# Agents — caas.sh

**Multistep workflows. One sandbox per step.**

Powered by [Constal](https://constal.ai/).

Every step of an agent workflow runs in its own isolated sandbox. Files carry forward, progress is checkpointed, and you can inspect any run.

Example workflow — fix failing tests:

1. Inspect repository — complete
2. Edit code — complete
3. Run test suite — running
4. Save checkpoint — next

## Workflows: close your laptop, wake up to a pull request

A workflow is one YAML file. Each step boots a fresh sandbox, gets only the files you declare, and checkpoints the moment it finishes. The run carries on without you.

```yaml
workflow: fix-failing-tests
image: registry.caas.sh/your-org/node-agent:24
egress: [github.com, api.github.com, registry.npmjs.org]
inputs:
  repo: github.com/your-org/app

steps:
  - id: checkout
    name: Inspect repository
    run:
      - git clone ${{ inputs.repo }} .
      - npm ci
      - npm test -- --json > report.json || true
    outputs: [.]

  - id: fix
    name: Edit code
    agent: claude-code
    task: Make the failing tests in report.json pass.
    inputs: [checkout]
    outputs: [src/, tests/]

  # A failing exit stops the run. Red tests never become a PR.
  - id: test
    name: Run test suite
    run: npm test
    inputs: [checkout, fix]

  - id: pr
    name: Open pull request
    run: gh pr create --fill
    inputs: [checkout, fix]
    secrets: [GITHUB_TOKEN]
```

One completed run of fix-failing-tests:

1. **Inspect repository** — 1m 52s · clone, install, record failing tests · checkpoint saved · hands off `.` (repo + report.json)
2. **Edit code** — 6m 41s · claude-code, 3 files changed · checkpoint saved · hands off `src/` and `tests/`
3. **Run test suite** — 2m 58s · npm test, exit 0 · checkpoint saved
4. **Open pull request** — 0m 29s · GITHUB_TOKEN attached at egress · checkpoint saved · pull request opened

4 sandboxes · 12 minutes · about $0.04 ([how it adds up](https://caas.sh/pricing.html#workflow-example)).

- **Isolation — nothing leaks between steps.** Each step boots a clean sandbox. Only the files it declares cross over, matched by content hash. No leftover state, no dependency drift.
- **Recovery — a 2 a.m. crash costs one step.** Every finished step is a checkpoint. If step three fails, the run resumes at step three and you pay only for what reruns. Checkpoints and resumes are free.
- **Secrets — your agent never holds your keys.** Tokens are attached after traffic leaves the sandbox, so code inside can’t print, log or leak a token it never sees.

[Run this workflow](https://console.caas.sh/)

## Controls: decide what an agent can reach

- **MCP Gateway.** Connect steps to MCP servers through an authenticated endpoint.
- **Model Gateway.** Manage keys and rules for the models an agent uses.
- **Network Policy.** Limit outbound destinations and keep credentials out of the guest.
- **Operations.** Status, usage, and checkpoints to resume a run.

## Run your first workflow

Persistent sandboxes, network controls, and usage-based pricing. Get started in the [console](https://console.caas.sh/).

[Features](https://caas.sh/features.html) · [Pricing](https://caas.sh/pricing.html)
