Build a Claude Code-style CLI agent
~20 min TypeScript PythonWhat you’re building: a CLI coding agent: a terminal harness runs inside a persistent sandbox with the repo, packages, and shell it needs, and streams its work back.
Primitives you’ll use: Organization, Sandboxes, Agents, Deployments, Custom domains
What you’re building
Claude Code and Codex turn a prompt into code from the terminal. To offer that to your users as a product, run the harness inside a machine you control, not on their laptops: a sandbox with the repository, the toolchain, and the shell.
MIOSA ships harness definitions (Claude Code, Codex, OSA, or custom) and runs them against a machine. You dispatch a run, stream its tool calls and output, and collect the files and artifacts it created. The sandbox persists between turns, so a session has a real workspace, and it can be snapshotted or destroyed on demand.
The important architectural point: the agent works in the MIOSA machine. Your backend orchestrates; the files, commands, and artifacts live in the runtime.
What you need on MIOSA
Architecture
Step 1: Create an account and an API key
Install the CLI, sign in, and mint a key for your product. The secret is printed once; store it as an environment variable, never in code.
npm i -g @miosa/cli
miosa login
miosa whoami
miosa api-key create cli-agent-key --preset agent # prints the secret once
export MIOSA_API_KEY="msk_u_..." Both SDKs read MIOSA_API_KEY from the environment, so a server or a worker needs nothing else. See API keys for scopes and how to create keys in the console.
Step 2: Create the resources
The CLI can list the harnesses and models available to your organization:
miosa agent harnesses Step 3: Wire the agent loop
On the machine, a one-liner is enough to run a saved agent: miosa agent run reviewer --sandbox harness-box "review the diff".
Step 4: Preview
A Preview is a throwaway public URL for a port inside the machine. Start the app as a background process so it survives the CLI disconnecting, then expose its port.
Open the exact Preview URL MIOSA returns.
Step 5: Deploy
Publish the machine to an immutable Deployment. Give it the source machine, the path the app lives at inside it, and the command that serves it.
Publishing the same deployment name again creates a new immutable version and keeps the same URL. Roll back with miosa deploy rollback cli-agent --to <version-id>, and inspect a live app with miosa deploy logs cli-agent -n 100. See Publishing and Rollback.
Step 6: Custom domain
Attach a domain your customer owns to the deployment. The platform URL keeps working while DNS propagates.
miosa deploy domain-add cli-agent app.example.com
miosa deploy domains cli-agent # shows the DNS record and verification target
miosa deploy domain-verify cli-agent <domain-id> Copy the exact DNS record MIOSA shows into the customer’s DNS provider; for a subdomain it is normally a CNAME. Once verified and TLS is active, MIOSA routes the domain to the deployment’s active version. In code, read the URL from the publish response instead of building it: the SDK method is miosa.deployments.domains.add(deploymentId, { domain }) (TypeScript) or miosa.deployments.domains(deployment_id).add(domain=...) (Python). See Domains.
Costs and limits
Everything bills while it runs: machines (sandboxes and computers) by the second, managed databases while running, and deployments when they serve. Pausing a machine stops compute billing but keeps disk. Set an --idle-timeout or a --ttl so a forgotten machine cannot run forever, and cap spend with rate limits and per-workspace quotas.
- Pricing - plans, the published rate card, and the free Developer grant.
- Sizing and limits - machine sizes and what each costs to run.
- Timeouts and auto-stop -
--ttl,--idle-timeout, and pause/resume.