Burrowbox

io.github.burrowboxv1.0.0更新于 Oct 4, 2026

Persistent Linux computers for AI agents: desktop, signed-in browser, vault, apps and shell.

已验证Streamable HTTP可网页运行Developer ToolsCloud & InfrastructureSecurity & Monitoring

概览

AI 生成的概览

为助手提供一台持久运行的 Linux 计算机,含桌面、保持登录的浏览器、凭据保险库、应用和 shell,可通过 MCP 访问。

功能
Burrowbox 为 AI 代理提供持久运行的 Linux 计算机,每台都有桌面、保持登录状态的浏览器、凭据保险库以及自己的 MCP 端点。平台端点和每台机器的端点提供连接信息,机器可以创建、列出、启动、停止、调整规格、定时和销毁,并支持截图、应用和窗口。保险库保存登录信息,代理可以使用但看不到内容;自动化可在机器内运行定时任务和 webhook。
适用场景
当助手需要一台真实、有状态的计算机而不是无状态的工具调用时适用:保持浏览器会话登录、运行 shell 命令和桌面应用,或跨会话保存凭据。也适合把预热池中预配置好的机器直接交付给客户的产品。
运行要求
通过 Streamable HTTP 连接 burrowbox.dev 的远程端点。需要 Authorization 请求头,值为 Account 到 API keys 中获取的 Burrowbox API 密钥(tmk_...);机器令牌(tmm_...)仅对单台机器有效。README 中的客户端库读取 BURROWBOX_KEY,并需要全局 fetch(Bun、Node 18+、Deno、Workers)。
安装前请注意
Authorization 请求头携带 Burrowbox API 密钥,属于机密,应保留在服务器端。机器会计费,InsufficientCreditError 等错误说明存在支出,需关注余额和用量。机器会执行命令、应用和自动化,实时查看链接可共享且可开启控制,需确认暴露范围。保险库凭据可被代理使用,webhook 负载应使用签名密钥校验。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Burrowbox,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。

其他 MCP 客户端

把它添加到你客户端的 mcpServers 配置中。

{
  "mcpServers": {
    "burrowbox": {
      "type": "http",
      "url": "https://burrowbox.dev/mcp"
    }
  }
}

README

burrowbox-js

TypeScript client library for the Burrowbox API: persistent Linux computers for AI agents, each with a desktop, a browser that stays signed in, a credential vault and its own MCP endpoint.

→ Start using Burrowbox · API docs

Install

bash
bun add burrowbox

npm (npm install burrowbox) and pnpm (pnpm add burrowbox) work too. No runtime dependencies. Works anywhere with a global fetch: Bun, Node 18+, Deno, Cloudflare Workers. Keep API keys on your server.

Quickstart

Create an API key under Account → API keys and export it:

bash
export BURROWBOX_KEY=tmk_...

Create a machine and connect an agent to it over MCP:

ts
import { Burrowbox, toAgentSdkMcpServers } from "burrowbox";import { query } from "@anthropic-ai/claude-agent-sdk";
const bb = new Burrowbox(); // reads BURROWBOX_KEY
// Boots in a few seconds. It turns itself off (keeping its state) after an hour.const machine = await bb.machines.create({ name: "research-bot", size: "tiny", ttlMinutes: 60 });
// MCP URL + the machine's scoped token (tmm_…), which only works on this machine.const mcp = await bb.machines.mcp(machine);
for await (const msg of query({  prompt: "Open news.ycombinator.com and summarise the top 5 stories.",  options: { mcpServers: toAgentSdkMcpServers(mcp) },})) {  if (msg.type === "result" && msg.subtype === "success") console.log(msg.result);}
await bb.machines.stop(machine); // files, apps, logins and open windows are kept

mcp is plain data ({ name, url, token, headers }), so it works with any Streamable HTTP MCP client. toMessagesApiMcpServer(mcp) gives the Anthropic Messages API MCP connector shape, and toClaudeCodeCommand(mcp) prints a claude mcp add command.

Features

  • Machines: create, list, start, stop, resize, schedule and destroy, plus screenshots, apps and windows.
  • MCP: connection details for each machine's endpoint and for the platform endpoint.
  • Live view: signed links to embed a machine's screen in your product. You choose whether viewers can take control.
  • Vault: store logins in a machine. Agents can use them without ever seeing them.
  • Warm pools: keep machines booted and set up from a template, then claim one instantly for a customer.
  • Automations: cron jobs and webhooks that run commands, MCP tools or HTTP calls inside a machine.
  • Event webhooks: signed notifications when machines change state, plus verifyWebhookSignature().
  • Billing and VPN: balance, usage per customer, and residential VPN locations.
  • Typed errors (NotFoundError, InsufficientCreditError, RateLimitError…), timeouts, and automatic retries for idempotent requests.
ts
const bb = new Burrowbox({  apiKey: process.env.BURROWBOX_KEY, // or a machine token (tmm_…) for MCP and live-view only  baseUrl: "https://burrowbox.dev",  timeoutMs: 60_000,  maxRetries: 2,  fetch: customFetch, // optional});

Verify event webhooks

ts
import { constructWebhookEvent } from "burrowbox";
// Pass the raw body, not re-serialized JSON. Throws WebhookSignatureError if it doesn't verify.const event = await constructWebhookEvent(await req.text(), req.headers.get("burrowbox-signature"), process.env.BURROWBOX_WEBHOOK_SECRET!);if (event.type === "machine.stopped") console.log(event.data.machine.id, event.data.detail);

It uses Web Crypto, so the same code runs in Bun, Node, Deno, Workers and edge runtimes.

The full surface is in API.md.

Development

The repo uses Bun for installs and scripts. Tests run on Vitest, the build on tsup (ESM + CJS + types).

bash
bun installbun run typecheck && bun run test && bun run buildbun run smoke   # import the built package from Node (ESM and CJS)

License

MIT

来源:README.md,提交 d668007

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v1.0.0最新Oct 4, 2026