ACCESS
No token, no tool call.
The gateway checks every request against a revocable client token and its tool grants before anything reaches your server.
Deploy from a stdio command, a Git repo, or a container image. Clients get an authenticated endpoint with saved state and a full view of activity.
YOUR CODE GETS INTO THE SANDBOX THREE WAYS
MCP CLOUD
An MCP server is one YAML file: where the code comes from, the machine it gets, the hosts it may reach, and which clients may call which tools. caas.sh runs it in its own sandbox behind an authenticated endpoint.
server: search-mcpsource: stdio: npx search-mcpsize: 1 vCPU · 1 GiB · 5 GBstate: persistent: true snapshots: nightly at 02:00idle: stop after 30mtokens:AUTHno token, no tool call - name: laptop-claude tools: [search.query, search.fetch]ACCESSthis client, these tools - name: ci-pipeline tools: [search.query]GRANTSsearch.fetch not granted expires: 30degress: [api.search.example.com]OUTBOUNDeverything else blockedAUTHline 10 · no token, no tool call
ACCESSline 12 · this client, these tools
GRANTSline 14 · search.fetch not granted
OUTBOUNDline 17 · everything else blocked
ACCESS
The gateway checks every request against a revocable client token and its tool grants before anything reaches your server.
STATE
Files and app state persist across calls and restarts, with nightly snapshots you can roll back to.
VISIBILITY
Traces record the tool, caller, timing and result, never the arguments, with a trace ID that reaches your server’s logs.
Bring the command, repo, or image you already have.