Run the work in the cloud.
Keep the keys at home.

Each muxcode task can run in its own sandbox on Cloudflare. The agent reads, edits and runs checks there, while the model loop, your model keys and every permission decision stay on your Mac.

Pro and Pro+ · One sandbox per task · Runs on Cloudflare

What it is for. Work you would rather not run locally.

Two halves. One task.

The sandbox never sees a model. muxcode keeps the conversation and decides what may run; the sandbox only carries out the reads, edits and commands it is sent.

Two backends, one set of files

A command runs in the light shell when it can, with no network at all. It moves to the container when a program it names is missing. Both see the same workspace.

muxcode Sandbox
  • Shell
    • grep -r TODO src (runs)
    • cat package.json (runs)
  • Container
    • cargo test (runs)
    • mvn test (runs)

The keys stay home

Model traffic never reaches the sandbox, and nothing of muxcode's is installed there. It only carries out the reads, edits and commands it is sent.

Only what the task needs

Only the variables the app sends for the task reach a command. Paths outside the workspace are refused, and every command stops after 30 minutes.

Downloads in. Nothing out.

The container reaches the internet through one gateway. It can fetch packages and clone from GitHub; it cannot push, publish or send your code anywhere.

Downloads in, nothing out

Package registries, crates, Go, Maven and Gradle, Packagist, GitHub and Debian mirrors are on the list. Reads to them go through. A push, a publish or any other host does not.

Container Gateway
  • Listed
    • npm install zod (runs)
    • git fetch (runs)
    • git push (refused)
  • Unlisted
    • curl paste.example (refused)

Credentials stripped

Authorization and cookie headers are removed from every request, and none is added. A redirect comes back to the container and goes through the same check.

Every decision logged

Each request is recorded with its method, host and the rule that answered it.

See where each part runs

Start from your branch. Land a branch.

The repository moves over Git, in both directions. A task works on its own fork, so nothing it does touches your repository until you fetch the result and choose to land it.

Sleeps, and keeps the files

After 20 idle minutes the compute stops. The files stay, and the next command wakes it. The container starts only when a command needs it.

Comes back as a branch

The change is committed to a branch on the task's fork, for you to fetch and land. A task stopped for 14 days deletes its files and its fork.

Scoped to the task. Scoped to your workspace.

Every request is checked against the workspace key that made it. A sandbox belongs to one task in one workspace, and it can reach nothing else.

  • A fence around the files Paths outside /workspace and /home/agent are refused, whatever the command asks for.
  • Your environment stays yours Only the variables the app sends for the task reach a command. HOME and PATH come from the sandbox.
  • Tokens that expire Git tokens are scoped to one repository, last 15 minutes and never travel in a URL.
  • Names you cannot forge Every repository name is built from your authenticated workspace. A request cannot name another.
  • A ceiling on every command A command is stopped after 30 minutes. Closing the connection stops it sooner.
  • Roles that mean something Viewers cannot start a sandbox. Running commands in a repository takes a member who can change it.

Your project's checks. Already installed.

The container carries the toolchains muxcode runs a project's tests, linters and type checks with, each pinned to a version and checksum.

  • Rust 1.98
  • Node 24 · pnpm · Yarn
  • Bun
  • Go 1.27
  • Python 3 · uv · pytest
  • JDK 21 · Maven · Gradle
  • PHP 8.4 · Composer
  • git · ripgrep · fd · jq

Hours you can see. Limits that hold.

The sandbox is included with Pro and Pro+. In a team, each member's own hours join a pool the whole team shares.

Asked before it runs

A task is admitted before it starts or wakes. Past the month's hours, or the member's running cap, it stays stopped and says why.

Warned before it stops

At nine-tenths of the month's hours the task says so. At the limit it stops, and its files stay.

Visible to the team

Sandbox tasks and triage runs, their activity and checkpoints, show in the workspace console.

These prompts already work. Run them in a sandbox task.

Start a task in the sandbox from muxcode, paste one, and change the names to yours.

  • Toolchains Run the Go and PHP test suites in the sandbox and fix whatever fails.
  • Long runs Run the full integration suite in the sandbox and tell me which tests are slowest.
  • Isolation Try the Postgres 17 upgrade in the sandbox. Migrate, run the tests, and leave my machine alone.
  • Isolation Upgrade every dependency to its latest major, run the build, and checkpoint only if it is green.
  • Reproduce Reproduce the bug from issue 412 in a clean checkout and show me the failing test first.
  • Supply chain Install the project from a clean clone and list every package it downloads.
Plan, build and review on your desktop The harness the sandbox works for: orchestration, the permission gate and your own models. Harness

Give the task a sandbox. Keep the rest at home.

The desktop harness is free. Pro and Pro+ add the cloud sandbox, search by meaning and re-index on push.