Use the integrated agents
Before you write an agent loop, look at what the sandbox already runs.boat promptdrives five coding agents: Claude Code, Codex, pi, OpenCode and Prime Agent.- It has memory, parallel conversations, streaming events and a model choice for each prompt.
- For most platforms, it replaces the daemon.
- Use your user’s key, not yours. Create the sandbox with
--no-env. Pass the user’s key as a per-sandbox variable:-e ANTHROPIC_API_KEY=…,-e OPENAI_API_KEY=…. Every harness reads it. Nothing of your account is on the sandbox. Keys are per sandbox. So users whose keys must stay apart get their own sandbox (patterns 1 and 3). A sandbox that you pay for can serve many users through conversations (pattern 2). - Use one conversation for each user session.
POST /promptwithnew: truereturns aconversationId. Store it with the session. Send it back asconversationIdwith each later message. Conversations run in parallel on one sandbox, and each one has its own memory. They stay after a stop and resume. So pattern 3 works without changes: resume the sandbox, then prompt the same conversation. - Add an agent and model picker. A selector in your UI maps directly to the
providerandmodelfields ofPOST /prompt. A switch in the middle of a conversation keeps the history. Users can change their choice for each message. - Stream to your UI.
GET /eventswith a cursor gives structured events for prompts, responses and tool calls. Each event has itsconversationId. Filter withconversationto show each user only their own session. - Add a stop button.
POST /interruptwithconversationstops the turn of one user. The other conversations keep running. - Add house rules, tools and MCP servers. The agents read usual config files from the sandbox home:
AGENTS.md,CLAUDE.md, MCP registrations and skills. Put yours in the template once, and every fork starts with them. Put per-user rules in the prompt or in per-user sandboxes. See Customize the harness. - Send attachments.
boat prompt --attachputs the user’s files under~/attachmentson the sandbox. It sends images inline to vision models. From a backend, write the file with the file endpoint, and give its path in the prompt.
Bring your own harness: the daemon pattern
You do not have to use the integrated agents. Your harness can run in your own infrastructure, or you can want full control of the agent loop. Then put a small HTTP daemon in the sandbox and talk to it directly:- Install it. Copy the binary in with
boat scp, or put it in your template. - Keep it alive. Run it as an always-on systemd service. It then survives stop, resume and fork.
- Expose it.
host <port> --privategives it a stable HTTPS URL that a_tokenprotects. Use that token as the credential of the daemon. Store it in your backend. - Drive it from your backend over plain HTTPS. Your harness sends work. The daemon runs it with full access to the machine and streams the results back.
Without a daemon
You can also work without a daemon:
A daemon is useful when you need streaming, concurrency, or less latency than one-shot commands give.