# boxd > Composable computers for devs and agents. Real hardware-isolated Linux VMs in the cloud: compose one, then spin up as many as you need. boxd gives developers and AI agents their own persistent Linux machines accessible via SSH. No SDK required — if it can open an SSH connection, it can use boxd. ## Quick start ``` curl -fsSL https://boxd.run/downloads/install.sh | sh boxd machine new my-app ``` ## Links - Website: https://boxd.run - Pricing: https://boxd.run/pricing - Capabilities: https://boxd.run/features - Use cases: https://boxd.run/use-cases - Blog: https://boxd.run/blog - Contact: https://boxd.run/contact - Full LLM context: https://boxd.run/llms-full.txt ## Capabilities - https://boxd.run/features/cli — One binary drives every boxd machine: create, fork, exec, publish. --json on every command, plus an interactive REPL and managed SSH config. - https://boxd.run/features/forking — Copy a running machine in under 200ms, save its memory and disk as a snapshot, or roll it back to a checkpoint in place. Running state included, not just the disk. - https://boxd.run/features/domains — Every boxd machine gets an HTTPS URL. Publish any port on a named subdomain, forward raw TCP or UDP, and point your own domain at it — certificates and DNS handled. ## Use cases - https://boxd.run/use-cases/dev-environments — Every developer gets a machine with the app already running. Fork it to experiment, share a URL to preview it, and pay nothing while it sleeps. - https://boxd.run/use-cases/agent-sandboxes — The fastest, most isolated agent sandboxes. KVM virtualization, EU-hosted, under 10ms cold boot. - https://boxd.run/use-cases/background-agents — Let agents ship code while your team sleeps. Fork a machine, run the agent, sleep when done. ## Blog & manifesto - https://boxd.run/blog/the-agent-lives-inside-the-machine — Fork, hibernation, persistence, SSH. Why every boxd decision flows from one architectural bet. - https://boxd.run/blog/persistence-beats-ephemeral — Why persistent state is the foundation of everything boxd does, and what falls out for free. - https://boxd.run/blog/where-to-run-agent-harness-production — Anthropic and LangChain define what an agent harness is. This piece answers the question they don't: where does the harness actually live in production? - https://boxd.run/blog/mcp-server-hosting-complete-guide — Where do production MCP servers actually live? The four hosting patterns, what changes when MCP goes to production, and the five properties a remote MCP server host needs. - https://boxd.run/blog/anthropic-computer-use-on-a-remote-vm — Computer use needs a desktop. The hard part isn't the API. It's where the desktop lives. What the workload actually needs from its host, and why most cloud primitives don't ship with a display. - https://boxd.run/blog/self-hosted-agent-execution-for-engineering-teams — Where does the agent actually execute? The compliance and engineering dimensions, what the substrate has to provide, and the EU sovereignty angle, honestly. - https://boxd.run/blog/cloud-dev-environment-complete-guide — Why CDE is back in the conversation, the four shapes the category comes in this year, and what changed when AI agents joined the workload. - https://boxd.run/blog/billions-of-machines — 99.9% of code will soon be written and maintained by agents. What those agents need from a machine, derived one requirement at a time. - https://boxd.run/blog/cloud-for-small-software — We believe the unit of small software is a running machine. - https://boxd.run/blog/where-to-run-self-hosted-apps — Every self-hosting list tells you what to run, not where. The four real homes for self-hosted software compared: a box at home, a VPS, Coolify on a VPS, and managed persistent machines. - https://boxd.run/blog/heroku-alternatives-small-apps — Sorted by shape rather than by vendor. When Render, Railway or Fly.io is the right answer, when a plain Linux machine is, and how the current pricing actually compares. - https://boxd.run/blog/run-a-script-24-7 — Why your laptop, nohup, GitHub Actions cron and serverless all fall over, and the working systemd setup that keeps a scraper or bot running through crashes and reboots. - https://boxd.run/blog/boxd-vs-exe-dev — Two products in the same lane: persistent Linux VMs over SSH, batteries included. An honest comparison of the design choices that fall out of the shared thesis. - https://boxd.run/blog/boxd-vs-sprites — Sprites and boxd agree on the architecture: persistent microVMs are the right primitive for AI agents. Where the two implementations diverge, honestly. - https://boxd.run/blog/development-workspaces — A development environment made of machines: one you work on, a fork of it for every task in flight, an address on each, and a snapshot the whole team starts from. - https://boxd.run/blog/preview-environments — Every pull request gets its own machine, forked from your golden image, live at its own URL, and reclaimed when the branch closes. - https://boxd.run/blog/coding-agents — Claude Code, Codex and OpenCode ship on every machine, already logged in and already told how the platform works. - https://boxd.run/blog/personal-assistants — An always-on machine with tools, memory and a messaging gateway, so your assistant keeps working after you close your laptop. - https://boxd.run/blog/sandboxes — Run untrusted code behind a real KVM boundary, and dial the isolation up to airtight when the workload needs it. - https://boxd.run/blog/agentic-saas — Create and manage a machine per user through the SDK, without operating a fleet by hand. - https://boxd.run/blog/reproducible-rl-environments — Give every rollout a byte-identical warm start, forked in milliseconds, so your numbers measure the policy and not the setup. - https://boxd.run/blog/agent-swarm-intelligence — Run many agents at once, each on its own machine, and collect one answer instead of a pile of half-finished branches. - https://boxd.run/blog/oss-integrations — The open source agent frameworks that already run on boxd machines, and what they use underneath. - https://boxd.run/blog/every-clone-wakes-up-confused — A cloned VM resumes holding its parent's clock calibration, LAPIC state, network config and entropy pool. How an injected NMI, a pvclock MSR rewrite, an APIC_TMICT poke and a signal to PID 1 put it right. - https://boxd.run/blog/fork-for-somebody-elses-process — Why fork() and userfaultfd both fail at cloning a running microVM, and the Linux system call we added instead: one VMA imported from a paused process with fork-style CoW, THP included. - https://boxd.run/blog/a-secret-the-machine-never-has — The guest gets an unguessable 37-byte dummy; the real credential is substituted into the request at the network boundary. TLS interception, per-host verdicts, and the two bugs that only appear in production. - https://boxd.run/blog/machines-inside-your-own-network — Serve a whole organization's machines over its own Tailscale network. Same hostnames, same TLS certificates, reachable only from inside the tailnet. How the boxd edge joins a tailnet in-process, why the listener is the tenant, and what changes for the team. - https://boxd.run/blog/saga-legal — How Saga Legal replaced one shared staging server with a boxd preview environment per pull request: about 380 pull requests a month, legal sign-off in 30 to 90 minutes instead of a day or more, set up in one day with no app changes. - https://boxd.run/blog/we-raised-2m-to-kill-localhost — boxd has raised €2 million in pre-seed funding led by BlueYard Capital, with Antler, OVNI, s20, Script Capital and angels who have built developer infrastructure. Why every developer should get unlimited remote environments in milliseconds, and what we are building next. - https://boxd.run/blog/my-kernel-snitches — Automatic port detection in a microVM, from the inside out: a listen() trigger patched into net/socket.c, an 8-byte message over a legacy PIO port, and a design where the guest can lie without it mattering. - https://boxd.run/blog/automations-that-sleep — Where an automation should run, and why its trigger has to live outside the machine: schedules and events held by the platform, a machine that hibernates between runs and wakes in milliseconds, no environment rebuilt, and nothing to deploy. - https://boxd.run/blog/a-single-rust-binary — boxd is one Rust binary. No Postgres, no Redis, no Kubernetes. Why simplicity is the design. - https://boxd.run/blog/architecture/how-boxd-works — An honest architectural tour: KVM microVMs, Raft consensus, SSH-first routing, and per-VM cgroups. - https://boxd.run/blog/boxd-101 — A machine in milliseconds, ten agents in parallel on forks of it, resume with memory intact, and a bill that stops while it waits. ## Key features - Persistent state: Files, packages, databases, running processes — all survive disconnects, reboots, and time. Your agent stops at 2am, picks up at 9am. - Instant forking: Fork a full machine — memory, disk, processes — in under 200ms. Branch to explore approaches in parallel, keep the winner. - Scriptable interface: Drive everything from the `boxd` CLI, with `--json` on every command for scripts and agents. No dashboard, no heavyweight SDK. - Always on: Machines keep running after you disconnect. Long builds, background jobs, agent tasks all continue. - Automatic HTTPS URLs: Every machine gets a public URL automatically. Certificates and DNS handled. - KVM isolation: Every machine runs its own kernel — real hardware-level isolation, not containers. Safe for untrusted, agent-generated code. - Pause to zero: Machines sleep when idle. You pay nothing while they're off. Resume in sub-millisecond. - Self-hostable: Run boxd on your own infrastructure, any KVM-capable server. EU hosting by default. No vendor lock-in. ## Specs - Ubuntu 24.04 (full, unminimized, with man pages and systemd) - 2 vCPU, 8 GiB RAM, 100 GiB disk per machine (default size) - Cold boot: <10ms - Resume from sleep: instant (sub-millisecond) - Fork time: <200ms ## Pricing - Credit-based, billed in euros or US dollars (an organization's currency is set when it is created). RAM bills on memory in use and disk on what you have written to, never on provisioned size. - vCPU: EUR 0.049 / USD 0.059 per vCPU-hour, on the machine's full vCPU count, only while it runs. - RAM: EUR 0.015 / USD 0.018 per GiB-hour, on memory actually resident (not the provisioned 8 GiB), while running or in standby. - Disk: EUR 0.0001 / USD 0.00012 per GiB-hour, on disk written to (not the provisioned 100 GiB), in every state. Hibernated machines pay for disk only. - A default machine (2 vCPU / 8 GiB) is about EUR 0.22 / USD 0.26 per hour at full memory while it runs, and about EUR 0.13 / USD 0.16 per hour holding 2 GiB with 20 GiB written to disk. - Every account is an organization: shared machines, one credit balance, 50 machines included. - EUR 30 / USD 30 free credits for new accounts, granted when a payment method is added. - Custom: bigger machines, higher quotas, volume pricing, or self-host/BYOC on your own hardware. For companies of any size. Contact us. ## Architecture Custom Rust VMM built on KVM. No Firecracker, no Docker, no external dependencies. Raft consensus for coordination. European hosting by default. ## Contact - Email: contact@boxd.sh - Book a call: https://boxd.run/contact