Sandbox server
The front door. It signs users in without an account, gives each one a private sandbox, queues them when every spot is taken and cleans up after them.
Components
Anonymous sign-in
Hosted MCP clients such as claude.ai call from shared, rotating server addresses, so an IP address cannot tell users apart. The server therefore uses a standard OAuth 2.1 flow whose sign-in page has a single button, Create my sandbox: no account and no email.
- Discovery: the client finds the sign-in endpoints by itself (RFC 9728 and RFC 8414).
- Registration: the client registers itself automatically (RFC 7591).
- Authorization: one-time code with PKCE (S256), so an intercepted code is useless.
- Tokens: an access token lasts 1 hour; the refresh token lasts 30 days and is replaced on every use.
- Storage: clients and tokens are stored hashed. Codes and pending sign-ins live in memory only.
- Each token maps to a random sandbox key. That key, not the IP address, decides which sandbox you get.
The slot pool
500 sandboxes are created in advance as separate ZFS datasets, so the server never needs administrator rights while it runs. Connecting and listing the tools never takes a slot; a slot is taken on your first tool call.
The waiting queue
- When all 500 are in use, your tool call joins a queue in arrival order and tells you your position and an estimated wait.
- A freed slot goes straight to the front of the queue: the sandbox is created at once and a one-time note says it is ready.
- Optionally, the sign-in page asks for an email address for a single "your sandbox is ready" message. It is kept in memory only, never written to disk, and deleted once sent or after 24 hours. The server sends at most 60 such emails an hour.
Cleanup
Every tool call refreshes the sandbox. A watchdog checks regularly, and a sandbox that has been idle for 10 minutes is emptied and its slot freed. Your login stays valid, so your next tool call simply gets a new, empty sandbox, with a short note saying so.
Isolation
- Path jail: every path a tool receives is resolved against your sandbox and refused if it leads outside it.
- Symlink check: a link inside the sandbox, for example from a cloned repository, could point anywhere. The jail finds the deepest part of the path that exists, resolves where it really lives and refuses it if that is outside the sandbox. A link that cannot be resolved is refused too.
- Per-call context: each tool call runs with its own context naming your sandbox, your project map and your edit state, so tools can never mix up two users.
Endpoints
POST /mcp: the MCP endpoint.GET /health: pool status and queue length (it drives the live spot counter on these pages)./.well-known/*,/register,/authorize,/token: the sign-in flow.
Try it
Add this URL as a custom connector in your MCP client:
https://mcp.itamos-technologia.com/mcp- Add the URL as a connector in your MCP client.
- A page opens: choose Create my sandbox. No account needed.
- Ask your agent to clone a repository and explore it with the tools.
—/500 spots in use right now.