Download Cosmonic Desktop (Beta)
Public beta · Free · macOS, Windows & Linux

Build and run your agent's code, sandboxed.

Your coding agent writes code faster than you can read it. Cosmonic Desktop is a local AI sandbox: it runs MCP servers and agent code on your own machine, where each one starts with no access to your files, network, or keys until you grant it.

No account required· Run your first sandbox in minutes

Build with your agent

Prompt to a sandboxed app, instantly

Bring your own coding agent. Install the cosmonic-sandbox skill, or connect Desktop's MCP server, and the code your agent writes lands in a sandbox you can read before it runs. Your app is compiled locally and runs in a sandbox from the first second.

Works with the agents you already use
Claude Code Codex Gemini CLI Antigravity Kiro OpenClaw opencode Hermes Agent Pi Cowork Cursor Cursor CLI GitHub Copilot Cline Zed Goose Kilo Code Crush Augment CLI Trae Warp
Cosmonic Desktop — Builder
From a sentence to a sandboxed app, reaching Running in seconds.

Tiny footprint

Fast enough to sandbox everything,
small enough to run it all

A fresh sandbox per call is cheap, and idle workloads cost nothing. Secure every tool your agent touches without compromises.

<1 ms
per-call instantiation, so a clean sandbox for every invocation
1,000s / host
thousands to tens of thousands of workloads on one machine, by size
0 idle
scales to zero when nothing's calling, then wakes on demand

Under the hood, each workload is a WebAssembly component running on CNCF wasmCloud, so you can deploy at scale and you're never locked in.

How it works

Code only gets what you grant

Every workload starts with zero authority: no filesystem, no network, no environment, no clock. It gets exactly the capabilities you grant and nothing else, so a poisoned tool or an injected instruction has nowhere to go. Open Inspect to see the whole boundary before anything runs.

your files your keys a host you allow
Inspect · read before it runs
github-mcp Component 1.9 MB on disk

Can reachonly what you granted

Networkapi.github.com

Never grantednever requested, never reachable

All other network
Your files & home folder
Secrets & keys
A real MCP server from the built-in app catalog, seen in Inspect: it reaches GitHub’s API and nothing else.

In the box

Everything you need to run agent code locally

Launchpad
A catalog of ready-made, sandboxed apps and MCP servers.
Builder
Prompt-to-sandboxed-app with your own coding agent.
Inspect
Review the capabilities of any app.
MCP Inspector
Try a server's tools by hand, then hand it to your agent.
Local inference
Point it at Ollama so your tools call a model that never leaves your machine.
cosmonic CLI
Scaffold, dev-loop, and deploy from your terminal.

Three ways to start

Get started in minutes

Install Desktop and pick a starting point. Whichever you choose, the code runs deny-by-default and you see its boundary before it starts.

Run something now

Pull from the Launchpad

Grab a ready-made, already-sandboxed app or MCP server from the built-in catalog and deploy it in a click. Review what it can reach, then run it.

Build your own

Describe an app to the Builder

Say what you want in plain language. Your coding agent builds and deploys in a sandbox.

Arm your agent

Give your agent a sandboxed tool

Build an MCP server and register it with Claude Code, Cursor, and other agents in one step. Your agent gets a new tool in your sandbox.

FAQ

Running agent code safely,
answered

Is it safe to run the code my AI coding agent writes?

The risk isn't the agent; it's the code and MCP servers it runs. Cosmonic Desktop runs each of them in its own WebAssembly sandbox with deny-all egress: no access to your files, network, or keys until you grant it.

How do I set up a Claude Code sandbox?

Install Cosmonic Desktop and connect it to Claude Code with its MCP server. Claude Code then builds and runs its code and MCP servers as sandboxed workloads on your machine, each starting with deny-all egress. The Claude Code sandbox guide walks through the setup.

How do I sandbox an MCP server for Claude Code or Cursor?

Run the MCP server as a Cosmonic Desktop workload. It starts with no file, network, or credential access; you grant exactly the capabilities it needs, and everything else stays denied.

How do I run an MCP server locally?

Cosmonic Desktop runs MCP servers on your own machine (no cloud sandbox required), each isolated with deny-all egress by default. It's free on macOS, Windows, and Linux.

Is Cosmonic Desktop free, and which platforms does it run on?

Yes. Cosmonic Desktop is free and runs on macOS, Windows, and Linux. It's currently in public beta.

Public beta

Cleared for launch

Download Cosmonic Desktop and run your first sandboxed workload in minutes. Free forever for personal use, local, and yours.

macOS · Windows · Linux