Highflame Forge
Run coding agents like Claude Code in isolated, policy-enforced cloud sandboxes.
forge is a CLI client of the hosted Forge control plane. You sign in, launch
an agent in an isolated sandbox, and never put cloud-provider credentials on
your laptop. Requires Python 3.12+ on macOS or Linux.
Install
forge is a console script. Install it as a tool so the forge binary
lands on your PATH (usually ~/.local/bin on Linux):
uv tool install highflame-forge
If the next prompt says command not found, that directory is not on PATH yet:
uv tool update-shell
# then open a new terminal, or: export PATH="$HOME/.local/bin:$PATH"
uv pip install highflame-forge only installs into the active virtualenv. The
script then lives at .venv/bin/forge and is invisible until you source .venv/bin/activate, or you run uv run --with highflame-forge forge ….
Alternatively:
pipx install highflame-forge
First run
forge login
forge connect
forge create --harness claude-code
forge loginopens a browser and stores credentials for this machine. Account and project are fixed at sign-in; switch project by signing in again with--project NAME.forge connectauthorizes GitHub so private repos clone. Skip it for public repos —forge claudewill also prompt the first time it meets a private repo.forge create --harness claude-codealways starts a new sandbox. Run it from a git checkout and that repo is cloned in (current branch, unless you pass--repo/--ref). It prints an id; open a shell withforge shell --id <id>.
Day to day, use forge claude from the checkout instead. It reattaches to
the workspace you already have, and launches one if you do not.
cd ~/src/my-repo
forge claude
Arguments after forge claude are passed through to claude. Put -- first
for any that Forge would otherwise read as its own.
On a machine with no browser (typically SSH into a dev box):
forge login --headless
Commands
forge --help is the published surface. There is no forge train,
forge sweep, forge estimate, or forge gpus.
Account
forge login # sign in through your browser
forge login --headless # print a code to approve from another device
forge login --project NAME # sign in to this project (name, slug, or id)
forge logout # discard this profile's stored credentials
forge whoami # identity, project, and which control plane
forge connect # GitHub, so private repos work
Workspaces
forge claude # Claude Code; reattaches if one is running
forge claude --id ID # attach to a specific sandbox
forge shell # interactive shell (your only sandbox)
forge shell --id ID # name the sandbox when you have more than one
forge shell --id ID pwd # one-off remote command
forge create --harness claude-code # always a fresh sandbox
forge list # running sandboxes
forge kill SANDBOX_ID # shut one down (name it; see forge list)
forge workspaces # saved filesystems (outlive the sandbox)
create is the explicit verb: you pick the agent. Other harnesses that are
wired today:
forge create --harness codex
forge create --harness python --entrypoint agent.py
forge create --harness langgraph
python and langgraph run your agent. The repo comes from your
checkout, its dependencies are installed at boot, and inference is governed
the same way as every other harness — with no Highflame-specific code in it.
See forge create --help for the full harness list, egress bundles
(--policy-bundle), isolation floor (--isolation), and billing flags
(--subscription, --byok, --key-free, --direct). Names that are not
wired yet fail rather than provision a broken sandbox.
Configuration
The CLI talks HTTPS to the control plane. It does not take cloud-provider credentials. Optional overrides:
# Which stored login to use (also: forge --profile NAME …)
FORGE_PROFILE=default
# Set at login if you are not on the default deployment
FORGE_API_URL=https://api-dev.highflame.dev
FORGE_AUTH_URL=https://studio-dev.highflame.dev
--api-url and --auth-url live on forge login only. Switching
deployments is a re-login, so a token minted against one environment is never
sent to another.
Development
git clone https://github.com/highflame-ai/highflame-forge.git
cd highflame-forge
uv sync --extra dev
uv run pytest tests/
uv run mypy src/highflame_forge
uv run ruff check src/
License
MIT License — see LICENSE for details.
Metadata
Release files for highflame-forge 0.0.7
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| highflame_forge-0.0.7.tar.gz | 369.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| highflame_forge-0.0.7-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 775.1 kB
Release files / highflame_forge-0.0.7.tar.gz
| Download URL | highflame_forge-0.0.7.tar.gz |
|---|---|
| Size | 369.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
2e7b85f45d486a399034b07b15bd3cb42b562570f277d67b645dd2b5f683e488
|
|
BLAKE2b-256 checksum How to use checksums |
8efd035775822720f3284843661f7e182329d5ef177d8a49975061ee611ea7b5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 18, 2026.
Transparency logRelease files / highflame_forge-0.0.7-py3-none-any.whl
| Download URL | highflame_forge-0.0.7-py3-none-any.whl |
|---|---|
| Size | 406.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b83e16342ac715e5b34bc2d57d829129dbb9257d1a4a8afd70058cedbe0aae66
|
|
BLAKE2b-256 checksum How to use checksums |
a94ebe18b6633c0877d157771b08085a9e76a13ea02e432e9699a76d4580dab9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 18, 2026.
Transparency log