Skip to main content

Airut

Sandboxed Claude Code over email and Slack. Named "Airut" (Finnish: herald/messenger).

Send a message — email or Slack — with instructions, and get results back in the same thread. Starting a new task is as simple as starting a new conversation. Airut handles everything behind the scenes: workspace creation, container isolation, network sandboxing, session persistence, and cleanup.

Self-hosted: your code and conversations never leave your infrastructure.

You → Email/Slack → Airut → Claude Code (container) → PR → Reply → You

Key Features

  • Zero-friction tasking — send a message to start a task. No workspace setup, no session management, no cleanup.
  • Defense-in-depth sandboxing — container isolation, network allowlist via proxy, and credential masking limit blast radius when agents run with full autonomy.
  • Conversation persistence — reply to continue where you left off. Claude Code session context is maintained across messages.
  • Task-to-PR foundation — combined with proper repo configuration (CLAUDE.md, CI tooling, branch protection), enables end-to-end autonomous workflows where agents push PRs for human review.
  • Email and Slack channels — authenticate via DMARC (email) or workspace membership (Slack), with sender authorization per repo.
  • Web dashboard — monitor running tasks, view network activity logs, and configure the server.

Quick Start

Prerequisites

  • Linux (dedicated VM recommended, Debian 13 tested)
  • uv, Git, and Podman (rootless)
  • At least one channel per repository:
    • Email: Dedicated email account with IMAP/SMTP access
    • Slack: Slack workspace with app installation permissions

Install

# Install uv (if not already installed)
curl -LsSf https://astral.sh/uv/install.sh | sh

# Install Airut from PyPI
uv tool install airut

Or install the latest development version from main:

uv tool install airut --from git+https://github.com/airutorg/airut.git

Deploy

# Validate system dependencies
airut check

# Install and start the systemd service
airut install-service

Configure

Open http://localhost:5200 in your browser. Click Configure to open the config editor. Add repositories, set up channels, configure credentials, and adjust resource limits.

You can also edit ~/.config/airut/airut.yaml directly. See the documented example for the full schema.

Update

airut update

How It Works

Each conversation runs in an isolated container with its own git workspace, Claude Code session, and sandboxed network. The recommended workflow has agents push PRs for your review — you review, leave comments, and reply to iterate.

You: "Add user authentication"
    ↓
Agent: works → pushes PR → replies with PR link
    ↓
You: review PR, leave comments
    ↓
You: reply "Address the review comments"
    ↓
Agent: reads comments → fixes → updates PR → replies
    ↓
You: approve and merge

Sandbox Library

The airut.sandbox module is a standalone library for safe containerized execution of headless Claude Code. It can be used independently of the gateway to run Claude Code in isolated containers from any Python application — CI pipelines, automation scripts, custom integrations, or your own agent orchestrator.

Core capabilities:

  • Container lifecycle — two-layer image build, execution, and cleanup via Podman or Docker
  • Network isolation — transparent DNS-spoofing proxy enforcing a domain allowlist, with no HTTP_PROXY env vars or iptables rules needed
  • Secret masking — surrogate credential injection so real secrets never reach the container, with proxy-side replacement on egress
  • Event streaming — append-only log of Claude's streaming JSON output, safe for concurrent reads during execution
  • Outcome classification — typed Outcome enum (success, timeout, prompt-too-long, session-corrupted, container-failed) so callers match on outcomes instead of parsing strings

Quick example:

from airut.sandbox import Sandbox, SandboxConfig, Mount, ContainerEnv, Outcome

sandbox = Sandbox(SandboxConfig())
sandbox.startup()

image = sandbox.ensure_image(dockerfile, context_files)
task = sandbox.create_task(
    execution_context_id="my-run-1",
    execution_context_dir=run_dir,
    image_tag=image,
    mounts=[Mount(host_path=repo, container_path="/workspace")],
    env=ContainerEnv(variables={"ANTHROPIC_API_KEY": key}),
    timeout_seconds=600,
)
result = task.execute("Fix the failing tests")

if result.outcome == Outcome.SUCCESS:
    print(result.response_text)

sandbox.shutdown()

See the sandbox spec for full architecture details and API reference.

Documentation

Full documentation is available on GitHub:

License

MIT License. See LICENSE for details.

Release files for airut 0.26.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for airut 0.26.0
File Size Uploaded
airut-0.26.0.tar.gz 1.7 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for airut 0.26.0
File Interpreter ABI Platform
airut-0.26.0-py3-none-any.whl Python 3 none any Details

Total release size: 2.2 MB

Release files / airut-0.26.0.tar.gz

Download URL airut-0.26.0.tar.gz
Size 1.7 MB
Tags Source
SHA-256 checksum
How to use checksums
e580178442d8865730c01db9cc975e1330dc5d059d1e74ff6ba4bd0ed75c899a
BLAKE2b-256 checksum
How to use checksums
36282ae2fd9c2fb9fb0802c731f80e8dc5af2b04a1cdc027e88afc3daa4a6b33
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release files / airut-0.26.0-py3-none-any.whl

Download URL airut-0.26.0-py3-none-any.whl
Size 547.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
cb998e915681988ecee219c0d167a6a41490852fdedde7b7c97eac6a93621d6c
BLAKE2b-256 checksum
How to use checksums
ab4c984e3196d0d58351a828ed486d364f0cb0c7893cdca266bf30b56a80ee0f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.26.0 This release

2 release files

0.25.8

2 release files

0.25.4

2 release files

0.25.3

2 release files

0.25.1

2 release files

0.25.0

2 release files

0.24.1

2 release files

0.24.0

2 release files

0.23.0

2 release files

0.22.1

2 release files

0.20.2

2 release files

0.20.1

2 release files

0.20.0

2 release files

0.19.0

2 release files

0.18.0

2 release files

0.17.2

2 release files

0.17.1

2 release files

0.17.0

2 release files

0.16.1

2 release files

0.16.0

2 release files

0.15.0

2 release files

0.13.1

2 release files

0.13.0

2 release files

0.12.0

2 release files

0.11.0

2 release files

0.10.0

2 release files

0.9.1

2 release files

0.9.0

2 release files

0.8.3

2 release files

0.8.2

2 release files

0.8.1

2 release files

0.8.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page