Platform Agents Docs Pricing Security Start building →
ovrin/agents
Agent environments

One API. Four coding agents, each with a real machine.

Every environment below is the same underlying sandbox — gVisor isolation, default-deny egress, a mounted /workspace — with a different agent CLI pre-installed and authenticated. Pick a template, pass a key, run.

Template reference

Every environment, one line of config.

Swap the template and the matching auth env var — everything else about the API is identical.

Claude Codeclaude-code · ANTHROPIC_API_KEY
Codexcodex · OPENAI_API_KEY
Gemini CLIgemini-cli · GEMINI_API_KEY
DeepSeek Harnessdeepseek-harness · DEEPSEEK_API_KEY
What's shared

Every environment gets the same guarantees.

01
gVisor isolation
Each sandbox runs in a kernel-isolated gVisor sandbox, not a shared-kernel container.
02
Default-deny egress
Nothing resolves except the hosts your policy allowlists — the agent's own API, your registry, your git host.
03
Nothing left behind
Kill the sandbox and the filesystem, process table and network state are gone. Memory persists only if you write it there.

Pick an agent. Ship today.

Self-service from the first minute. No demo call, no sales gate, no waitlist.

$pip install ovrin