Connect your accounts. Keep the keys out of the box.
Your refresh tokens stay encrypted on our server. Your box gets an access token and nothing more. Every box is walled off from its neighbours, and one stated bet buys full Docker at $5.
From $5 a month · Docker and sudo included · Cancel from the dashboard any time
How the box is built
- Tokens
Refresh tokens never enter the box
Your Codex and Claude refresh tokens stay encrypted in our database. The box gets a file with one access token, renewed on schedule. An agent running with sudo holds nothing that can mint a new one.
- Accounts
Disconnect and it is gone
Remove an account in the dashboard and its tokens are deleted from our server and from every box that used it.
- Prompts
Your prompts go straight to the model
Model traffic leaves your box for Anthropic or OpenAI directly and never passes through detachbox.
- Bet
Our bet: one kernel, many boxes
Boxes are unprivileged system containers with isolated user namespaces on a shared kernel, with nesting on so Docker runs inside. We bet that a shared kernel, patched every week, is the right price for full Docker at $5. The price is one planned reboot a month, emailed 48 hours ahead.
- Network
Walled off from its neighbours
Each box reaches the public internet at 50, 100 or 200 Mbit by plan. Private networks, our servers, neighbouring boxes and outbound mail on port 25 are blocked for every box.
- Limits
One box cannot starve another
CPU, memory, disk and process count are capped per box by plan. A runaway build stays inside its own box.
- Previews
Previews on their own domain
Your dev servers answer on detachbox.dev, a separate domain from detachbox.com, private to you until you make a port public. Dashboard cookies never reach them.
- Agents
Approvals off, inside a sandbox
Agent CLIs ship with prompts off because the box is theirs to break. The worst an agent can do is wreck its own box, and reset rebuilds it from a clean image.
- Reboots
Reboots keep your files
Planned reboots come with 48 hours' notice by email. Files, Docker images and volumes survive and boxes start on their own; running processes and tmux sessions start fresh.
- Access
Key-only SSH through a gateway you can verify
SSH takes keys, never passwords. The dashboard shows the gateway's host key fingerprint, and a stopped or suspended box refuses SSH.
Found something?
Write to [email protected] about abuse coming from a box, and to [email protected] about the security of the service.
Questions about this
Can you see what runs in my box?
We see what any host sees: CPU, memory, disk and traffic per box. We use it to keep the node healthy and catch abuse. Your files stay yours: we open a box only when you ask for help, to investigate a security incident or abuse, or when the law requires it.
Is it safe to connect my Claude or ChatGPT account?
Your refresh token stays encrypted on our server and never reaches the box. The box gets an access token for the CLI. Disconnect the account and we delete its tokens from our server and from every box that used it.
What if an agent goes rogue on my box?
It is fenced into your box: no private networks, no neighbours, no outbound mail. Reset the box from the dashboard and it comes back clean.
Why a shared kernel instead of a VM per box?
A VM per box would cost several times more for the same CPU and memory. The shared kernel is how a box with full Docker costs $5, and weekly patching plus a monthly reboot keep that kernel current.
Your agent gets the box. Your refresh tokens never do
Start a box, connect your subscriptions and let the agent work.
Start my boxCharged when the box starts · Cancel from the dashboard; the box runs to the end of the paid month