# caas.sh — Container as a Service

Persistent, secure VMs that deploy like containers. Run coding agents and MCP servers with built-in observability, authentication, and control.

- **Isolation:** every workload runs in its own VM.
- **Continuity:** every workload keeps its own state.
- **Control:** your rules for network access and callers.

## One runtime for agents and the tools they call

### Agent runtimes — a real machine for every agent

Give a coding agent its own machine, files, and network rules. Keep the workspace between steps, pause it, and return to the same state.

- **Use the harness you prefer.** Ready-made environment or your own image.
- **Keep the workspace.** Carry files forward and save snapshots.
- **See the run.** Status, usage, and changes without entering the VM.

The website shows this CLI preview:

```text
$ caas run claude-code
  provisioning isolated VM
✓ sandbox ready
```

### MCP Cloud — your MCP server works locally; put it online

Start with what you already have: a stdio command, a Git repo, or a container image. Give clients a hosted MCP endpoint with authentication, persistence, and a clear view of activity.

## How it works: both sides of the tool call

1. **Agent — start the work.** Runs in a persistent workspace with its own compute and files.
2. **Gateway — check the call.** Authenticate the caller and apply access rules first.
3. **MCP server — run the tool.** Keeps its own state and controlled outbound access.
4. **Your view — know what happened.** Result or failure, caller, and usage in one place.

## Start with one sandbox

Isolated, persistent, and billed only for what it uses. Get started in the [console](https://console.caas.sh/).

## Explore

- [Agent workflows](https://caas.sh/agents.html)
- [MCP Cloud](https://caas.sh/mcp-cloud.html)
- [Sandbox features](https://caas.sh/features.html)
- [Pricing](https://caas.sh/pricing.html)
