[{"data":1,"prerenderedAt":361},["ShallowReactive",2],{"navigation_docs":3,"-reference-sandbox-providers":168,"-reference-sandbox-providers-surround":358},[4,146],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":36},"Guide","i-lucide-book-open","\u002Fguide","1.guide",[10,14,37,55,59,63,67,71,75,79,83,87,109,134,138,142],{"title":11,"path":12,"stem":13},"What is Agent Zero?","\u002Fguide\u002Fintroduction","1.guide\u002F1.introduction",{"title":15,"icon":16,"path":17,"stem":18,"children":19,"page":36},"API","i-lucide-plug","\u002Fguide\u002Fapi","1.guide\u002F10.api",[20,24,28,32],{"title":21,"path":22,"stem":23},"API overview","\u002Fguide\u002Fapi\u002Foverview","1.guide\u002F10.api\u002F1.overview",{"title":25,"path":26,"stem":27},"Define endpoints","\u002Fguide\u002Fapi\u002Fdefine-endpoints","1.guide\u002F10.api\u002F2.define-endpoints",{"title":29,"path":30,"stem":31},"Use the API from a client","\u002Fguide\u002Fapi\u002Fuse-from-client","1.guide\u002F10.api\u002F3.use-from-client",{"title":33,"path":34,"stem":35},"Protect endpoints","\u002Fguide\u002Fapi\u002Fprotect-endpoints","1.guide\u002F10.api\u002F4.protect-endpoints",false,{"title":38,"icon":39,"path":40,"stem":41,"children":42,"page":36},"Authentication","i-lucide-lock","\u002Fguide\u002Fauthentication","1.guide\u002F11.authentication",[43,47,51],{"title":44,"path":45,"stem":46},"Authentication overview","\u002Fguide\u002Fauthentication\u002Foverview","1.guide\u002F11.authentication\u002F1.overview",{"title":48,"path":49,"stem":50},"GitHub OAuth","\u002Fguide\u002Fauthentication\u002Foauth","1.guide\u002F11.authentication\u002F2.oauth",{"title":52,"path":53,"stem":54},"Permissions","\u002Fguide\u002Fauthentication\u002Fpermissions","1.guide\u002F11.authentication\u002F3.permissions",{"title":56,"path":57,"stem":58},"Organizations","\u002Fguide\u002Forganizations","1.guide\u002F12.organizations",{"title":60,"path":61,"stem":62},"Frontend","\u002Fguide\u002Ffrontend","1.guide\u002F13.frontend",{"title":64,"path":65,"stem":66},"Mails","\u002Fguide\u002Fmails","1.guide\u002F14.mails",{"title":68,"path":69,"stem":70},"Internationalization","\u002Fguide\u002Finternationalization","1.guide\u002F15.internationalization",{"title":72,"path":73,"stem":74},"Deployment","\u002Fguide\u002Fdeployment","1.guide\u002F16.deployment",{"title":76,"path":77,"stem":78},"Tech stack","\u002Fguide\u002Ftech-stack","1.guide\u002F2.tech-stack",{"title":80,"path":81,"stem":82},"Installation","\u002Fguide\u002Finstallation","1.guide\u002F3.installation",{"title":84,"path":85,"stem":86},"Environment variables","\u002Fguide\u002Fenvironment-variables","1.guide\u002F4.environment-variables",{"title":88,"icon":89,"path":90,"stem":91,"children":92,"page":36},"Codebase","i-lucide-folder-tree","\u002Fguide\u002Fcodebase","1.guide\u002F5.codebase",[93,97,101,105],{"title":94,"path":95,"stem":96},"Codebase structure","\u002Fguide\u002Fcodebase\u002Fstructure","1.guide\u002F5.codebase\u002F1.structure",{"title":98,"path":99,"stem":100},"Dependencies","\u002Fguide\u002Fcodebase\u002Fdependencies","1.guide\u002F5.codebase\u002F2.dependencies",{"title":102,"path":103,"stem":104},"Formatting and linting","\u002Fguide\u002Fcodebase\u002Fformatting-linting","1.guide\u002F5.codebase\u002F3.formatting-linting",{"title":106,"path":107,"stem":108},"Agent Skills","\u002Fguide\u002Fcodebase\u002Fagent-skills","1.guide\u002F5.codebase\u002F4.agent-skills",{"title":110,"icon":111,"path":112,"stem":113,"children":114,"page":36},"Architecture","i-lucide-layers","\u002Fguide\u002Farchitecture","1.guide\u002F6.architecture",[115,118,122,126,130],{"title":110,"path":116,"stem":117},"\u002Fguide\u002Farchitecture\u002Foverview","1.guide\u002F6.architecture\u002F1.overview",{"title":119,"path":120,"stem":121},"State machine","\u002Fguide\u002Farchitecture\u002Fstate-machine","1.guide\u002F6.architecture\u002F2.state-machine",{"title":123,"path":124,"stem":125},"Execution boundary","\u002Fguide\u002Farchitecture\u002Fexecution-boundary","1.guide\u002F6.architecture\u002F3.execution-boundary",{"title":127,"path":128,"stem":129},"Issue-to-PR workflow","\u002Fguide\u002Farchitecture\u002Fissue-to-pr","1.guide\u002F6.architecture\u002F4.issue-to-pr",{"title":131,"path":132,"stem":133},"Adding a capability","\u002Fguide\u002Farchitecture\u002Fadding-a-capability","1.guide\u002F6.architecture\u002F5.adding-a-capability",{"title":135,"path":136,"stem":137},"Repository policy","\u002Fguide\u002Fconfiguration","1.guide\u002F7.configuration",{"title":139,"path":140,"stem":141},"Safety model","\u002Fguide\u002Fsafety","1.guide\u002F8.safety",{"title":143,"path":144,"stem":145},"Database","\u002Fguide\u002Fdatabase","1.guide\u002F9.database",{"title":147,"icon":148,"path":149,"stem":150,"children":151,"page":36},"Reference","i-lucide-book-marked","\u002Freference","2.reference",[152,156,160,164],{"title":153,"path":154,"stem":155},"CLI","\u002Freference\u002Fcli","2.reference\u002F1.cli",{"title":157,"path":158,"stem":159},"Model providers","\u002Freference\u002Fmodel-providers","2.reference\u002F2.model-providers",{"title":161,"path":162,"stem":163},"Source-control providers","\u002Freference\u002Fsource-control-providers","2.reference\u002F3.source-control-providers",{"title":165,"path":166,"stem":167},"Sandbox providers","\u002Freference\u002Fsandbox-providers","2.reference\u002F4.sandbox-providers",{"id":169,"title":165,"body":170,"description":351,"extension":352,"links":353,"meta":354,"navigation":355,"path":166,"seo":356,"stem":167,"__hash__":357},"docs\u002F2.reference\u002F4.sandbox-providers.md",{"type":171,"value":172,"toc":345},"minimark",[173,186,191,288,292,303,306],[174,175,176,177,181,182,185],"p",{},"Agent Zero v0.3 defines the vendor-neutral lifecycle in ",[178,179,180],"code",{},"packages\u002Frunner",": provision a credential-free request, expose the resulting checkout only as a ",[178,183,184],{},"Runner",", stop it explicitly, and expire bounded leases. A provider adapter owns its client and credentials privately. No SDK response or secret is copied into agent state, task history, lease snapshots, or logs.",[187,188,190],"h2",{"id":189},"evaluation","Evaluation",[192,193,194,213],"table",{},[195,196,197],"thead",{},[198,199,200,204,207,210],"tr",{},[201,202,203],"th",{},"Provider",[201,205,206],{},"Relevant primitives",[201,208,209],{},"Fit",[201,211,212],{},"Adapter note",[214,215,216,240,258],"tbody",{},[198,217,218,228,231,234],{},[219,220,221],"td",{},[222,223,227],"a",{"href":224,"rel":225},"https:\u002F\u002Fvitehub.dev\u002F",[226],"nofollow","ViteHub",[219,229,230],{},"Workspace, Sandbox, KV, Queue, Workflow, Schedule",[219,232,233],{},"Strongest match for a portable control-plane vocabulary and persistent workspaces paired with isolated execution",[219,235,236,237,239],{},"Preferred first portability pilot. Keep Workspace identifiers inside the adapter and expose only ",[178,238,184],{}," operations.",[198,241,242,249,252,255],{},[219,243,244],{},[222,245,248],{"href":246,"rel":247},"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fsandbox\u002F",[226],"Cloudflare Sandbox",[219,250,251],{},"Workers, Durable Objects, Containers, command\u002Ffile lifecycle, persistent storage and backups",[219,253,254],{},"Strong deployment-native option for a Cloudflare control plane",[219,256,257],{},"Map one lease to a Durable Object\u002Fcontainer lifecycle. Inject bindings into the adapter; never serialize them.",[198,259,260,267,270,273],{},[219,261,262],{},[222,263,266],{"href":264,"rel":265},"https:\u002F\u002Fvercel.com\u002Fdocs\u002Fsandbox",[226],"Vercel Sandbox",[219,268,269],{},"Ephemeral Firecracker microVMs, commands, snapshots, network policy and explicit stop",[219,271,272],{},"Strong isolated execution option for a Vercel deployment",[219,274,275,276,279,280,283,284,287],{},"Map ",[178,277,278],{},"provision",", command\u002Ffile operations, and ",[178,281,282],{},"stop"," to ",[178,285,286],{},"@vercel\u002Fsandbox","; keep token\u002Fproject\u002Fteam configuration private to the adapter.",[187,289,291],{"id":290},"decision","Decision",[174,293,294,295,298,299,302],{},"The core does not select a vendor. ",[178,296,297],{},"SandboxProvider"," and ",[178,300,301],{},"RunnerPool"," are the stable boundary; deployment packages can add ViteHub, Cloudflare, or Vercel implementations without changing the agent or server procedures. The first production adapter should pilot ViteHub because its Workspace\u002FSandbox split most directly represents Agent Zero's need for a durable checkout plus replaceable execution. Cloudflare and Vercel remain deployment-specific adapters behind the same tests.",[174,304,305],{},"Every adapter must prove:",[307,308,309,324,327,330,333,339],"ul",{},[310,311,312,313,316,317,316,320,323],"li",{},"no credential appears in ",[178,314,315],{},"SandboxRequest",", ",[178,318,319],{},"SandboxLease",[178,321,322],{},"TaskResult",", stored task JSON, or captured output;",[310,325,326],{},"observe\u002Fsuggest mounts are mechanically read-only;",[310,328,329],{},"network policy is applied rather than merely recorded;",[310,331,332],{},"CPU, memory, command timeout, output, active-count, per-repository, and lease-duration limits are enforced;",[310,334,335,338],{},[178,336,337],{},"release"," is idempotent and an expiry sweep stops abandoned sandboxes;",[310,340,341,342,344],{},"repository reads, writes, git inspection, and commands still flow only through ",[178,343,184],{},".",{"title":346,"searchDepth":347,"depth":347,"links":348},"",2,[349,350],{"id":189,"depth":347,"text":190},{"id":290,"depth":347,"text":291},"Agent Zero v0.3 defines the vendor-neutral lifecycle in packages\u002Frunner: provision a credential-free request, expose the resulting checkout only as a Runner, stop it explicitly, and expire bounded leases. A provider adapter owns its client and credentials privately. No SDK response or secret is copied into agent state, task history, lease snapshots, or logs.","md",null,{},true,{"title":165,"description":351},"fnf3sUHeWafiFgCssPz_cLu-p2ntcj84Rs1N1G6HqCM",[359,353],{"title":161,"path":162,"stem":163,"description":360,"children":-1},"Agent Zero integrates with source-control platforms through packages\u002Fsource-control: a\nprovider-neutral boundary with one adapter per platform. The agent runtime consumes only shared\ncontracts (ReviewInput, FeedbackItem, PullRequestRef); provider payload shapes, URLs, IDs,\nevent names, and credentials never cross the boundary. One deployment may connect repositories\nfrom several providers at once: inbound deliveries are routed to the adapter that recognizes\ntheir headers, and each configured provider keeps its own webhook secret.",1787482153102]