Build a Claude Code-style CLI agent

~20 min TypeScript Python

What you’re building: a CLI coding agent: a terminal harness runs inside a persistent sandbox with the repo, packages, and shell it needs, and streams its work back.

Primitives you’ll use: Organization, Sandboxes, Agents, Deployments, Custom domains

What you’re building

Claude Code and Codex turn a prompt into code from the terminal. To offer that to your users as a product, run the harness inside a machine you control, not on their laptops: a sandbox with the repository, the toolchain, and the shell.

MIOSA ships harness definitions (Claude Code, Codex, OSA, or custom) and runs them against a machine. You dispatch a run, stream its tool calls and output, and collect the files and artifacts it created. The sandbox persists between turns, so a session has a real workspace, and it can be snapshotted or destroyed on demand.

The important architectural point: the agent works in the MIOSA machine. Your backend orchestrates; the files, commands, and artifacts live in the runtime.

What you need on MIOSA

Architecture

Step 1: Create an account and an API key

Install the CLI, sign in, and mint a key for your product. The secret is printed once; store it as an environment variable, never in code.

npm i -g @miosa/cli
miosa login
miosa whoami
miosa api-key create cli-agent-key --preset agent     # prints the secret once
export MIOSA_API_KEY="msk_u_..."

Both SDKs read MIOSA_API_KEY from the environment, so a server or a worker needs nothing else. See API keys for scopes and how to create keys in the console.

Step 2: Create the resources

The CLI can list the harnesses and models available to your organization:

miosa agent harnesses

Step 3: Wire the agent loop

On the machine, a one-liner is enough to run a saved agent: miosa agent run reviewer --sandbox harness-box "review the diff".

Step 4: Preview

A Preview is a throwaway public URL for a port inside the machine. Start the app as a background process so it survives the CLI disconnecting, then expose its port.

Open the exact Preview URL MIOSA returns.

Step 5: Deploy

Publish the machine to an immutable Deployment. Give it the source machine, the path the app lives at inside it, and the command that serves it.

Publishing the same deployment name again creates a new immutable version and keeps the same URL. Roll back with miosa deploy rollback cli-agent --to <version-id>, and inspect a live app with miosa deploy logs cli-agent -n 100. See Publishing and Rollback.

Step 6: Custom domain

Attach a domain your customer owns to the deployment. The platform URL keeps working while DNS propagates.

miosa deploy domain-add cli-agent app.example.com
miosa deploy domains cli-agent          # shows the DNS record and verification target
miosa deploy domain-verify cli-agent <domain-id>

Copy the exact DNS record MIOSA shows into the customer’s DNS provider; for a subdomain it is normally a CNAME. Once verified and TLS is active, MIOSA routes the domain to the deployment’s active version. In code, read the URL from the publish response instead of building it: the SDK method is miosa.deployments.domains.add(deploymentId, { domain }) (TypeScript) or miosa.deployments.domains(deployment_id).add(domain=...) (Python). See Domains.

Costs and limits

Everything bills while it runs: machines (sandboxes and computers) by the second, managed databases while running, and deployments when they serve. Pausing a machine stops compute billing but keeps disk. Set an --idle-timeout or a --ttl so a forgotten machine cannot run forever, and cap spend with rate limits and per-workspace quotas.

Next steps

Was this page helpful?