# Tenki Sandbox MCP [Health: Active]

**Category:** 👨‍💻 Code Execution  
**Repository:** https://github.com/LuxorLabs/tenki-mcp  
**GitHub Stars:** 0  
**npm Downloads (last month):** 356  
**Views:** 1  
**Installs:** 0  
**Upvotes:** 0  
**Directory Page:** https://allmcps.com/mcp/tenki-sandbox-mcp

## Description
Disposable microVM sandboxes for AI agents: run code, read/write files, git, preview URLs.

## Claude Desktop Quick Installation
Install path detected from listing signals. Uses `npx` (confidence: high):

```json
"mcpServers": {
  "tenki-sandbox-mcp": {
    "command": "npx",
    "args": ["-y","@tenkicloud/mcp"],
    "env": {
      "TENKI_API_KEY": "",
      "TENKI_AUTH_TOKEN": ""
    }
  }
}
```

**Requires environment variables:** `TENKI_API_KEY`, `TENKI_AUTH_TOKEN` — the values above are empty placeholders; fill in real credentials before running (see the repository for what each one is for).

## Documentation

## What Tenki Sandbox MCP does

Tenki Sandbox MCP MCP server gives an MCP-compatible agent access to disposable microVMs managed by Tenki Cloud. Agents can create, inspect, pause, resume, extend, and terminate sandboxes, or use the one-shot run workflow to boot a sandbox, execute code, return the result, and tear it down.

The server covers more than code execution. Its tools handle file reads and writes, directory operations, path metadata, file moves, selected Git actions, network port exposure, preview URLs, binary artifact transfers, SSH credentials, snapshots, volumes, templates, and workspace settings. It exposes 71 tools: public Tenki API methods, workflow helpers, and an authentication-status tool.

## How it works

The package runs as `@tenkicloud/mcp` and communicates over MCP stdio by default. An agent calls a tool, and the server sends the corresponding request to Tenki Cloud's control plane. Execution takes place inside a disposable microVM instead of the machine running the MCP client. Tenki Sandbox MCP MCP server can also run in Streamable HTTP mode for remote clients.

Authentication uses either `TENKI_API_KEY` or `TENKI_AUTH_TOKEN`. If both exist, the session token takes precedence. The server selects the request credential format from the token prefix. Without credentials, it still starts with `tenki_auth_status`, which reports the configured credential type, endpoint, and whether an identity check succeeds without revealing the token.

## Setup and configuration

For the normal local installation, set a Tenki credential and launch the package with `npx -y @tenkicloud/mcp`. No repository checkout or build is needed. Claude Desktop, Cursor, and Codex can start the command through their MCP configuration files. Claude Code can use either a local command with an environment variable or Tenki's hosted MCP endpoint with browser-based login.

The control-plane endpoint defaults to `https://api.tenki.cloud` and can be changed with `TENKI_API_ENDPOINT`; `TENKI_API_URL` is an alias. `TENKI_MCP_READONLY=1` restricts registration to read tools, while `TENKI_MCP_DISABLED_TOOLS` accepts a comma-separated exclusion list. `TENKI_MCP_AUDIT=1` logs tool names and argument keys to stderr.

For HTTP hosting, set `TENKI_MCP_TRANSPORT=http`. The default port is 3000 and the default bind address is loopback. A non-loopback bind requires `TENKI_MCP_HTTP_TOKEN`; hosted OAuth deployments use the documented public URL, issuer, scope, resource, and identity-service settings.

## Tools and capabilities

- Run shell, Python, or JavaScript code with `tenki_run_code`, or execute commands in an existing sandbox with `tenki_exec`.
- Create and manage sandboxes, including bulk termination and activity reporting.
- Read, write, list, move, create, inspect, and remove filesystem paths.
- Clone, check out, inspect diffs, and view Git logs through `tenki_git`; other Git commands can run through execution.
- Expose ports and create, open, bind, resolve, touch, or delete preview URLs.
- Transfer binary data through signed upload and download URLs.
- Manage snapshots, persistent volumes, templates, SSH access, and workspace settings.

## Limitations and notes

Tenki Sandbox MCP MCP server exposes the Sandbox product, not Tenki's separate Code Reviewer or Runners products. The Git tool supports exactly clone, checkout, diff, and log; unsupported Git operations must use command execution. HTTP mode is beta according to the provided documentation and uses one shared API key in a single-user deployment, so network exposure requires deliberate bearer-token configuration.

Sandboxes are disposable, boot in approximately two seconds according to the project documentation, and are billed per second. Starting a fresh MCP client session may be necessary after configuration changes so the client discovers the tools.

_Full upstream README: https://allmcps.com/mcp/tenki-sandbox-mcp/readme_

