Lightweight hosted runtime
No machine attached
Limited JavaScript, public HTTP where enabled, and granted tool calls. No general shell, filesystem, git, or browser.
Agent loop versus execution
When you choose an ExecWarden-hosted loop, ExecWarden keeps the transcript and run state. The execution choice decides whether the task gets only lightweight hosted tools or a customer-configured machine.
Lightweight hosted runtime
Limited JavaScript, public HTTP where enabled, and granted tool calls. No general shell, filesystem, git, or browser.
Connected execution environment
A VM, Docker environment, or local machine provides the files, shell, processes, git, browser, tests, containers, and network access configured for the task.
Connect it deliberately
A connected environment is a place to execute, not a blanket of ExecWarden policy. Decide what the machine exposes locally, attach it to the run that needs it, and keep external credentials behind tools supplied through ExecWarden where possible.
Customer configuration
The customer configures the VM, Docker host, or local machine, including its files, network reachability, installed software, and local secrets.
Run attachment
A hosted session can bind to a sandbox volume on configured capacity. External clients use their existing environment and connect to tools through ExecWarden MCP.
External credentials
A GitHub or SaaS credential held by ExecWarden follows grants and approvals. A separate token placed on the machine can be used outside that path.
Examples
Execution paths
Start persistent agent work with or without connected machine capacity.
Read moreConfigure the VM, Docker host, or local machine that will supply shell, files, processes, and network access.
Read moreSee which access ExecWarden controls and which access remains local to the execution environment.
Read moreGet started during beta
Use the app during beta, or open the docs and choose the first agent task you want to control.