Computers for AI agents

A computer for every agent. Yours, and your customers'.

Burrowbox gives agents persistent little Linux machines: a desktop, a browser that stays signed in, a credential vault and an MCP endpoint. Run one for your own agent, or provision one for every customer of your SaaS. Turn it off, and it comes back exactly as it was.

No card needed · Billed by the minute · Stop any time

Two ways in

One burrow, or a whole warren.

The same machines power a single agent or every customer of your product.

For agent builders

A computer for your agent.

Give your agent a real desktop and browser that it keeps from one day to the next.

  • Create a machine in about a second
  • Connect Claude Code or any MCP client with one command
  • Watch it work live, and take over whenever you like
  • Pay by the minute; turn it off and it keeps everything
Start free

What's inside

Everything an agent needs to get real work done.

Each machine is a full, private Linux computer, small enough to run dozens at once.

A real desktop

A quiet little Linux desktop. Agents see it through screenshots and accessibility trees, then click, type and scroll through the same MCP tools.

A browser that stays signed in

Each machine has its own persistent browser profile. Cookies, logins and tabs survive restarts, so your agent doesn't start from zero every morning.

Credentials it never sees

Store logins and 2FA secrets in an encrypted vault. The agent asks the machine to log in, and the password never reaches the model.

Install anything

apt packages, .deb files, AppImages, Flatpaks or a shell script. Whatever the agent installs is still there next time.

Watch live, or take over

Stream the whole desktop, a single app window, or just the browser in real time. Jump in with your own mouse and keyboard whenever you want.

On when you need it

Keep a machine always on, give it 30 minutes, or let it destroy itself when the job is done. You only pay while it runs.

How it works

From zero to a working agent computer in a minute.

  1. 1

    Create a machine

    Pick a size and how long it should stay on. It boots in about a second.

  2. 2

    Connect your agent

    Every machine has its own MCP endpoint and token. Paste one command into Claude Code or any MCP client.

  3. 3

    Let it work, and watch

    Your agent browses, installs and operates apps. You follow along live from any browser.

Terminal
# connect Claude Code to one of your machines
claude mcp add --transport http research-bot \
  https://burrowbox.dev/api/machines/a1b2c3/mcp \
  --header "Authorization: Bearer tmm_…"

# …or let the agent manage machines itself
claude mcp add --transport http burrowbox \
  https://burrowbox.dev/mcp \
  --header "Authorization: Bearer tmk_…"
browser_navigatebrowser_loginapps_installapps_launch screenshotclicktype_textget_app_stateshell_runvault_type_secret +30 more

Persistence

Off doesn't mean gone.

Stop a machine at 6pm and start it at 9am. The same windows are open, the same tabs are loaded, and it's still signed in.

Working

Terminal open, three browser tabs, signed in to your tools, an app installed.

Turned off

Its whole disk is snapshotted: files, installed apps, the vault and every browser cookie, plus which windows and tabs were open.

Back on

It restores in seconds. Windows reopen in place, tabs reload, and you're still logged in.

Pricing

Pay by the minute. Only while it runs.

Prepaid credit, no subscription. New accounts start with free credit.

Stopped machines keep their disk for a small hourly fee. When your credit runs out, machines stop and keep their state.

FAQ

Questions, answered.

What exactly is a machine?

A small, isolated Linux computer running in a container: a lightweight desktop, a browser, a credential vault, and a daemon that exposes everything over MCP. It has its own disk that persists until you destroy the machine.

Can I give each of my customers their own machine?

Yes, that's what platforms use Burrowbox for. Create machines through the API with your key (one per customer, or per task), give each customer's agent the token scoped to its machine, and set a schedule so idle machines turn off and keep their state. Usage is metered per machine.

Which agents can use it?

Anything that speaks the Model Context Protocol over HTTP, including Claude Code, Claude Desktop, and custom agents built on an MCP client. Each machine has its own endpoint and a token scoped to that machine only.

How do stored credentials stay safe?

They're encrypted on the machine with a key held by the platform, not on the machine's disk. Agents fill login forms with browser_login or vault_type_secret, which inject the secret without ever returning it to the model.

What happens when I turn a machine off?

Its entire filesystem is snapshotted (files, installed apps, the vault and browser cookies), along with the list of open windows and tabs. On the next start the snapshot is restored and your windows and tabs reopen where they were. While a machine runs, a save point is also taken every 30 minutes.

What if I run out of credit?

Running machines are stopped, and their state is kept. Top up and start them again. Nothing is deleted unless you choose to destroy a machine.

Can I watch or take control?

Yes. Open a machine to stream the full desktop, a single app window, or just the browser in real time, and use your own keyboard and mouse at any point.

Give every agent a home.

For your own agent, or for every customer you serve. Running in under a minute.