status, size and expiry. |
| `list_sandboxes` | Everything on the account, newest first — useful for finding strays. |
| `extend_sandbox` | Pushes the expiry out when a job outgrows its timeout. |
| `destroy_sandbox` | Destroys it and stops billing. |
| `get_usage` | Remaining credit and recent usage. |

## Notes for agents

- Code runs as an unprivileged user. There is no `sudo`, so `apt-get` will not work; use
  `pip install --user --break-system-packages` or `npm install`, both of which do.
- `run_command` waits for the command to finish. Start a server with `&` or it will hold the call
  open until the timeout.
- A sandbox is destroyed when its timeout expires whether or not `destroy_sandbox` is called, so a
  forgotten sandbox costs minutes, not money forever. Calling it anyway returns the minutes you were
  not going to use.

## Environment

| Variable | |
|---|---|
| `AAS_API_KEY` | Required. Your API key. |
| `AAS_BASE_URL` | Optional. Defaults to `https://sandbox-as-a-service.com`. Use the origin only, without `/v1`; the client adds that API prefix. |

MIT licensed. The service it talks to is at
[sandbox-as-a-service.com](https://sandbox-as-a-service.com);
[docs](https://sandbox-as-a-service.com/docs/mcp).

More