rusted.sh
A capability runtime for AI agents

When your agent needs a tool, it builds one.

Connect rusted once. Your agent can write JavaScript, run it in a fresh sandbox, and keep what works as a live HTTP endpoint or MCP server — in under a second.

One connection // six primitives // tools on demand

capability build · rusted.sh
try → keep

need→Track a repo's stars for release notes

agent⏺execute code: "export default async ({ repo }) => { … }"

←{ stars: 103204 } / 38ms

agent⏺deploy name: "repo-stars"

←live: https://rusted.sh/f/repo-stars / rev 1

later$curl -X POST https://rusted.sh/f/repo-stars

{ "stars": 103204 } / 2.3ms exec

Install / one binary

$curl -fsSL https://raw.githubusercontent.com/iluxav/rusted/main/install.sh | sh

Run locally. Point at rusted.sh when you are ready.

connect rusted once

One endpoint. Six primitives. Tools on demand.

Give your agent a small surface for writing, testing, deploying, and removing the capabilities it needs. Use OAuth in hosted assistants, or an API key from a CLI or IDE.

Claude Code

$ claude mcp add --transport http rusted https://rusted.sh/mcp

The first call opens a browser sign-in — OAuth end to end, no key to manage.

Claude.ai · ChatGPT

https://rusted.sh/mcp

Add as a custom connector and approve the sign-in. Clients register themselves — OAuth 2.1 with PKCE, discovery included.

Codex · Cursor · any JSON config

{ "mcpServers": { "rusted": {
    "url": "https://rusted.sh/mcp",
    "headers": { "Authorization": "Bearer <key>" } } } }

Prefer a header? Mint a key in the console — same endpoint, same six tools. An OAuth sign-in issues one of these keys anyway, revocable from the same list.

cold start ~1ms, fresh sandbox
deploy code → URL in < 1s
toolbox one endpoint, six primitives

how it works

Six primitives. JavaScript supplies the rest.

A fixed tool catalog only covers what someone predicted in advance. rusted gives an agent a compact execution surface instead. When a capability is missing, the agent can write it, try it, and decide whether it should persist.

execute()

Try it. Run a block of code once, get the answer, throw the sandbox away.

deploy()

Keep it. The same block becomes a live URL in under a second — callable by you, by other agents, by anything that speaks HTTP.

inbox_create()

Be reachable. Mint a throwaway URL the outside world can POST to — OAuth callbacks, webhooks, "tell me when it's done."

+ 3 more

inbox_read, list, delete — housekeeping. This is the whole API.

after the conversation

Tools that outlive the conversation.

Keep what works. A deployed function stays addressable and gains only the capabilities you declare — secrets, state, object storage, or an inbox. Nothing is on by default.

config.secrets

Encrypted secrets

Declare the names, store the values once. AES-256-GCM at rest, injected per invocation — the code never holds a credential.

context.state

Durable state

Compare-and-swap storage that survives redeploys. Counters, sessions, queues — without standing up a database.

inbox + fetch

Webhooks in, webhooks out

Inboxes receive from Stripe, GitHub, anyone; fetch calls out. An agent can build both halves of an integration and leave it running.

/f/@stage/…

Environments

Every environment is a full overlay — its own secrets, its own state. Try things without touching prod.

Use HTTP when a URL is enough. When a capability needs a set of tools, deploy a complete MCP server from the same runtime. rusted is the factory, not the catalog.

sandbox.capabilitiesread only
filesystemundefined
private_networkdenied
heap32 MB cap
deadlineuncatchable
contextfresh per call

bounded autonomy

Capabilities are explicit. Limits are hard.

Every invocation starts in a fresh sandbox with an uncatchable deadline, a heap cap, no filesystem, and no private network. Secrets, state, and object access appear only when declared. You choose who can connect and deploy; rusted keeps each function's authority visible and bounded.

Need Python or a whole OS? Use a microVM. Need a small capability an agent can create, keep, and remove? That's rusted.

give your agent a place to build

Connect rusted once. Let your agent build what it needs.

Start with six primitives. Keep the useful results as live HTTP endpoints or MCP servers.