Skip to main content

MCP server exposing a hosted boxxkite control-plane (sandbox lifecycle, exec, files) as native tools for MCP-compatible clients (Claude Code, Claude Desktop, Codex, Cursor, etc.).

Project description

boxxkite-mcp

PyPI

An MCP server over a hosted boxxkite control-plane — lets any MCP-compatible client (Claude Code, Claude Desktop, Codex, Cursor, etc.) attach a real sandboxed code-execution backend as a native tool source, zero custom integration code.

Prefer no local install? A control-plane deployment built from this repo also exposes a remote Streamable HTTP MCP endpoint directly at https://your-control-plane.example.com/mcp/ — add that URL to your MCP client's config instead of installing this package. See docs/HOSTED-MCP-DESIGN.md. Use this package when you want the MCP server process running on your own machine instead.

Install

pip install boxxkite-mcp
# or, to run it as a standalone MCP server without a project venv:
pipx install boxxkite-mcp

Configuration

Two required environment variables:

Variable Meaning
BOXXKITE_BASE_URL Base URL of the boxxkite control-plane
BOXXKITE_API_KEY A bxk_live_... API key for your account

Run

BOXXKITE_BASE_URL=https://your-control-plane.example.com \
BOXXKITE_API_KEY=bxk_live_... \
boxxkite-mcp

Speaks MCP over stdio — point an MCP client's config at the boxxkite-mcp command.

Tools

Sandbox lifecycle and exec/file tools — create_sandbox, destroy_sandbox, get_sandbox, list_sandboxes, exec, file_create, view, str_replace, ls, glob, grep — every per-sandbox tool takes session_id as a parameter, so the calling agent owns the full lifecycle within one conversation.

Custom image tools (build a sandbox image with extra packages baked in, then pass its id as create_sandbox's image_id) — create_sandbox_image, get_sandbox_image, list_sandbox_images, delete_sandbox_image.

Independent storage volume tools (create persistent storage mountable into one or more sandboxes via create_sandbox's volume_mounts) — create_sandbox_volume, get_sandbox_volume, list_sandbox_volumes, delete_sandbox_volume.

Outbound-MCP connection tools (grant a sandbox network egress to a curated MCP catalog entry via create_sandbox's mcp_connection_names — see docs/OUTBOUND-MCP-DESIGN.md; there is no MCP-proxy transport yet, so this only widens network reachability, it doesn't yet let the sandbox speak MCP protocol to the destination) — create_mcp_connection, list_mcp_connections, delete_mcp_connection.

Language-server (LSP) tools for code intelligence inside a sandbox — start a language server, open a file into it, request completions at a position, then stop it — lsp_start, lsp_open, lsp_completion, lsp_stop. Like the other per-sandbox tools, each takes session_id.

That's 26 tools in total.

Security

exec runs arbitrary shell commands with no client-side allowlist — the isolation boundary is the sandbox itself (see the root repo's SECURITY.md), not these MCP tools' argument validation. exec/view results are returned to the calling LLM as plain, unsanitized text — treat sandbox output as untrusted input, the same as a web-fetch or file-read tool's result.

Related tools

Moving an in-progress local Claude Code/Codex CLI/opencode session (full conversation history) into a fresh boxxkite sandbox is not something this MCP server can do as a tool call: a handoff adapter needs to read local, on-disk CLI session state (e.g. Claude Code's ~/.claude/projects/... files) on the user's own machine, while an MCP tool call runs wherever the MCP client invokes it, and boxxkite-mcp itself is a thin proxy to the hosted control-plane with no access to the calling agent's local filesystem. That's handled instead by a separate, local-only companion CLI, boxxkite-handoff — see ../docs/handoff-adapters.md and ../handoff-cli/README.md for how it works. Not yet published to PyPI.

Development

pip install -e ".[dev]"
pytest tests/

See the root README for what boxxkite is and the full self-hosting story.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

boxxkite_mcp-0.2.3.tar.gz (17.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

boxxkite_mcp-0.2.3-py3-none-any.whl (11.7 kB view details)

Uploaded Python 3

File details

Details for the file boxxkite_mcp-0.2.3.tar.gz.

File metadata

  • Download URL: boxxkite_mcp-0.2.3.tar.gz
  • Upload date:
  • Size: 17.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.11.19 {"installer":{"name":"uv","version":"0.11.19","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

File hashes

Hashes for boxxkite_mcp-0.2.3.tar.gz
Algorithm Hash digest
SHA256 b75645d8e749d65fdb30323a790e350dfe55b508236026aebbaf74a1ef235845
MD5 91f95a41a7a5a079d8ace4805823e46d
BLAKE2b-256 67f5dc44f581c58776c0a356e821e1bd516ce13eba03517b082673ee591a40ff

See more details on using hashes here.

File details

Details for the file boxxkite_mcp-0.2.3-py3-none-any.whl.

File metadata

  • Download URL: boxxkite_mcp-0.2.3-py3-none-any.whl
  • Upload date:
  • Size: 11.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.11.19 {"installer":{"name":"uv","version":"0.11.19","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

File hashes

Hashes for boxxkite_mcp-0.2.3-py3-none-any.whl
Algorithm Hash digest
SHA256 5c07e1cc11e9dcb05046107075a3f388e08a6c183e3b9d25a5a09a105518b89e
MD5 8d4eeeca1f3bfa8f39c462d6de50faa7
BLAKE2b-256 3bd2e8dab96db248e708576627e00ac55400e2d679782da7461eb0633b7e0bd5

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page