Boring Computers
boringcomputers.com- Category
- Developer Tools
- Rank
- No. 982Tools index
- Pricing
- Open Source
- Type
- TOOL
- Use case
- Deployment & Operations
- Interfaces
- API
- Builder
- @Rasmic
- GitHub
- 335 stars
- Date
About
Boring Computers lets you spin up Firecracker microVMs in milliseconds — each with a terminal, full Linux desktop over VNC, real browser, and preinstalled coding agents like Claude and Codex. An AI agent can see the screen and drive mouse and keyboard, making it ideal for automated coding, research, or sandboxed compute tasks. It's fully open-source and self-hostable with your own API keys.
What it does
Boring Computers boots real Linux virtual machines, hardware isolated with a kernel of their own via Firecracker, and hands the machine to an AI agent to work in. Each one offers a shell, or a full graphical session reachable over VNC with a browser and a terminal carrying assistants like Claude and Codex. An agent drives the screen with clicks and keystrokes, or writes and runs code and gets a live URL to what it built. Machines restore from a snapshot in milliseconds and clone mid-session so attempts branch from one checkpoint. Reach it via a command-line tool, a TypeScript library, a REST and WebSocket API, or an MCP server.
Why it's ranked here
A Go host daemon, an Effect-based TypeScript control plane with billing, auth and audit services, a typed SDK, a CLI and an MCP server all ship together under Apache 2.0: this is a real, working system, not a demo wrapper. What keeps it from ranking higher is the gap between the catalogue promise and the current repository: the one-command self-hosted installers have been retired, and the only supported way to run your own instance now depends on one bare-metal hosting provider's signed release process. The project also describes itself as pre-public-beta with a security checklist still outstanding.
What's good
Isolation is the real kind: each machine gets its own kernel under hardware virtualization rather than sharing one with a container, and the guest control channel runs over a virtual socket instead of the network, so nothing needs a guest IP to be reachable. Cloning a running machine takes about 35 milliseconds and copies its live state, cheap enough to fork attempts from one checkpoint and keep whichever works. The client library is typed end to end, with explicit schemas for machines, volumes and templates, and it ships alongside a CLI and an MCP server, so a script and an AI assistant can drive the same machine through one contract.
Tradeoffs
The self-hosting story is narrower than it looks. The old SSH-based Linux installer and the Apple Silicon installer used to build a host from source in one command; both now just print a pointer to a runbook, because host setup only accepts signed images through one bare-metal hosting vendor's enrollment flow. Guests are Linux only, a deliberate low-level choice in the agent binary. The natural-language agent that writes and runs code for you is switched off on the managed cloud entirely, pending centralized credential and cost controls; only direct command execution works there today. Network egress allowlisting for managed machines is defined in the API but reserved, not yet enabled.
How to use it well
This fits a team building an agent that needs an actual computer, not just a function sandbox: a coding agent that should see a real browser and terminal, or one that benefits from cloning parallel attempts and keeping the best. Plug it into an existing MCP-capable assistant through the bundled server for a fast start, or use the typed client library for programmatic control with retries and idempotency handled. Because the do-it-yourself installers are gone, plan on the managed cloud or the vendor-specific bare-metal runbook, not a laptop or an arbitrary server. Skip it if you need non-Linux guests, or a compute layer with no dependency on one host provider.
Technical notes+
guest-agent/main.go implements the in-guest control channel directly on the Linux AF_VSOCK socket API rather than TCP, with a single agentServer holding a bounded connection semaphore so concurrent terminal sessions cannot exceed capacity. nehemiahd/server.go separates two auth models behind one mux: a legacy bearer-token API for local/self-hosted mode and a managed-host path (NehemiahMode) where every data-plane route also requires a per-machine lease header checked with subtle.ConstantTimeCompare, and where URL-embedded tokens are rejected outright. apps/nehemiah/src/main.ts is the Effect-based control plane; it wires Postgres, S3-compatible object storage for templates and volumes, Stripe billing, and Clerk-issued sessions into typed services (MachineService, TemplateService, VolumeService) and only constructs the volume-storage adapter when both an object-storage config and a volumeBroker secret are present, otherwise the API keeps a typed 503. packages/sdk/src/index.ts defines the wire contract with effect Schema structs for Machine, Volume and Template responses and exports hard caps including MAX_FILE_TRANSFER_BYTES (16 MiB) and MAX_TTY_FRAME_BYTES (64 KiB). packages/cli/src/index.ts binds a stored API key or device-login session to the specific API origin it was issued against and throws CredentialOriginError rather than silently reusing it against a different URL. packages/mcp/index.mjs exposes launch_computer, run_command, run_task, screenshot, preview_url, extend_computer, fork_computer, publish_computer, list_templates and list_computers as MCP tools, and explicitly disables run_task's local LLM path when targeting the managed cloud. docs/architecture.md documents the boot sequence (cp --reflink=auto rootfs copy, raw Firecracker API calls, a NEHEMIAH_READY serial marker) and a WRAP/OWN/RENT dependency map naming Neon, Clerk, Stripe and Latitude.sh as external dependencies. docs/nehemiah/api-contract.md states the OpenAPI 3.1 document is generated from the control plane's own route definitions and checked by a route-inventory test that fails on drift.
Observed
- License
- Apache-2.0
- Stack
- Go host daemon; Effect-based TypeScript control plane; SvelteKit web app; npm/Turborepo monorepo
- Interfaces
- CLI, TypeScript SDK, REST + WebSocket API, MCP server
- Packaging
- SDK and MCP server published as installable npm packages
- Guest platform
- Guest operating system is Linux only
- Self-hosting path
- One-command self-hosted installers are retired; the supported path provisions a managed bare-metal host from a signed release
- Control-plane dependencies
- Stripe for billing, Clerk for auth, Neon Postgres, and R2/S3-compatible object storage
Read from README.md, package.json, gateway/main.go, guest-agent/main.go, nehemiahd/main.go, nehemiahd/server.go, packages/mcp/index.mjs, apps/nehemiah/src/main.ts, docs/architecture.md, packages/cli/src/index.ts, packages/sdk/src/index.ts, docs/nehemiah/api-contract.md.
What it can do
Spin up isolated Linux virtual machines on demand
Single HTTP API call → Running Firecracker microVM with full Linux environment, ready in milliseconds
Provide a remote Linux desktop session
Launched microVM instance → Full Linux desktop accessible via VNC connection
Execute automated coding tasks using AI agents
Coding task or prompt sent to preinstalled agents (Claude, Codex) → Generated, executed, or modified code within the sandboxed VM
Enable AI agents to control a browser visually
Task instructions for the AI agent → AI-driven mouse and keyboard interactions within a real browser session
Run sandboxed compute or research tasks in isolation
User-defined scripts, prompts, or workloads → Task results executed inside an isolated, disposable VM environment
Self-host the platform on your own infrastructure
KVM-capable Linux server with Anthropic and S3 API keys → Fully operational self-hosted microVM platform using your own credentials
Access a terminal inside a running VM
Launched microVM instance → Interactive shell terminal for command-line operations within the VM
Tags
Tech Stack
Media

Comments (0)
No comments yet
Editorially curated, with community endorsements as a secondary signal. Corrections welcome.