Skip to main content

Highflame Forge

Python 3.12+ License: MIT

Run coding agents like Claude Code in isolated, policy-enforced cloud sandboxes.

forge is a CLI client of the hosted Forge control plane. You sign in, launch an agent in an isolated sandbox, and never put cloud-provider credentials on your laptop. Requires Python 3.12+ on macOS or Linux.

Install

forge is a console script. Install it as a tool so the forge binary lands on your PATH (usually ~/.local/bin on Linux):

uv tool install highflame-forge

If the next prompt says command not found, that directory is not on PATH yet:

uv tool update-shell
# then open a new terminal, or: export PATH="$HOME/.local/bin:$PATH"

uv pip install highflame-forge only installs into the active virtualenv. The script then lives at .venv/bin/forge and is invisible until you source .venv/bin/activate, or you run uv run --with highflame-forge forge ….

Alternatively:

pipx install highflame-forge

First run

forge login
forge connect
forge create --harness claude-code
  1. forge login opens a browser and stores credentials for this machine. Account and project are fixed at sign-in; switch project by signing in again with --project NAME.
  2. forge connect authorizes GitHub so private repos clone. Skip it for public repos — forge claude will also prompt the first time it meets a private repo.
  3. forge create --harness claude-code always starts a new sandbox. Run it from a git checkout and that repo is cloned in (current branch, unless you pass --repo / --ref). It prints an id; open a shell with forge shell --id <id>.

Day to day, use forge claude from the checkout instead. It reattaches to the workspace you already have, and launches one if you do not.

cd ~/src/my-repo
forge claude

Arguments after forge claude are passed through to claude. Put -- first for any that Forge would otherwise read as its own.

On a machine with no browser (typically SSH into a dev box):

forge login --headless

Commands

forge --help is the published surface. There is no forge train, forge sweep, forge estimate, or forge gpus.

Account

forge login                 # sign in through your browser
forge login --headless      # print a code to approve from another device
forge login --project NAME  # sign in to this project (name, slug, or id)
forge logout                # discard this profile's stored credentials
forge whoami                # identity, project, and which control plane
forge connect               # GitHub, so private repos work

Workspaces

forge claude                       # Claude Code; reattaches if one is running
forge claude --id ID               # attach to a specific sandbox
forge shell                        # interactive shell (your only sandbox)
forge shell --id ID                # name the sandbox when you have more than one
forge shell --id ID pwd            # one-off remote command
forge create --harness claude-code # always a fresh sandbox
forge list                         # running sandboxes
forge kill SANDBOX_ID              # shut one down (name it; see forge list)
forge workspaces                   # saved filesystems (outlive the sandbox)

create is the explicit verb: you pick the agent. Other harnesses that are wired today:

forge create --harness codex
forge create --harness python --entrypoint agent.py
forge create --harness langgraph

python and langgraph run your agent. The repo comes from your checkout, its dependencies are installed at boot, and inference is governed the same way as every other harness — with no Highflame-specific code in it.

See forge create --help for the full harness list, egress bundles (--policy-bundle), isolation floor (--isolation), and billing flags (--subscription, --byok, --key-free, --direct). Names that are not wired yet fail rather than provision a broken sandbox.

Configuration

The CLI talks HTTPS to the control plane. It does not take cloud-provider credentials. Optional overrides:

# Which stored login to use (also: forge --profile NAME …)
FORGE_PROFILE=default

# Set at login if you are not on the default deployment
FORGE_API_URL=https://api-dev.highflame.dev
FORGE_AUTH_URL=https://studio-dev.highflame.dev

--api-url and --auth-url live on forge login only. Switching deployments is a re-login, so a token minted against one environment is never sent to another.

Development

git clone https://github.com/highflame-ai/highflame-forge.git
cd highflame-forge
uv sync --extra dev

uv run pytest tests/
uv run mypy src/highflame_forge
uv run ruff check src/

License

MIT License — see LICENSE for details.

Metadata

Release files for highflame-forge 0.0.7

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for highflame-forge 0.0.7
File Size Uploaded
highflame_forge-0.0.7.tar.gz 369.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for highflame-forge 0.0.7
File Interpreter ABI Platform
highflame_forge-0.0.7-py3-none-any.whl Python 3 none any Details

Total release size: 775.1 kB

Release files / highflame_forge-0.0.7.tar.gz

Download URL highflame_forge-0.0.7.tar.gz
Size 369.0 kB
Tags Source
SHA-256 checksum
How to use checksums
2e7b85f45d486a399034b07b15bd3cb42b562570f277d67b645dd2b5f683e488
BLAKE2b-256 checksum
How to use checksums
8efd035775822720f3284843661f7e182329d5ef177d8a49975061ee611ea7b5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 18, 2026.

Transparency log

Release files / highflame_forge-0.0.7-py3-none-any.whl

Download URL highflame_forge-0.0.7-py3-none-any.whl
Size 406.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b83e16342ac715e5b34bc2d57d829129dbb9257d1a4a8afd70058cedbe0aae66
BLAKE2b-256 checksum
How to use checksums
a94ebe18b6633c0877d157771b08085a9e76a13ea02e432e9699a76d4580dab9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 18, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.0.7 This release

2 release files

0.0.6

2 release files

0.0.5

2 release files

0.0.4

2 release files

0.0.3

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page