Burrowbox

Persistent Linux computers for AI agents: desktop, signed-in browser, credential vault, app installs and shell, over MCP.

Hosted MCP Server

npx add-mcp 'https://burrowbox.dev/mcp'

Installs into Claude Code, Codex, Cursor and more

Documentation

MCP

Burrowbox speaks the Model Context Protocol over Streamable HTTP. There are two kinds of endpoint.

Platform MCP

POST /mcp with your API key. Lets an agent manage machines itself.

ToolWhat it does
machines_listYour machines, with status, expiry and MCP URL; filter by external_id and labels
machine_createCreate and boot a machine (name, size, screen, ttl_minutes, on_expire, external_id, labels)
machine_getDetails, including mcpUrl and mcpToken
machine_start / machine_stopTurn a machine on or off; state is kept
machine_set_ttlChange how long it stays on (null = always on)
vpn_locations, machine_set_vpn, machine_vpn_statusVPN locations: browse from a residential IP in a chosen country
machine_resizeChange the size (tiny … large) without recreating; a running machine restarts once (~20 s)
machine_updateUpdate the machine's agent to the latest release (live when possible) — see Updates
machine_set_browserSwitch the browser: light (fast, no WebGL) or full (Chromium with WebGL) — see Browser mode
machine_set_tagsSet external_id (your customer's id) and labels
pools_list, pool_create, pool_update, pool_delete, pool_claimWarm pools: keep machines booted and hand one to a customer instantly
usage_by_customerSpend per external_id or per machine (Billing)
event_webhooks_list, event_webhook_create, event_webhook_test, event_webhook_deleteEvent webhooks: get notified when machines change state
machine_destroyDelete a machine permanently (its disk, vault, snapshots, schedules and webhooks)
machine_schedule_*, machine_webhook_*, machine_job_runsScheduled jobs and webhooks; see Scheduled jobs & webhooks
machine_live_viewA link to watch or take over the machine, ready for an <iframe> (Embed the live view)
machine_call_toolCall any machine tool without a second connection
account_balanceBalance, burn rate and runway
claude mcp add --transport http burrowbox https://burrowbox.dev/mcp

Clients that support OAuth (Claude, Cursor, VS Code) open a Burrowbox page to sign in and approve, so you don't need a key (OAuth). Otherwise, pass an API key:

claude mcp add --transport http burrowbox https://burrowbox.dev/mcp \
  --header "Authorization: Bearer $BURROWBOX_KEY"

Machine MCP

POST /api/machines/{id}/mcp with the machine's mcpToken (or your API key). This is what an agent uses to operate the computer.

Browser

The machine's persistent browser. Cookies, local storage and tabs survive restarts, and you can watch it live.

ToolArguments
browser_navigateurl
browser_snapshotmax_chars — URL, title, text and interactive elements tagged [ref]
browser_clicktarget — a ref from the snapshot, or a CSS selector
browser_filltarget, value, submit
browser_type / browser_press_keytext / key
browser_evaluateexpression
browser_screenshot—
browser_tabsaction: list, new, switch, close
browser_logincredential (optional; matched by URL) — fills and submits a login form from the vault
human_solve_captchakind, sitekey, url, timeoutSeconds, tokenOnly — solves the verification challenge on the current page (Cloudflare verification pages, Turnstile, reCAPTCHA v2, hCaptcha). Billed per use

Desktop

ToolArguments
screenshot, desktop_screenshotCapture the screen
get_app_stateAccessibility tree + screenshot of one app
list_windows, focused_window, activate_windowWindow management
click, drag, scroll, type_text, press_keyInput, by element index, selector or coordinates
perform_action, set_valueAccessibility actions

Apps, shell and files

ToolArguments
apps_listquery
apps_installkind: apt (packages), deb (url), appimage (url, name), flatpak (ref), script
apps_launchapp or command — waits for the window
shell_runcommand, cwd, timeout_seconds, background
browser_capabilitiesThe browser engine (light / full) and whether pages get WebGL/WebGL2
network_infoPublic IP, country and network the machine browses from, and whether a VPN location is set
file_read / file_writepath / path, content

Vault

ToolArguments
vault_listNames, URLs and usernames — never secrets
vault_setname, url, username, password, totp_secret
vault_type_secretname, field (username / password / totp) — types into the focused app
vault_deletename

Automations

Added by the platform, scoped to this machine: schedule_create, schedule_list, schedule_update, schedule_delete, schedule_run, webhook_create, webhook_list, webhook_rotate, webhook_delete, job_runs. An agent can schedule its own work ("check this dashboard every morning at 9") or give another system a URL that triggers it. See Scheduled jobs & webhooks.

Session

Tool
session_saveRecord open windows and tabs now (also happens every 20 s)
machine_infoWhat's running and how the tools fit together