Machines for your customers
If your SaaS runs agents on behalf of your customers (to browse, log in to their tools, fill forms, or operate desktop apps), give each customer their own Burrowbox machine.
#The pattern
- One machine per customer. Create it the first time a customer needs an agent, and store the machine
idandmcpTokennext to the customer in your database. - Scoped tokens. Give that customer's agent only its machine's
mcpToken. It can't reach any other machine or your account. - Their credentials stay in their machine. Put the customer's logins in that machine's vault; agents use them with
browser_loginwithout ever seeing them. - Switch off when idle. Set
ttlMinuteswhen you start a session. When it expires the machine turns off and keeps its state, so the next session picks up where it left off, still signed in.
// Node.js example
const api = (path, init = {}) =>
fetch(`https://burrowbox.dev${path}`, {
...init,
headers: { Authorization: `Bearer ${process.env.BURROWBOX_KEY}`, "Content-Type": "application/json" },
}).then((r) => r.json());
async function machineFor(customer) {
if (!customer.machineId) {
const m = await api("/api/machines", {
method: "POST",
body: JSON.stringify({ name: customer.slug, size: "tiny", ttlMinutes: 30 }),
});
await db.customers.update(customer.id, { machineId: m.id, machineToken: m.mcpToken });
return m;
}
// Wake it up for a new session; it resumes exactly where it left off.
return api(`/api/machines/${customer.machineId}/start`, {
method: "POST",
body: JSON.stringify({ ttlMinutes: 30 }),
});
}
#Showing your customer what the agent did
Pull a screenshot at any time with GET /api/machines/{id}/screenshot.jpg, or stream the live view into your product (see Live view).
#Costs
You pay per machine-minute while running, plus a small rate for the saved snapshot while stopped. A customer who uses their agent for 30 minutes a day on a tiny machine costs about $1.05 a month in running time plus $0.72 for storage.