Exec Sandbox MCP Server
by inhumanio.github.inhuman/mcp-execv0.5.4
Single exec tool running caller Python in a network-isolated locked-down sandbox.
context tax
queued
security
queued
cold start
queued
freshness
Maintained3mo ago
Install Exec Sandbox MCP server
Install in Claude Code
claude mcp add exec -e MCP_EXEC_AUTH_TOKEN='<mcp-exec-auth-token>' -- docker run -i --rm -e MCP_EXEC_AUTH_TOKEN docker.io/idconstruct/mcp-exec:v0.5.4Install in Cursor
{
"mcpServers": {
"exec": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"MCP_EXEC_AUTH_TOKEN",
"docker.io/idconstruct/mcp-exec:v0.5.4"
],
"env": {
"MCP_EXEC_AUTH_TOKEN": "<mcp-exec-auth-token>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"exec": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"MCP_EXEC_AUTH_TOKEN",
"docker.io/idconstruct/mcp-exec:v0.5.4"
],
"env": {
"MCP_EXEC_AUTH_TOKEN": "<mcp-exec-auth-token>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"exec": {
"type": "stdio",
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"MCP_EXEC_AUTH_TOKEN",
"docker.io/idconstruct/mcp-exec:v0.5.4"
],
"env": {
"MCP_EXEC_AUTH_TOKEN": "<mcp-exec-auth-token>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"exec": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"MCP_EXEC_AUTH_TOKEN",
"docker.io/idconstruct/mcp-exec:v0.5.4"
],
"env": {
"MCP_EXEC_AUTH_TOKEN": "<mcp-exec-auth-token>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| MCP_EXEC_TRANSPORT | — | — | MCP transport. Must be 'stdio' for direct docker/stdio use. |
| MCP_EXEC_DEFAULT_TIMEOUT_S | — | — | Default wall-clock timeout per exec, seconds. |
| MCP_EXEC_MAX_TIMEOUT_S | — | — | Maximum wall-clock timeout a caller may request, seconds. |
| MCP_EXEC_MAX_OUTPUT_BYTES | — | — | Cap on combined stdout/stderr before truncation. |
| MCP_EXEC_MAX_STDIN_BYTES | — | — | Cap on stdin passed to the sandboxed code. |
| MCP_EXEC_AUTH_TOKEN | — | yes | Optional X-MCP-AUTH token (http/sse transports only). |
Freshness
Maintained — last maintenance signal 3mo ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-07-20 · 3mo ago · GitHub
Latest release
no data · GitHub
Package published
no data · npm/PyPI
Registry entry updated
2026-07-20 · 3mo ago · official registry · v0.5.4
FAQ
›How do I install the Exec Sandbox MCP server in Claude Code?
Run: claude mcp add exec -e MCP_EXEC_AUTH_TOKEN='<mcp-exec-auth-token>' -- docker run -i --rm -e MCP_EXEC_AUTH_TOKEN docker.io/idconstruct/mcp-exec:v0.5.4. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Exec Sandbox require an API key?
Yes. It expects MCP_EXEC_AUTH_TOKEN, of which 1 is a secret.
›Can I use Exec Sandbox as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Exec Sandbox in the official MCP registry?
Yes, as io.github.inhuman/mcp-exec.
Alternatives to Exec Sandbox
Other code execution & sandboxes MCP servers.