Overview
Run coding agents in a sandbox with governed access to credentials, network, files, and tools
Stashbase runs coding agents inside a sandbox, either a native OS sandbox or an isolated Docker container, with policy-controlled access to credentials, network destinations, files, dependencies, and MCP tools. Secret values never enter the agent's process environment. The agent receives short-lived placeholders instead. Stashbase exchanges a placeholder for its secret only when the agent makes a supported HTTP(S) request to that secret's approved destination.
Continue in Agents
Learn more about agents.
The Agents guide covers setup, profile configuration, audit logs, supported tools, and the security boundary.