Run Skyvern on MIOSA
~15 min TypeScript PythonWhat you’re building: Open-source browser automation that drives real sites with vision.
Primitives you’ll use: Sandbox, Postgres
Agent prompt
Start with your coding agent
Choose how you will use it. The brief installs and runs the real tool on MIOSA, then shapes it for your team or your customers. Copy it into OSA, Claude Code, Codex, or Cursor.
Template coming soon1 What are you building?
Leave it empty and your agent will propose 3 names, pick one, and use it for resources, the domain and branding.
3 Configure
Reference tool
Skyvern, by Skyvern AI (https://www.skyvern.com): open-source browser automation that uses vision and a model to drive websites and complete workflows without brittle selectors.
How it works: Skyvern reads a page with vision and a model, then acts on it (click, type, extract) to complete a multi-step workflow; the same workflow can be applied to a different site.
Key capabilities:
Vision plus model control of a page
Reusable multi-step workflows
Structured extraction with schemas
Handles 2FA and password managers
Open source
You will install and RUN the real Skyvern (open source (AGPL-3.0)). Read its docs first: https://github.com/Skyvern-AI/skyvern. Every install command below comes from them; if the docs and this brief disagree, the docs win.
How it runs on MIOSA
Where it runs -> a MIOSA sandbox (an isolated Linux workspace)
State and files -> Workflows, runs and screenshots live in the database; keep the SQLite file or your managed Postgres reachable and the work survives a pause.
Model -> your own provider key, never a MIOSA platform key
Its web port 8080 -> a MIOSA preview URL (`miosa preview create`)
Your customers -> one workspace each, isolated from each other
Goal
Install and run Skyvern on a MIOSA sandbox, so it can serve my customers. Each customer is isolated in its own workspace; I meter usage and bill them.
Product name: propose 3 product names, pick one, and use it for resource names, the domain and branding. Until you pick, <product-name> stands for it in the commands below.
Scale: a prototype.
Set up
npm i -g @miosa/cli
miosa login && miosa whoami
miosa api-key create <product-name>-key --preset agent
export MIOSA_API_KEY="msk_u_..."
miosa org
Resources
Sandbox: the agent's isolated Linux workspace
miosa create <product-name>-box --wait
Managed Postgres
miosa api POST /databases -d '{"name":"<product-name>-db","engine":"postgresql"}'
Auth and tenancy
Your organization is the platform; customers never get a MIOSA account, they sign into YOUR product. One workspace per customer, created as they onboard, isolates their machines, runs and data.
miosa workspace create <product-name>-customer-1
Tag every machine and run with the customer id in `metadata`, and never query across customers. Meter usage per customer with GET /api/v1/usage and set who pays with PUT /api/v1/bill-to (/docs/platform/usage-and-billing).
Install Skyvern
Run these inside the sandbox (for example `miosa exec <product-name>-box -- bash -lc '<command>'`), in order. The commands are from the official docs.
python3 --version # Python 3.11 or later is recommended
pip install "skyvern[all]"
Check: the install finishes without errors; the next sections configure and start it.
Configure
Add your own model key (OPENAI_API_KEY, ANTHROPIC_API_KEY or GEMINI_API_KEY) so Skyvern can reason about the page.
The pip path defaults to SQLite; point it at a managed Postgres with `skyvern quickstart --database-string=postgresql+psycopg://<user>:<pass>@<host>:5432/<db>` when you need one.
Model: Anthropic (Claude). Calls use my own provider key (ANTHROPIC_API_KEY); MIOSA platform keys are never used.
export ANTHROPIC_API_KEY="..." # set it in the process environment, or the Secrets API; never write it into files you commit
Run it
Start it and prove it works.
skyvern quickstart
skyvern status
Scripted, non-interactive use (what a product or a queue would call):
skyvern run server # the API without the UI, for your own task queue
Check: a headless task completes and prints a result.
Persistence and access
Workflows, runs and screenshots live in the database; keep the SQLite file or your managed Postgres reachable and the work survives a pause.
It listens on port 8080. Run it as a background process so it outlives your shell, then open a preview:
miosa preview create <product-name>-box 8080 --name web
Check: the preview URL answers, and still answers after the machine pauses and resumes (previews wake it on request).
Make it a product
One Skyvern instance per customer workspace (or a pool with a task queue) behind your own API keys; never expose the raw UI publicly.
Limits and costs
Pin the version you tested and update deliberately; these tools change quickly.
Give the tool only the credentials it needs, as secrets, not baked into files.
Prototype: keep it to one machine at the default size, skip replicas and custom hostnames you do not need, and delete everything when you are done.
Acceptance checks
Skyvern runs on a MIOSA sandbox and answers a real task.
State survives a pause and resume.
Each customer has its own workspace and its own instance; nothing is shared between them.
Everything it created can be deleted with nothing left running.
What your choices added
- Build a product. a workspace per customer, per-customer metering and bill-to
- Agent suggests a name. proposes 3 product names and picks one; commands use <product-name>
- Model: Anthropic. your own provider key
- Prototype. one small machine, no extras, easy to delete
- Postgres. already part of this guide
What you're building
open-source browser automation that uses vision and a model to drive websites and complete workflows without brittle selectors Modelled on Skyvern, by Skyvern AI.
Skyvern reads a page with vision and a model, then acts on it (click, type, extract) to complete a multi-step workflow; the same workflow can be applied to a different site.
Primitives you'll use: Sandbox · Postgres
- Vision plus model control of a page
- Reusable multi-step workflows
- Structured extraction with schemas
- Handles 2FA and password managers
- Open source
You install and run the real Skyvern on MIOSA. Read the official docs first: github.com/Skyvern-AI/skyvern. Every install command below comes from them; if the docs and this guide disagree, the docs win. Skyvern is open source (AGPL-3.0).
What you need on MIOSA
Each row is one thing to create before you start. The number matches the step that uses it.
- Organization and API key Scopes every call; a workspace key is all a worker needs.
miosa api-key create app-key --preset agentDocs - Sandbox The isolated Linux workspace the agent writes code and runs commands in.
miosa create app-box --template nextjs --waitDocs - Postgres Managed relational data, injected as DATABASE_URL in the machine and in production.
miosa api POST /databases -d '{"name":"app-db","engine":"postgresql"}'Docs - A workspace per customer Isolates each customer’s machines, deployments, and data as they onboard.
miosa workspace create customer-1Docs - Branding and white-label Your name and slug on previews, deployments, and the desktop; customers never see MIOSA.
miosa orgDocs - Usage metering and bill-to Usage per customer, and which account pays for new machines.
miosa org billDocs
Architecture
How it runs on MIOSA
Where it runs -> a MIOSA sandbox (an isolated Linux workspace)
State and files -> Workflows, runs and screenshots live in the database; keep the SQLite file or your managed Postgres reachable and the work survives a pause.
Model -> your own provider key, never a MIOSA platform key
Its web port 8080 -> a MIOSA preview URL (`miosa preview create`)
Your customers -> one workspace each, isolated from each other
Auth and tenancy
Your organization is the platform; customers never get a MIOSA account, they sign into YOUR product. One workspace per customer, created as they onboard, isolates their machines, runs and data.
miosa workspace create skyvern-customer-1Tag every machine and run with the customer id in `metadata`, and never query across customers. Meter usage per customer with GET /api/v1/usage and set who pays with PUT /api/v1/bill-to (/docs/platform/usage-and-billing).
Install Skyvern
Run these inside the sandbox (for example `miosa exec skyvern-box -- bash -lc '<command>'`), in order. The commands are from the official docs.
python3 --version # Python 3.11 or later is recommendedpip install "skyvern[all]"Check: the install finishes without errors; the next sections configure and start it.
Configure
Add your own model key (OPENAI_API_KEY, ANTHROPIC_API_KEY or GEMINI_API_KEY) so Skyvern can reason about the page.
The pip path defaults to SQLite; point it at a managed Postgres with `skyvern quickstart --database-string=postgresql+psycopg://<user>:<pass>@<host>:5432/<db>` when you need one.
Model: Anthropic (Claude). Calls use my own provider key (ANTHROPIC_API_KEY); MIOSA platform keys are never used.
export ANTHROPIC_API_KEY="..." # set it in the process environment, or the Secrets API; never write it into files you commitRun it
Start it and prove it works.
skyvern quickstartskyvern statusScripted, non-interactive use (what a product or a queue would call):
skyvern run server # the API without the UI, for your own task queueCheck: a headless task completes and prints a result.
Persistence and access
Workflows, runs and screenshots live in the database; keep the SQLite file or your managed Postgres reachable and the work survives a pause.
It listens on port 8080. Run it as a background process so it outlives your shell, then open a preview:
miosa preview create skyvern-box 8080 --name webCheck: the preview URL answers, and still answers after the machine pauses and resumes (previews wake it on request).
Make it a product
One Skyvern instance per customer workspace (or a pool with a task queue) behind your own API keys; never expose the raw UI publicly.
Limits and costs
Pin the version you tested and update deliberately; these tools change quickly.
Give the tool only the credentials it needs, as secrets, not baked into files.
Prototype: keep it to one machine at the default size, skip replicas and custom hostnames you do not need, and delete everything when you are done.
Acceptance checks
Skyvern runs on a MIOSA sandbox and answers a real task.
State survives a pause and resume.
Each customer has its own workspace and its own instance; nothing is shared between them.
Everything it created can be deleted with nothing left running.