Stashbase

Overview

Run coding agents in a sandbox with governed access to credentials, network, files, and tools

Stashbase runs coding agents inside a sandbox, either a native OS sandbox or an isolated Docker container, with policy-controlled access to credentials, network destinations, files, dependencies, and MCP tools. Secret values never enter the agent's process environment. The agent receives short-lived placeholders instead. Stashbase exchanges a placeholder for its secret only when the agent makes a supported HTTP(S) request to that secret's approved destination.

Continue in Agents

Learn more about agents.

The Agents guide covers setup, profile configuration, audit logs, supported tools, and the security boundary.

On this page