Build an internal Business OS

~20 min TypeScript Python

What you’re building: an internal company OS: a private platform for your team, where agents, apps, and data live together behind your own login.

Primitives you’ll use: Organization, Sandboxes, Computers, Agents, Postgres, Deployments, Custom domains

What you’re building

A Business OS is the internal counterpart of a commercial platform: one place where your team runs agents, builds internal apps, and keeps the data they need. It is private by default and owned by the company.

On MIOSA you build it once and reuse it: an organization with workspaces per team, sandboxes and computers for agents and builders, managed databases for shared data, and deployments for the internal apps. A private preview domain and custom domains keep everything behind your own hostname.

MIOSA’s own BusinessOS template is open source under Apache 2.0 and is the reference for this shape; use it as a starting point or build your own on the same primitives.

What you need on MIOSA

Architecture

Step 1: Create an account and an API key

Install the CLI, sign in, and mint a key for your product. The secret is printed once; store it as an environment variable, never in code.

npm i -g @miosa/cli
miosa login
miosa whoami
miosa api-key create business-os-key --preset agent     # prints the secret once
export MIOSA_API_KEY="msk_u_..."

Both SDKs read MIOSA_API_KEY from the environment, so a server or a worker needs nothing else. See API keys for scopes and how to create keys in the console.

Step 2: Create the resources

Step 3: Wire the agent loop

Publish the internal apps (and the OS shell itself) with the deploy step, and put them behind your company domain with the domain step.

Step 4: Preview

A Preview is a throwaway public URL for a port inside the machine. Start the app as a background process so it survives the CLI disconnecting, then expose its port.

Open the exact Preview URL MIOSA returns.

Step 5: Deploy

Publish the machine to an immutable Deployment. Give it the source machine, the path the app lives at inside it, and the command that serves it.

Publishing the same deployment name again creates a new immutable version and keeps the same URL. Roll back with miosa deploy rollback business-os --to <version-id>, and inspect a live app with miosa deploy logs business-os -n 100. See Publishing and Rollback.

Step 6: Custom domain

Attach a domain your customer owns to the deployment. The platform URL keeps working while DNS propagates.

miosa deploy domain-add business-os app.example.com
miosa deploy domains business-os          # shows the DNS record and verification target
miosa deploy domain-verify business-os <domain-id>

Copy the exact DNS record MIOSA shows into the customer’s DNS provider; for a subdomain it is normally a CNAME. Once verified and TLS is active, MIOSA routes the domain to the deployment’s active version. In code, read the URL from the publish response instead of building it: the SDK method is miosa.deployments.domains.add(deploymentId, { domain }) (TypeScript) or miosa.deployments.domains(deployment_id).add(domain=...) (Python). See Domains.

Costs and limits

Everything bills while it runs: machines (sandboxes and computers) by the second, managed databases while running, and deployments when they serve. Pausing a machine stops compute billing but keeps disk. Set an --idle-timeout or a --ttl so a forgotten machine cannot run forever, and cap spend with rate limits and per-workspace quotas.

Next steps

Was this page helpful?