---
title: "Host agent work · intentic"
description: "Run the sandbox on a server you own. You approve installed software, connect through a private tunnel and keep usage data in the sandbox."
url: "https://intentic.dev/features/host/"
---

Self-hosting

# Host the work. Keep control.

A sandbox is a Docker container on your laptop, desktop or server. Move it to a server so agents can keep working when your laptop is off.

[Create your workspace](https://app.intentic.dev)[Open the live workspace](https://intentic.dev/demo/)

acme-shop · /sandbox

![The sandbox hub: the acme-shop sandbox on ada-pc with its installed version, its own URL and the memory and cores it may use, over the disk it takes up, beside the list of everything it holds: usage, environment, secrets, agent account, extensions, access, areas and personas.](https://intentic.dev/_astro/sandbox-overview.Ces43QEb_Z1J3QDC.webp)

![The sandbox hub: the acme-shop sandbox on ada-pc with its installed version, its own URL and the memory and cores it may use, over the disk it takes up, beside the list of everything it holds: usage, environment, secrets, agent account, extensions, access, areas and personas.](https://intentic.dev/_astro/sandbox-overview.CwkMaiGT_1MuAI2.webp)

- No code

 the platform stores no source, prompts or credentials
- MIT

 all of intentic is open source, platform included
- No open ports

 the sandbox makes a private outbound connection

## Self-hosted

A private tunnel connects your browser to the sandbox. On a server, it keeps running without you.

Your browser

Chat, files, editor, terminal

your browser connects directly through a private tunnel

Your machine

Sandboxes, repos, credentials, capabilities

intentic platform

Stores your identity and sandbox URL. Does not handle commands or files.

## You control what is installed

A Dockerfile defines the sandbox's installed software. The agent can propose a change, but it waits for your approval before applying it.

acme-shop · /sandbox/environment

![The sandbox Environment tab: an overlay Dockerfile diff awaiting review, adding an imagemagick install, with Reject and Approve buttons.](https://intentic.dev/_astro/sandbox-environment.CT2YmKR8_RlAck.webp)

![The sandbox Environment tab: an overlay Dockerfile diff awaiting review, adding an imagemagick install, with Reject and Approve buttons.](https://intentic.dev/_astro/sandbox-environment.ONxVrycJ_2mbmCo.webp)

## Make the environment reproducible

Download its live shape as sandbox.toml: repository remotes, connection shapes, secret names, the approved overlay and non-default agent settings. Commit it, compare another sandbox for drift, or seed a fleet without exporting a credential or transcript.

- Definitions are deterministic TOML derived from the live sandbox, never a stale second copy
- Applying one is preview-first: overlays wait for the new owner's approval and connections wait for authentication

## See usage where it happens

The sandbox records the tokens and cost of each turn. The usage stays in your own ledger because the AI account is yours.

acme-shop · /sandbox/usage

![The sandbox Usage tab: a month of spend per day, stacked by Claude Code and Codex, with the cost broken down by model and by the agent that spent it.](https://intentic.dev/_astro/sandbox-spend.DwtYY5fb_ZwbUqC.webp)

![The sandbox Usage tab: a month of spend per day, stacked by Claude Code and Codex, with the cost broken down by model and by the agent that spent it.](https://intentic.dev/_astro/sandbox-spend.DLjkjfKP_Z1EviKp.webp)

## What the platform actually holds

It stores your identity, sandbox URL and teammate access. It does not store your code, keys or transcripts.

### Stays inside your sandbox

- Your code and repos
- Every credential and token
- The agent's transcripts
- The container and its image

### All the platform holds

- Your identity (Google sign-in)
- The sandbox's name and URL
- Billing state
- Grants to invited teammates

Stored records use AES-256-GCM encryption. The product has no feature that can decrypt them.

## One sandbox, several people

The owner installs the tools; invited teammates share the sandbox, each signed in as themselves.

- Invite people by email. The sandbox enforces their access, not just the interface.
- Teammates can chat, work, review and open the web apps running in the sandbox.
- Removing someone's access takes effect immediately.

Y

You Owner

installs tools · connects systems · full control

S

Sam Teammate

chats, works & reviews · opens sandbox apps

A

Ada Teammate

chats, works & reviews · opens sandbox apps

each over its own private tunnel

one specialized sandbox

storefront · on the owner's machine

running

[Guide Where does your code go when you use a cloud coding agent? A straight answer, the approaches that are not this product included.](https://intentic.dev/guides/where-your-code-goes-with-cloud-coding-agents/)

[Next Agent Workspace → Many agents, one board](https://intentic.dev/features/run/)

[Create your workspace](https://app.intentic.dev)[Read the quickstart](https://intentic.dev/docs/quickstart/)
