cpuos

Integration · Protocol

MCP (Model Context Protocol) with cpuos sandboxes

Expose cpuos sandboxes as MCP tools so Claude, Cursor and any MCP client can run commands and files in an isolated microVM.

SDK
@cpuos/sdk · pip install cpuos
Model endpoint
https://gpuos.si/v1 or any OpenAI-compatible
Status
Early access

Why sandbox MCP tools

Many MCP servers that run code or shell commands execute them on your own machine, with your files, your SSH keys and your network. A sandbox-backed MCP server gives the assistant a real Linux machine to work in, and nothing on your laptop is in reach.

cpuos provides an MCP server to early-access teams. The example below builds a minimal one with the official TypeScript MCP SDK, so you can see exactly which tools the client gets and adapt them.

A minimal MCP server

Install
npm install @modelcontextprotocol/sdk zod @cpuos/sdk
server.ts
import { McpServer } from "@modelcontextprotocol/sdk/server/mcp.js"import { StdioServerTransport } from "@modelcontextprotocol/sdk/server/stdio.js"import { Sandbox } from "@cpuos/sdk"import { z } from "zod"const server = new McpServer({ name: "cpuos-sandbox", version: "0.1.0" })let current: Sandbox | undefinedconst sandbox = async () =>  (current ??= await Sandbox.create({ template: "devbox", timeout: "1h" }))server.registerTool(  "run_command",  {    description: "Run a shell command in an isolated Linux sandbox.",    inputSchema: { command: z.string() },  },  async ({ command }) => {    const run = await (await sandbox()).exec(command, { timeout: "5m" })    const text = [      "exit_code=" + run.exitCode,      run.stdout.slice(-8000),      run.stderr.slice(-4000),    ].join("\n")    return { content: [{ type: "text", text }] }  })server.registerTool(  "write_file",  {    description: "Write a text file in the sandbox.",    inputSchema: { path: z.string(), content: z.string() },  },  async ({ path, content }) => {    await (await sandbox()).files.write(path, content)    return { content: [{ type: "text", text: "Wrote " + path }] }  })server.registerTool(  "preview_url",  {    description: "Public HTTPS URL for a port opened in the sandbox.",    inputSchema: { port: z.number().int() },  },  async ({ port }) => ({    content: [{ type: "text", text: (await sandbox()).url(port) }],  }))await server.connect(new StdioServerTransport())

cpuos is in early access: @cpuos/sdk (npm) and cpuos (PyPI) ship to early-access teams first, and read the API key from CPUOS_API_KEY. The calls on this page show the current API shape.

Connect a client

Claude Desktop, Cursor and most MCP clients read a JSON file with an mcpServers map. Build the server, then point the client at it and pass the cpuos key in its environment.

MCP client config
{  "mcpServers": {    "cpuos": {      "command": "node",      "args": ["/path/to/server.js"],      "env": { "CPUOS_API_KEY": "<your cpuos key>" }    }  }}

With a local model in an MCP-capable assistant such as Continue, both halves stay under your control: the model on your GPUs through gpuOS, the tools in cpuos sandboxes.

Official documentation: modelcontextprotocol.io

Questions

Which MCP clients work?
Any client that supports stdio MCP servers, including Claude Desktop, Cursor, Continue and VS Code. The server only needs Node.js and network access to cpuos.
Does the sandbox see my local files?
No. It only sees what the assistant writes into it through the tools. That is the point.
What happens to the sandbox when the client closes?
In this example it runs until its timeout. Add a tool or a shutdown hook that calls pause to keep the state, or let the timeout end it.

Related

Run MCP (Model Context Protocol) tool calls in a sandbox

cpuos is in early access: a Firecracker microVM per task, hosted in the EU or on your servers, billed per second and free while paused.

gpuOS · where models think

Need the model too? Run it on gpuOS

gpuOS serves open models on your own GPUs behind one OpenAI-compatible API. The model reasons on gpuOS, the agent acts in a cpuOS sandbox.