An autonomous coding agent that runs in the browser. You give it a task; it plans, reads/writes files, and runs shell commands — all inside an isolated, ephemeral Vercel Sandbox VM, never on your real machine.
Built with Next.js, the Vercel AI SDK ToolLoopAgent,
and @vercel/sandbox.
- Each browser session gets its own persistent sandbox (
src/lib/sandbox.ts). - The agent (
src/lib/agent.ts) has four tools (src/lib/tools.ts): read file, write file, list directory, run shell command — all executed inside that sandbox. src/app/api/agent/route.tsstreams the agent's reasoning and tool calls to the browser viacreateAgentUIStreamResponse.- The UI (
src/components/) renders it as a black/red/gold terminal console.
cp .env.example .env.localGet an API key from Vercel AI Gateway
and set it as AI_GATEWAY_API_KEY in .env.local. (On a Vercel deployment
this is automatic via OIDC — no key needed.)
vercel link
vercel env pullThis pulls a short-lived VERCEL_OIDC_TOKEN into .env.local, which
@vercel/sandbox uses to create VMs. It expires after ~12h locally — rerun
vercel env pull when it does. In production on Vercel this is automatic.
npm install
npm run devOpen http://localhost:3000.
Every message can trigger several LLM calls and spin up a sandbox VM, so a script hammering the endpoint could run up your AI Gateway bill fast. Two guards are in place:
- Per-IP rate limit (
src/lib/rate-limit.ts): max 8 requests per 10 minutes per IP, backed by Vercel Runtime Cache (falls back to in-memory locally). Excess requests get a429. - Capped agent loop (
src/lib/agent.ts): each message can run at most 15 tool-loop steps, bounding the worst-case cost of a single request.
This isn't bulletproof (a botnet spreading across many IPs would still get through) — for stronger protection, set a spending limit on AI Gateway in your Vercel dashboard, or add the WAF custom-rule rate limit described in Vercel Firewall docs (requires Pro plan).
vercel deploy --prodCosts to be aware of: every message triggers a model call (billed through your Vercel/Anthropic usage) and may spin up a sandbox VM (billed per second of use, see Sandbox pricing). If you deploy this publicly without authentication, anyone with the URL can run up your bill — add auth before sharing the link widely.