forkd MCP server
An MCP server that exposes forkd microVM sandboxes as tools to any MCP-aware client — Claude Desktop, Claude Code, Cursor, Cline, etc.
What it lets the agent do
Once registered, the agent can:
| Tool | What |
|---|---|
list_snapshots |
See available parent templates |
create_snapshot |
Build a new snapshot from kernel + rootfs (v0.2.0+) |
spawn_sandboxes |
Fork N children from a template. Accepts prewarm: bool (v0.2.0+) |
branch_sandbox |
Branch a running sandbox into a new tag (v0.2.0+). Accepts diff: bool for v0.3's 6-15× source-pause reduction on typical agent workloads (143× ceiling). |
list_sandboxes |
List live sandboxes |
get_sandbox |
Inspect one sandbox by id |
exec_command |
Run a shell command in a sandbox |
eval_code |
Evaluate Python against the warmed PID-1 |
wait_for_text |
Poll a file in the guest for a marker string (v0.2.0+) |
ping_sandbox |
Health-check a sandbox |
kill_sandbox |
Terminate one sandbox |
The killer one is branch_sandbox: pause a running agent
sandbox, snapshot, fan out N children that inherit the source's
exact state and diverge under copy-on-write. Modal does this as
their proprietary moat; forkd is the open-source equivalent. See
bench/pause-window/RESULTS-v0.3.md
for the measured numbers.
Each tool maps 1:1 onto a forkd-controller REST endpoint
(docs/API.md). The server is stateless; the
controller owns sandbox lifecycle.
Install
pip install forkd-mcp
# or from source:
pip install -e .
Requires the forkd-controller daemon running locally
(README) and reachable
on http://127.0.0.1:8889 by default.
Configure
Environment variables:
| Var | Default | Purpose |
|---|---|---|
FORKD_URL |
http://127.0.0.1:8889 |
Controller base URL |
FORKD_TOKEN |
unset | Bearer token, required when daemon is started with --token-file |
FORKD_HTTP_TIMEOUT |
60 |
Per-request timeout (seconds) |
Register with Claude Desktop
Add to your claude_desktop_config.json (macOS:
~/Library/Application Support/Claude/claude_desktop_config.json):
{
"mcpServers": {
"forkd": {
"command": "forkd-mcp",
"env": {
"FORKD_URL": "http://127.0.0.1:8889",
"FORKD_TOKEN": "<contents-of-/etc/forkd/token>"
}
}
}
}
Restart Claude Desktop. The eight tools above will appear in the "hammer" menu.
Register with Claude Code
claude mcp add forkd --env FORKD_URL=http://127.0.0.1:8889 \
--env FORKD_TOKEN=$(sudo cat /etc/forkd/token) \
-- forkd-mcp
Verify with claude mcp list.
Register with Cursor
Add to ~/.cursor/mcp.json (or per-workspace .cursor/mcp.json):
{
"mcpServers": {
"forkd": {
"command": "forkd-mcp",
"env": {
"FORKD_URL": "http://127.0.0.1:8889",
"FORKD_TOKEN": "<contents-of-/etc/forkd/token>"
}
}
}
}
Restart Cursor (or hit "Refresh" on the MCP settings page).
Register with Cline
In the Cline extension settings, open "MCP Servers" → "Edit MCP Settings" and add:
{
"mcpServers": {
"forkd": {
"command": "forkd-mcp",
"env": {
"FORKD_URL": "http://127.0.0.1:8889",
"FORKD_TOKEN": "<contents-of-/etc/forkd/token>"
},
"disabled": false,
"autoApprove": ["list_snapshots", "list_sandboxes", "get_sandbox", "ping_sandbox"]
}
}
}
The autoApprove list is read-only tools that don't need
per-call confirmation. Mutating tools (spawn_sandboxes,
branch_sandbox, exec_command, kill_sandbox,
create_snapshot) always prompt by default.
Smoke test
# In one shell, start the controller:
sudo systemctl start forkd-controller
# In another, run the MCP server stand-alone (stdio transport):
FORKD_TOKEN=$(sudo cat /etc/forkd/token) forkd-mcp
# The server will block on stdin waiting for an MCP client.
To exercise the server without an MCP client, point any MCP debugger
at it (e.g. npx @modelcontextprotocol/inspector forkd-mcp).
What this is and isn't
Is — a thin wrapper that lets MCP clients drive forkd. The agent plans, the MCP server forwards, the controller actually forks VMs.
Isn't — a sandbox itself. forkd-controller must be running, and
the host needs KVM + a registered snapshot. See
recipes/ for ready-to-fork parent images.
Metadata
Release files for forkd-mcp 0.2.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| forkd_mcp-0.2.1.tar.gz | 8.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| forkd_mcp-0.2.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 16.3 kB
Release files / forkd_mcp-0.2.1.tar.gz
| Download URL | forkd_mcp-0.2.1.tar.gz |
|---|---|
| Size | 8.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
c79cb2bad44733adfe97bad1b5b2a91f8454bda19d4f92b22dbfed260fb79961
|
|
BLAKE2b-256 checksum How to use checksums |
35d9f240d68468d8c434c2c7bb5396f9f4b5df98da1d08312f75cf7656b5f2b2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 31, 2026.
Transparency logRelease files / forkd_mcp-0.2.1-py3-none-any.whl
| Download URL | forkd_mcp-0.2.1-py3-none-any.whl |
|---|---|
| Size | 8.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
4688ec7a78748c2060c95938a39d59a1351525aa54ad159ae0ba890c75f79539
|
|
BLAKE2b-256 checksum How to use checksums |
23c83b78a2e0be3388b68d30f6e1aca210f01d31fe7bed0a9bc04e5cb3811deb
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 31, 2026.
Transparency log