When your agent needs a tool, it builds one.
Connect rusted once. Your agent can write JavaScript, run it in a fresh sandbox, and keep what works as a live HTTP endpoint or MCP server — in under a second.
One connection // six primitives // tools on demand
need→Track a repo's stars for release notes
agent⏺execute code: "export default async ({ repo }) => { … }"
←{ stars: 103204 } / 38ms
agent⏺deploy name: "repo-stars"
←live: https://rusted.sh/f/repo-stars / rev 1
later$curl -X POST https://rusted.sh/f/repo-stars
{ "stars": 103204 } / 2.3ms exec
Install / one binary
$curl -fsSL https://raw.githubusercontent.com/iluxav/rusted/main/install.sh | sh
Run locally. Point at rusted.sh when you are ready.
connect rusted once
One endpoint. Six primitives. Tools on demand.
Give your agent a small surface for writing, testing, deploying, and removing the capabilities it needs. Use OAuth in hosted assistants, or an API key from a CLI or IDE.
Claude Code
$ claude mcp add --transport http rusted https://rusted.sh/mcp
The first call opens a browser sign-in — OAuth end to end, no key to manage.
Claude.ai · ChatGPT
https://rusted.sh/mcp
Add as a custom connector and approve the sign-in. Clients register themselves — OAuth 2.1 with PKCE, discovery included.
Codex · Cursor · any JSON config
{ "mcpServers": { "rusted": {
"url": "https://rusted.sh/mcp",
"headers": { "Authorization": "Bearer <key>" } } } }
Prefer a header? Mint a key in the console — same endpoint, same six tools. An OAuth sign-in issues one of these keys anyway, revocable from the same list.
how it works
Six primitives. JavaScript supplies the rest.
A fixed tool catalog only covers what someone predicted in advance. rusted gives an agent a compact execution surface instead. When a capability is missing, the agent can write it, try it, and decide whether it should persist.
execute()
Try it. Run a block of code once, get the answer, throw the sandbox away.
deploy()
Keep it. The same block becomes a live URL in under a second — callable by you, by other agents, by anything that speaks HTTP.
inbox_create()
Be reachable. Mint a throwaway URL the outside world can POST to — OAuth callbacks, webhooks, "tell me when it's done."
+ 3 more
inbox_read, list, delete — housekeeping. This is the whole API.
after the conversation
Tools that outlive the conversation.
Keep what works. A deployed function stays addressable and gains only the capabilities you declare — secrets, state, object storage, or an inbox. Nothing is on by default.
config.secrets
Encrypted secrets
Declare the names, store the values once. AES-256-GCM at rest, injected per invocation — the code never holds a credential.
context.state
Durable state
Compare-and-swap storage that survives redeploys. Counters, sessions, queues — without standing up a database.
inbox + fetch
Webhooks in, webhooks out
Inboxes receive from Stripe, GitHub, anyone; fetch calls out. An agent can build both halves of an integration and leave it running.
/f/@stage/…
Environments
Every environment is a full overlay — its own secrets, its own state. Try things without touching prod.
Use HTTP when a URL is enough. When a capability needs a set of tools, deploy a complete MCP server from the same runtime. rusted is the factory, not the catalog.
bounded autonomy
Capabilities are explicit. Limits are hard.
Every invocation starts in a fresh sandbox with an uncatchable deadline, a heap cap, no filesystem, and no private network. Secrets, state, and object access appear only when declared. You choose who can connect and deploy; rusted keeps each function's authority visible and bounded.
Need Python or a whole OS? Use a microVM. Need a small capability an agent can create, keep, and remove? That's rusted.
give your agent a place to build
Connect rusted once. Let your agent build what it needs.
Start with six primitives. Keep the useful results as live HTTP endpoints or MCP servers.