Introduction
Corevelos runs untrusted, agent-generated code in hardware-isolated MicroVMs — booted in milliseconds and billed by the second.
Corevelos gives AI agents a safe place to run code. Every sandbox is a hardware-isolated MicroVM with its own kernel, filesystem and network — not a shared container — so agent-generated code runs with real blast-radius containment.
Why MicroVMs
A container shares the host kernel; a MicroVM does not. For executing untrusted, agent-written code, that boundary is the product:
- Hardware isolation — a dedicated kernel per sandbox.
- Millisecond cold starts — boot a fresh sandbox in ~128ms, pause to disk and resume in about a second with memory intact.
- Metered to the second — allocation × time billing for vCPU, RAM and storage, with spend caps and per-key attribution.
How it fits together
Quickstart
Create your first sandbox in under a minute.
Sandboxes
Lifecycle: create, run commands, files, pause, resume, kill.
Projects
Group resources, set per-project limits, share across a team.
SDK & CLI
TypeScript and Python SDKs, plus a zero-dependency CLI.
Where to run it
Drive Corevelos from the TypeScript or Python SDK, the CLI, or the REST API directly. Agent frameworks can connect through the Model Context Protocol (MCP) server and create sandboxes natively.