Burrowbox

io.github.burrowboxv1.0.0更新於 Oct 4, 2026

Persistent Linux computers for AI agents: desktop, signed-in browser, vault, apps and shell.

已驗證Streamable HTTP可網頁執行Developer ToolsCloud & InfrastructureSecurity & Monitoring

概覽

AI 產生的概覽

為助理提供一台常駐的 Linux 電腦,內含桌面、保持登入的瀏覽器、憑證保管庫、應用程式與 shell,可透過 MCP 存取。

功能
Burrowbox 為 AI 代理提供常駐的 Linux 電腦,每台都有桌面、保持登入狀態的瀏覽器、憑證保管庫以及自己的 MCP 端點。平台端點與每台機器的端點提供連線資訊,機器可以建立、列出、啟動、停止、調整規格、排程與銷毀,並支援截圖、應用程式與視窗。保管庫儲存登入資訊,代理可以使用但看不到內容;自動化可在機器內執行排程工作與 webhook。
適用情境
當助理需要一台真實、有狀態的電腦,而不是無狀態的工具呼叫時適用:保持瀏覽器工作階段登入、執行 shell 指令與桌面應用程式,或跨工作階段保存憑證。也適合把預熱池中預先設定好的機器直接交付給客戶的產品。
執行需求
透過 Streamable HTTP 連線 burrowbox.dev 的遠端端點。需要 Authorization 標頭,值為 Account 到 API keys 取得的 Burrowbox API 金鑰(tmk_...);機器權杖(tmm_...)僅對單一機器有效。README 中的客戶端程式庫讀取 BURROWBOX_KEY,並需要全域 fetch(Bun、Node 18+、Deno、Workers)。
安裝前請注意
Authorization 標頭攜帶 Burrowbox API 金鑰,屬於機密,應保留在伺服器端。機器會計費,InsufficientCreditError 等錯誤代表有支出,需留意餘額與用量。機器會執行指令、應用程式與自動化,即時檢視連結可分享且可開啟控制,需確認暴露範圍。保管庫憑證可被代理使用,webhook 內容應以簽章密鑰驗證。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Burrowbox,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "burrowbox": {
      "type": "http",
      "url": "https://burrowbox.dev/mcp"
    }
  }
}

README

burrowbox-js

TypeScript client library for the Burrowbox API: persistent Linux computers for AI agents, each with a desktop, a browser that stays signed in, a credential vault and its own MCP endpoint.

→ Start using Burrowbox · API docs

Install

bash
bun add burrowbox

npm (npm install burrowbox) and pnpm (pnpm add burrowbox) work too. No runtime dependencies. Works anywhere with a global fetch: Bun, Node 18+, Deno, Cloudflare Workers. Keep API keys on your server.

Quickstart

Create an API key under Account → API keys and export it:

bash
export BURROWBOX_KEY=tmk_...

Create a machine and connect an agent to it over MCP:

ts
import { Burrowbox, toAgentSdkMcpServers } from "burrowbox";import { query } from "@anthropic-ai/claude-agent-sdk";
const bb = new Burrowbox(); // reads BURROWBOX_KEY
// Boots in a few seconds. It turns itself off (keeping its state) after an hour.const machine = await bb.machines.create({ name: "research-bot", size: "tiny", ttlMinutes: 60 });
// MCP URL + the machine's scoped token (tmm_…), which only works on this machine.const mcp = await bb.machines.mcp(machine);
for await (const msg of query({  prompt: "Open news.ycombinator.com and summarise the top 5 stories.",  options: { mcpServers: toAgentSdkMcpServers(mcp) },})) {  if (msg.type === "result" && msg.subtype === "success") console.log(msg.result);}
await bb.machines.stop(machine); // files, apps, logins and open windows are kept

mcp is plain data ({ name, url, token, headers }), so it works with any Streamable HTTP MCP client. toMessagesApiMcpServer(mcp) gives the Anthropic Messages API MCP connector shape, and toClaudeCodeCommand(mcp) prints a claude mcp add command.

Features

  • Machines: create, list, start, stop, resize, schedule and destroy, plus screenshots, apps and windows.
  • MCP: connection details for each machine's endpoint and for the platform endpoint.
  • Live view: signed links to embed a machine's screen in your product. You choose whether viewers can take control.
  • Vault: store logins in a machine. Agents can use them without ever seeing them.
  • Warm pools: keep machines booted and set up from a template, then claim one instantly for a customer.
  • Automations: cron jobs and webhooks that run commands, MCP tools or HTTP calls inside a machine.
  • Event webhooks: signed notifications when machines change state, plus verifyWebhookSignature().
  • Billing and VPN: balance, usage per customer, and residential VPN locations.
  • Typed errors (NotFoundError, InsufficientCreditError, RateLimitError…), timeouts, and automatic retries for idempotent requests.
ts
const bb = new Burrowbox({  apiKey: process.env.BURROWBOX_KEY, // or a machine token (tmm_…) for MCP and live-view only  baseUrl: "https://burrowbox.dev",  timeoutMs: 60_000,  maxRetries: 2,  fetch: customFetch, // optional});

Verify event webhooks

ts
import { constructWebhookEvent } from "burrowbox";
// Pass the raw body, not re-serialized JSON. Throws WebhookSignatureError if it doesn't verify.const event = await constructWebhookEvent(await req.text(), req.headers.get("burrowbox-signature"), process.env.BURROWBOX_WEBHOOK_SECRET!);if (event.type === "machine.stopped") console.log(event.data.machine.id, event.data.detail);

It uses Web Crypto, so the same code runs in Bun, Node, Deno, Workers and edge runtimes.

The full surface is in API.md.

Development

The repo uses Bun for installs and scripts. Tests run on Vitest, the build on tsup (ESM + CJS + types).

bash
bun installbun run typecheck && bun run test && bun run buildbun run smoke   # import the built package from Node (ESM and CJS)

License

MIT

來源:README.md,提交 d668007

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.0.0最新Oct 4, 2026