Stashbase

Overview

Use the CLI to run sandboxed agents through the Agent Proxy

stashbase agent run launches an agent in a sandbox (native, or Docker) and routes its traffic through a local HTTP(S) Agent Proxy that enforces the profile's network, filesystem, and tool policy. The agent receives placeholders instead of secret values. When it sends a placeholder in an approved request header, Stashbase injects the matching secret only when the request matches that credential's host, method, and path policy. A binding without rules retains the legacy host-only behavior.

The complete Agents guide covers profile configuration, compatibility, audit logs, and the security boundary.

Continue in Agents

On this page