AI agents

Most platforms give an agent a fixed toolbox. Rusted gives it a place to make tools: an agent that can write JavaScript can mint a live endpoint in one call, invoke it in milliseconds, and throw it away when done.

Connect

Point any MCP client at the platform's server with a rusted API key:

{ "mcpServers": { "rusted": {
    "url": "https://rusted.sh/mcp",
    "headers": { "Authorization": "Bearer <your rusted api key>" } } } }

No key at hand? Hosted assistants (Claude, ChatGPT) and OAuth-capable CLIs can add https://rusted.sh/mcp as a connector and sign in through the browser instead — the server implements the MCP authorization spec end to end: RFC 9728/8414 discovery, dynamic client registration, and PKCE. The token an assistant receives is an ordinary API key, visible and revocable in the console's key list like any other.

Six tools, deliberately few: execute, deploy, list, delete, inbox_create, inbox_read. The prevailing MCP pattern hands a model dozens of tools whose schemas cost context before the conversation starts — an abstraction from when models couldn't write code. A model that writes code doesn't need a schema per capability; it needs fetch and somewhere safe to run. The sandbox is what makes handing that to a model defensible: hard wall-clock, heap, and output limits, no filesystem, no process, SSRF-guarded networking.

The loop

Try code without deploying anything — execute runs a handler ad-hoc and returns the result, logs, and timings:

execute({ "code": "export default async () => {
  const r = await fetch('https://api.github.com/repos/rust-lang/rust');
  return { stars: (await r.json()).stargazers_count };
}" })

Keep what works — deploy makes it a named, persistent endpoint and returns the URL. Deployment is a database write plus a compile check: the endpoint is live in well under a second. From then on it's plain HTTP — callable by the agent, by other agents, by anything:

curl -X POST https://rusted.sh/f/repo-stars -d '{}'

Fast enough to be a subroutine. Invocations run in a fresh sandbox with pre-compiled bytecode; typical handlers execute in single-digit milliseconds of pure execution time, and a simple function round-trips in well under 50 ms — an agent can treat a deployed function as a fast function call, not a slow external service. The numbers aren't folklore: GET /api/stats serves live per-function p95 execution times from the platform's own telemetry.

Tools that persist and coordinate

Deployed functions aren't limited to stateless glue. Declared capabilities give an agent's tools real machinery — durable CAS state that survives redeploys, object storage with presigned uploads, encrypted secrets, and per-environment isolation for trying things without touching prod:

export const config = { state: true, secrets: ["API_TOKEN"] };

And an agent can deploy MCP functions — serving tools to other models, with schema validation and optional OAuth handled by the platform. An agent building tools for its future selves, or for other agents, is the intended shape.

Receiving, not just calling

Agents can call out but can't be called back — no inbound address rules out OAuth callbacks, webhooks, and "tell me when it's done." Inboxes fix that inside the same six tools: inbox_create returns a throwaway URL anyone can POST to; inbox_read polls it by name. Start a flow, hand out the URL, keep working, collect the result.

Why this works well for agents, specifically

  • Errors are model-legible. A thrown error returns as a readable tool result with the message and console output — the model reads it and fixes its own code. Schema violations are named precisely before any sandbox boots.
  • Limits are honest. Execution budgets, rate limits, and refusals come back as structured answers an agent can act on (retry, back off, simplify), never as silent failures.
  • Everything is inspectable. list shows what exists, rusted logs and /api/stats show what happened — an agent can observe and manage its own fleet of functions.
  • TypeScript declarations exist (rusted types) describing exactly what the runtime has — nothing a model's training data promises from Node or the browser will typecheck if it won't run.

The pitch in one line: rusted is the MCP server that lets agents write their own tools — create in seconds, invoke in milliseconds, delete without ceremony.