npm i -g hotcell

npm i -g hotcell

Open-source CLI that runs isolated sandboxes for AI coding agents on your own Mac, Linux box, or bare-metal server.

66/100MonitorFree planFreemium

If your threat model is "I don't want an agent's sandbox to hold my real LLM or GitHub keys," hotcell is one of the few open-source tools that addresses it directly: with `--egress`, a cell holds only a short-lived per-sandbox token while the real key stays on the host. It is Apache-2.0, runs on hardware you own, and supports Docker plus Firecracker and Apple VZ for VM-grade isolation. It is also early: 17 GitHub stars, 264 commits, a README-first documentation story, and no public pricing page or hosted tier. Compare against managed cloud sandboxes such as E2B or Cloudflare's Sandbox SDK if you want turn-key convenience and someone else to run the fleet; pick hotcell if you want the fleet

Verified 15d ago · liveness 66/100 · cite: rightaichoice.com/tools/npm-i-g-hotcell

Best for
  • AI engineers running multiple coding agents in parallel
  • Security researchers who need egress-controlled agent execution
  • Teams already on bare metal, colima, OrbStack or podman
  • Open-source projects comfortable self-hosting an Apache-2.0 CLI
Not ideal for
  • Teams that want a managed cloud sandbox with someone else running the fleet
  • Non-technical users who need a graphical interface
  • Buyers who require a support contract, SLA or vendor pricing page
Visit Website

IntermediateSolo engineer on a Mac with Docker already installed: roughly 30 seconds for the guided first-run, then a few minutes to add keys and create your first cell. Bare-metal or cloud-VM Linux hosts take longer — Docker, KVM/Firecracker and the DOCKER_HOST export (for colima, OrbStack or podman) need to be in place before `hotcell start`, so budget an hour for a first clean fleet.Desktop · CLINo public APIVerified 15d ago
Pricing
Free plan
FreemiumFree tier5 hidden costs
Learning curve
Intermediate
Solo engineer on a Mac with Docker already installed: roughly 30 seconds for the guided first-run, then a few minutes to add keys and create your first cell. Bare-metal or cloud-VM Linux hosts take longer — Docker, KVM/Firecracker and the DOCKER_HOST export (for colima, OrbStack or podman) need to be in place before `hotcell start`, so budget an hour for a first clean fleet.
Runs on
DesktopCLI
No public API · 6 integrations
Who it's for
Solo AI engineer with a Mac MiniSecurity researcher on bare metal LinuxPlatform team on a shared cloud VM
Live sentiment
Is npm i -g hotcell actually worth it?

We scan live Reddit threads, YouTube comments, X posts, G2 reviews and other communities — and hand you an honest verdict in under a minute.

  • Honest verdict, not marketing
  • Real pros & cons from real users
  • Attributed quotes with receipts
Run a free scan

3 free scans · no card needed

Skip it if

Skip hotcell if you want a managed, turn-key cloud sandbox with vendor support and a pricing page rather than a self-hosted Apache-2.0 CLI you run on your own Mac, Linux box or bare metal.

The 30-second take
Biggest gripe

The hardware is the bill: admission control refuses to over-subscribe, so adding more parallel cells means buying or renting a bigger machine, not clicking a plan upgrade.

Price reality

No pricing tiers are published for hotcell — it is an Apache-2.0 CLI you install from npm, so the real cost is the hardware you point it at. That puts it below per-seat managed sandboxes such as E2B or Cloudflare Sandbox SDK on license spend while shifting cost into your own machines and ops time. Cheapest at small scale, and the economics improve the more cells one box can hold.

In short

npm i -g hotcell — Open-source CLI that runs isolated sandboxes for AI coding agents on your own Mac, Linux box, or bare-metal server. Best for AI engineers running multiple coding agents in parallel, Security researchers who need egress-controlled agent execution, Teams already on bare metal, colima, OrbStack or podman. Free to use.

What people actually say about npm i -g hotcell — is it worth it?

We ran a structured research pass across product reviews, community discussions, and post-purchase forum threads to surface the patterns vendors won't publish themselves. Below: the recurring strengths, the hidden costs people mention most, and the cohort that consistently regrets adopting this tool.

5 mentions across 1 source (Product Hunt) · researched Aug 6, 2026.

60% positive40% critical

Average across the 1 source that answered — each source counts once, not each post.

Recurring strengths
  • +Local sandboxing keeps data and processing on premise, enhancing privacy.
  • +Per-sandbox scoped tokens are a clean, secure way to handle API keys.
  • +Open source under Apache 2.0 allows self-hosting and customization.
  • +Runs on Mac, Linux, and bare metal, offering deployment flexibility.
  • +Low latency from local execution is a likely benefit, though unverified.
Recurring frustrations
  • −Very little public feedback; questions about isolation model go unanswered.
  • −No performance benchmarks shared, leaving overhead concerns unresolved.
  • −Project is only two months old, with an unproven track record.
  • −Lack of third-party reviews or audits could worry security-conscious users.
  • −Community is tiny, limiting community support and shared knowledge.
Patterns worth knowing
Curiosity about the isolation model and performance overhead
Seen on Product Hunt
Appreciation for the security-focused design, especially scoped tokens
Seen on Product Hunt
Excitement about the open-source, local-first approach
Seen on Product Hunt
Learning curve
intermediateProductive in ~A few hours (setup and configuration)
Hidden costs people mention
  • • Potential infrastructure costs for bare metal
  • • Time investment for setup and maintenance

Viability Score

66/100
Monitor

How well maintained and how widely used is npm i -g hotcell? Built from what the vendor actually publishes (docs, changelog, tutorials, integrations, pricing), whether the site is live, and how much real users discuss it. How we calculate this

Recent activity
not measured
Traction
72
Site health
95
User sentiment
60
What the vendor publishes
40

Last calculated: September 2026

How we score →

Key Features

  • npm-installable CLI (`npm i -g hotcell`) with a 30-second guided first-run setup
  • Per-sandbox keys: gateway swaps a short-lived per-cell token for the real host key
  • `hotcell keys add` for storing provider keys (e.g. openrouter) on the host only
  • `hotcell keys import .env` with per-variable gateway / inject / skip choice
  • Optional default-deny egress, kernel-enforced on Linux and microVMs
  • Docker runtime support across Mac and Linux
  • Firecracker microVMs on Linux/KVM for VM-grade isolation
  • Apple VZ microVMs on macOS for VM-grade isolation
  • Multiple cells per host with live CPU, memory and cost per sandbox
  • Admission control that refuses to over-subscribe instead of OOM-ing the host
  • `hotcell create -n 5 --repo ... --branch` for parallel isolated cells
  • Branch-per-cell cloning with auto branch naming (feat-1 … feat-5)
  • `hotcell terminal <id>` interactive shell inside a cell
  • `hotcell run --setup "..." "..."` one-shot create → run → destroy
  • `hotcell rm --all` teardown without touching your source repo

About npm i -g hotcell

FreemiumIntermediateNo APIDesktop · CLI

Hotcell is a self-hostable sandbox SDK and CLI, described by its author as "inspired by Cloudflare Sandbox SDK," that spins up isolated environments for AI coding agents on hardware you already own — a Mac Mini on your desk, a cloud VM, or a bare-metal box. You install it with `npm i -g hotcell`; the first run walks you through a 30-second guided setup before starting a live fleet of sandboxes. The core pitch is credential separation: with the `--egress` gateway, a sandbox only ever holds a short-lived per-cell token, so your OpenRouter or GitHub keys stay on the host and never enter a cell. LLM calls route through hotcell's gateway (metered, spend-capped, revocable) and each cell's git origin is wired through it automatically, so `git push` works without keys in the sandbox. A single daemon runs as many cells as the hardware allows, with live CPU, memory and cost per sandbox and admission control that refuses to over-subscribe rather than OOM the box. It supports containers via Docker everywhere, plus Firecracker (Linux/KVM) and Apple VZ (macOS) for VM-grade isolation behind one interface, alongside optional default-deny egress that is kernel-enforced on Linux and microVMs and advisory on macOS Docker. Practical commands include `hotcell create -n 5 --repo ... --branch`, `hotcell terminal <id>`, `hotcell run --setup "pip install ruff" "ruff check ."` for a one-shot create-run-destroy, and `hotcell rm --all`. This is a developer tool aimed at AI engineers and security researchers who need reproducible, auditable agent execution without cloud dependency — not a hosted turn-key product.

Behind the Verdict

Hotcell's differentiator is not the sandbox — Docker, Firecracker and Apple VZ already exist — it is the gateway that sits between the sandbox and the outside world. The `hotcell keys import .env` flow makes you decide, per variable, whether it goes to the gateway (real key stays on host, sandbox gets a per-sandbox token), is injected (real value copied into every sandbox), or is skipped. That single decision tree is the security model, and it is honest about its limits — the README notes the gateway has boundaries. Egress control is stronger on Linux and microVMs, where it is kernel-enforced, than on macOS Docker, where the README describes it as advisory. That distinction matters if you are running untrusted code on a laptop. Where hotcell is genuinely convenient: `hotcell create -n 5 --name feat --branch auto --opencode --repo https://github.com/you/app` produces five cells, each with the repo cloned onto its own branch (feat-1 … feat-5), OpenCode preinstalled and pointed at the gateway, and git origin wired through so pushes work keylessly. Live per-cell provisioning progress means slow setups don't falsely time out, which is a real papercut in scripted sandbox tools. Resource handling is the other strong point: one daemon with live CPU/mem/cost per sandbox and admission control that refuses to over-subscribe instead of OOM-ing the machine. The weaknesses are maturity and operability. Documentation lives largely in the README plus a docs/ directory in the repo, with benchmarks measured using the ComputeSDK harness and dax's OpenCode benchmark. There is no public changelog page, no pricing page, and no hosted option captured in the scrape — you are self-hosting or not using it. Docker socket quirks are on you: if you run colima, OrbStack or podman on a non-default socket, hotcell reads DOCKER_HOST rather than the docker CLI's context, so you export it before `hotcell start`. If you want a managed fleet, a support contract, or a GUI, this is the wrong tool. If you want five isolated agents chewing on one repo and your keys never in the cell, it is a credible, Apache-2.0 option.

Researching npm i -g hotcell? Get your full AI stack in 60 seconds.

Free, no signup — tell us your goal and get tools matched to your budget & existing stack.

Real-world workflow fit

Concrete scenarios for the personas npm i -g hotcell actually fits — and what changes day-one when you adopt it.

Solo AI engineer with a Mac Mini

Installs with `npm i -g hotcell`, runs the 30-second guided setup, adds an OpenRouter key with `hotcell keys add openrouter`, then creates five cells on one repo using `hotcell create -n 5 --name feat --branch auto --opencode`.

Outcome: Five isolated branches (feat-1 … feat-5) with OpenCode preinstalled; he opens a terminal per cell, runs a different agent task in each, and finishes with `hotcell rm --all` leaving the repo untouched.

Security researcher on bare metal Linux

Runs untrusted agent-generated code and needs egress locked down, so relies on default-deny egress that the README describes as kernel-enforced on Linux and microVMs, with Firecracker for VM-grade isolation.

Outcome: Agent processes run in microVM-isolated cells, LLM calls are metered and spend-capped through the gateway, and the host API keys are never present inside a cell.

Platform team on a shared cloud VM

Runs one hotcell daemon on a large VM to host many parallel cells, watching live CPU, memory and per-sandbox cost and letting admission control refuse to over-subscribe the machine.

Outcome: Agents queue instead of OOM-ing the box, and the team can see per-cell spend rather than discovering it on a provider invoice.

Use Cases

  • Run five isolated agents on one repo, each on its own branch, from a single machine
  • Keep LLM provider keys on the host so a compromised or misbehaving cell never sees them
  • Meter and spend-cap agent LLM calls through the gateway
  • Execute untrusted agent-generated code under default-deny egress on Linux or microVMs
  • Reproduce agent runs on bare metal or a desk Mac Mini without a cloud sandbox account
  • Use `hotcell run --setup "pip install ruff" "ruff check ."` for throwaway lint/CI style checks
  • Push agent work back to GitHub keylessly through the gateway-wired git origin
  • Work air-gapped or offline on hardware you control

Limitations

  • Hotcell is early-stage and self-hosted: the scrape shows 17 GitHub stars, 264 commits and one open issue, and documentation lives mainly in the repo README plus a docs/ folder rather than a dedicated docs site.
  • There is no public pricing page, no hosted tier and no changelog page captured, so there is no vendor SLA or support contract to lean on.
  • Isolation strength varies by platform — the README describes default-deny egress as kernel-enforced on Linux and microVMs but advisory on macOS Docker, so Mac users running hostile code get weaker guarantees.
  • Setup is CLI-only and assumes Docker knowledge; on non-default Docker sockets you must export DOCKER_HOST (for example unix://$HOME/.colima/default/docker.sock for colima) because hotcell does not read the docker CLI context.
  • No GUI, no built-in collaboration features, and no captured third-party integrations beyond Docker, Firecracker, Apple VZ, OpenCode, OpenRouter and GitHub.

as of 2026-09-14

Verification history

We have re-verified npm i -g hotcell 3 times since . Each pass re-reads the vendor's own pages and re-checks every listed field against that evidence; passes where nothing had changed are marked as such.

  1. — re-checked, vendor evidence unchanged
  2. — re-checked, vendor evidence unchanged
  3. — re-checked, vendor evidence unchanged

Free to cite with attribution — this page re-verifies continuously.

Hidden costs & gotchas

What the public pricing page doesn't put in bold. Captured from pricing-page footnotes, contract terms, and recurring complaints.

  • The hardware is the bill: admission control refuses to over-subscribe, so adding more parallel cells means buying or renting a bigger machine, not clicking a plan upgrade.
  • Anything you mark as 'inject' during `hotcell keys import .env` copies the real credential into every sandbox — convenient, but it silently gives up the key-isolation benefit you came for.
  • On macOS with Docker, egress is advisory rather than kernel-enforced, so the default-deny protection you may be budgeting for only fully applies on Linux and microVMs.
  • Self-hosting means you own upgrades, Docker socket fixes and on-call — there is no vendor pricing page or support tier captured to offload that.
  • Non-default Docker runtimes (colima, OrbStack, podman) require setting DOCKER_HOST yourself, which is unpaid setup time before your first cell runs.

Where the pricing makes sense

The company stage and team size where npm i -g hotcell's pricing actually pencils out — and where peers do it cheaper.

No pricing tiers are published for hotcell — it is an Apache-2.0 CLI you install from npm, so the real cost is the hardware you point it at. That puts it below per-seat managed sandboxes such as E2B or Cloudflare Sandbox SDK on license spend while shifting cost into your own machines and ops time. Cheapest at small scale, and the economics improve the more cells one box can hold.

Setup time & first value

How long it actually takes to get something useful out of npm i -g hotcell — broken out by persona, not the marketing-page minute.

Solo engineer on a Mac with Docker already installed: roughly 30 seconds for the guided first-run, then a few minutes to add keys and create your first cell. Bare-metal or cloud-VM Linux hosts take longer — Docker, KVM/Firecracker and the DOCKER_HOST export (for colima, OrbStack or podman) need to be in place before `hotcell start`, so budget an hour for a first clean fleet.

Switching to or from npm i -g hotcell

How to bring data in from common predecessors and how to get it back out — written for the switcher, not the buyer.

Migrating in
  • →From Cloudflare Sandbox SDK: the README describes hotcell as inspired by it, so port the sandbox lifecycle calls to hotcell's `create` / `terminal` / `rm` CLI verbs.
  • →From E2B or another hosted cloud sandbox: install the CLI, run the guided setup, then recreate each hosted template as a local cell using `docker` or Firecracker / Apple VZ runtimes.
Migrating out
  • ↗To E2B or a managed cloud sandbox: export the setup scripts you run in cells and re-register them as templates, then drop the local daemon.
  • ↗To plain Docker or Firecracker scripts: replace `hotcell create -n 5 --name feat --branch auto` with your own container/microVM orchestration per branch.

Integrations

DockerFirecrackerApple VZOpenCodeOpenRouterGitHub

Resources & Guides

Tools that pair well with npm i -g hotcell

Common stack mates teams adopt alongside npm i -g hotcell, with the specific reason each pairing earns its keep.

Featured Head-to-Head Comparisons

Alternatives to npm i -g hotcell

View all
Agentbox Sdk

Agentbox Sdk

Free, open-source TypeScript SDK that runs AI coding agents in isolated, pre-configured dev environments.

FreemiumTry

Popular in Agent Memory & Runtimes

Arcade AI

Arcade AI

Arcade is the MCP runtime that gives AI agents per-user authorization, governed tool execution, and audit trails.

FreemiumTry
Tobira

Tobira

Tobira gives AI agents public addresses—@handles, profiles, and guest chat for agent identity.

FreeTry

Frequently Asked Questions

Used npm i -g hotcell? Help shape our editorial sentiment research.