Skip to main content

terok-executor

terok-executor

PyPI License: Apache-2.0 REUSE status Quality Gate Status

One command to run an AI coding agent inside a hardened, rootless Podman container.

terok-executor builds the container, launches the agent against the directory you point it at, and keeps real credentials on the host. Use it on its own as a CLI, or import its AgentRunner from Python when you want library-grade control.

terok ecosystem — terok-executor sits between project orchestration and the hardened runtime

Quick start

pip install terok-executor
terok-executor run claude ~/my-workspace -p "Fix the bug"

The first run interactively offers any missing prerequisites — sandbox services, container images, agent credentials. Mandatory items (services, images) block the launch if declined; optional ones (SSH key, auth) print the consequence and proceed.

Individual steps would be:

terok-executor setup                               # install sandbox services + build base images
terok-executor auth claude                         # authenticate (OAuth or API key)
terok-executor run claude <dir> -p "Fix the bug"   # run the agent with an initial prompt

Use as a library

from terok_executor import AgentRunner

runner = AgentRunner()
runner.run_headless(
    agent="claude",
    repo=".",
    prompt="Fix the failing test in test_auth.py",
    max_turns=25,
)

AgentRunner exposes four launch methods — run_headless, run_interactive, run_web, run_tool — all with the same hardening guarantees.

Supported agents

Agent Auth Description
Claude Code OAuth*, API key Anthropic Claude Code
Codex OAuth*, API key OpenAI Codex CLI
Vibe API key Mistral Vibe
Copilot — GitHub Copilot (no vault route yet)
OpenCode — (uses provider keys) Harness that drives any OpenAI-compatible provider — curated configs for Helmholtz Blablador, KISSKI AcademicCloud, and OpenRouter (each authenticated with its own API key)
Pi — (uses provider keys) Multi-provider harness; routes through the phantom tokens of co-installed providers
gh OAuth, API key GitHub CLI
glab API key GitLab CLI
SonarCloud API key SonarCloud scanner
CodeRabbit API key CodeRabbit (sidecar tool)

* Claude and Codex OAuth are experimental.

terok-executor agents list lists the live roster (add --all to include tools and harness-driven providers).

Where it sits in the stack

terok-executor is the per-task layer. Above it, terok composes many concurrent runs across many projects. Below it, terok-executor delegates the host-side security boundary (terok-sandbox): the credential vault, the git gate, the egress firewall hooks, the per-container supervisor lifecycle (OCI createRuntime/poststop hooks).

Commands

Command Description
run Launch an agent (headless, interactive, or web)
setup Bootstrap sandbox services + container images
uninstall Remove sandbox services + container images
auth Authenticate a provider
agents Inspect the agent roster (list) and set the build-time default selection (set)
build Build base + agent images explicitly
run-tool Run a sidecar tool (CodeRabbit)
list List containers
start Start a stopped container
stop Stop a container (kept for a later start)
rm Remove a container and its host-side state
show-config Print the effective SandboxConfig as YAML (diffable across orchestrators)
vault Vault management (status, unlock, lock, list, passphrase, routes, clean)
sandbox Full terok-sandbox command tree (shield, vault, ssh, doctor, …)

Config override

Two top-level flags (precede the subcommand, like docker --config):

  • --config PATH — read this config.yml instead of the layered system/user paths (sets TEROK_CONFIG_FILE for the invocation).
  • --raw — ignore any config.yml; use sandbox/executor dataclass defaults only.

Higher-layer orchestrators (such as terok) typically construct a SandboxConfig from their own resolution chain and pass it into the executor as a library; the public expectation is that, for the fields they own in config.yml, the resulting sub-environment matches what standalone terok-executor would produce against the same file. Use show-config on both sides to verify.

Development

See the Developer Guide.

License

Apache-2.0

Metadata

Release files for terok-executor 0.5.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for terok-executor 0.5.0
File Size Uploaded
terok_executor-0.5.0.tar.gz 635.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for terok-executor 0.5.0
File Interpreter ABI Platform
terok_executor-0.5.0-py3-none-any.whl Python 3 none any Details

Total release size: 957.9 kB

Release files / terok_executor-0.5.0.tar.gz

Download URL terok_executor-0.5.0.tar.gz
Size 635.8 kB
Tags Source
SHA-256 checksum
How to use checksums
bc4a4bc76a59fb7b0daf58a6fc5dacee96f2fb5a47b52476c7ed2f4b83575ec9
BLAKE2b-256 checksum
How to use checksums
3f203026a55692a8823ba036f750eef6b963dc79f719c0bc560b8cd3bf617a40
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.

Transparency log

Release files / terok_executor-0.5.0-py3-none-any.whl

Download URL terok_executor-0.5.0-py3-none-any.whl
Size 322.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
1cc9241a5b8b318c436827f3418e2a37c6a1fdf1b467a5a18aaf13e3a6669bb3
BLAKE2b-256 checksum
How to use checksums
cf5063b6be0a6691e91d62004e1c54b30d2b80466b8ed49960ab4c919c3ff9aa
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.5.0 This release

2 release files

0.4.0

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page