boxxkite-mcp
An MCP server over a hosted boxxkite control-plane — lets any MCP-compatible client (Claude Code, Claude Desktop, Codex, Cursor, etc.) attach a real sandboxed code-execution backend as a native tool source, zero custom integration code.
Prefer no local install? A control-plane deployment built from this repo also exposes a remote Streamable HTTP MCP endpoint directly at
https://your-control-plane.example.com/mcp/— add that URL to your MCP client's config instead of installing this package. Seedocs/HOSTED-MCP-DESIGN.md. Use this package when you want the MCP server process running on your own machine instead.
Install
pip install boxxkite-mcp
# or, to run it as a standalone MCP server without a project venv:
pipx install boxxkite-mcp
Configuration
Two required environment variables:
| Variable | Meaning |
|---|---|
BOXXKITE_BASE_URL |
Base URL of the boxxkite control-plane |
BOXXKITE_API_KEY |
A bxk_live_... API key for your account |
Run
BOXXKITE_BASE_URL=https://your-control-plane.example.com \
BOXXKITE_API_KEY=bxk_live_... \
boxxkite-mcp
Speaks MCP over stdio — point an MCP client's config at the boxxkite-mcp command.
Tools
Sandbox lifecycle and exec/file tools — create_sandbox, destroy_sandbox,
get_sandbox, list_sandboxes, exec, file_create, view, str_replace,
ls, glob, grep — every per-sandbox tool takes session_id as a
parameter, so the calling agent owns the full lifecycle within one
conversation.
Custom image tools (build a sandbox image with extra packages baked in,
then pass its id as create_sandbox's image_id) — create_sandbox_image,
get_sandbox_image, list_sandbox_images, delete_sandbox_image.
Independent storage volume tools (create persistent storage mountable into
one or more sandboxes via create_sandbox's volume_mounts) —
create_sandbox_volume, get_sandbox_volume, list_sandbox_volumes,
delete_sandbox_volume.
Outbound-MCP connection tools (grant a sandbox network egress to a curated
MCP catalog entry via create_sandbox's mcp_connection_names — see
docs/OUTBOUND-MCP-DESIGN.md;
there is no MCP-proxy transport yet, so this only widens network reachability,
it doesn't yet let the sandbox speak MCP protocol to the destination) —
create_mcp_connection, list_mcp_connections, delete_mcp_connection.
Language-server (LSP) tools for code intelligence inside a sandbox — start a
language server, open a file into it, request completions at a position, then
stop it — lsp_start, lsp_open, lsp_completion, lsp_stop. Like the other
per-sandbox tools, each takes session_id.
MemoryBase tools — durable, account-scoped memory that survives past any one
sandbox or conversation (see
the developer guide for the
full model: opt-in, self-hosted retrieval by default, no third-party memory
API) — remember, recall, ingest_memory, memory_profile,
forget_memory. The server's MCP instructions steer a connecting agent to
call recall/memory_profile early in a task and remember when it learns
something durable, but nothing here changes what the account's own memory
retrieval settings do server-side.
That's 31 tools in total.
Security
exec runs arbitrary shell commands with no client-side allowlist — the
isolation boundary is the sandbox itself (see the root repo's SECURITY.md),
not these MCP tools' argument validation. exec/view results are returned
to the calling LLM as plain, unsanitized text — treat sandbox output as
untrusted input, the same as a web-fetch or file-read tool's result.
Related tools
Moving an in-progress local Claude Code/Codex CLI/opencode session (full
conversation history) into a fresh boxxkite sandbox is not something
this MCP server can do as a tool call: a handoff adapter needs to read
local, on-disk CLI session state (e.g. Claude Code's
~/.claude/projects/... files) on the user's own machine, while an MCP
tool call runs wherever the MCP client invokes it, and boxxkite-mcp itself
is a thin proxy to the hosted control-plane with no access to the calling
agent's local filesystem. That's handled instead by a local-only command in the main CLI,
boxxkite handoff <tool> — see
../docs/handoff-adapters.md for how it works.
Development
pip install -e ".[dev]"
pytest tests/
See the root README for what boxxkite is and the full self-hosting story.
Questions, bug reports, or need a usage-limit bump? Join the Discord.
Metadata
Release files for boxxkite-mcp 0.8.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| boxxkite_mcp-0.8.0.tar.gz | 20.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| boxxkite_mcp-0.8.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 33.9 kB
Release files / boxxkite_mcp-0.8.0.tar.gz
| Download URL | boxxkite_mcp-0.8.0.tar.gz |
|---|---|
| Size | 20.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
83c01e7b41840d8204e96ed27f09b6aec14d8f8a0bf47360b6a3e7a363a4dd55
|
|
BLAKE2b-256 checksum How to use checksums |
cba98572d4272c664859a211eab8c268bd580ac266852d1e46e076918158a492
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|
Release files / boxxkite_mcp-0.8.0-py3-none-any.whl
| Download URL | boxxkite_mcp-0.8.0-py3-none-any.whl |
|---|---|
| Size | 13.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
17b96ac82209616640f33ea33a4f57f17e4b320fe419c4c7d4a5b532e0d729c4
|
|
BLAKE2b-256 checksum How to use checksums |
9f13c9908212ba7812bfae0fc2a746d526f47636e6de987bc6f09fdfe4e7649e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|