Self-Hosted Deployment
Run the Caged MCP server and sandbox agent on your own infrastructure for full control over data and compute.Self-hosted mode uses the open-source components only. Features like the dashboard, trust scoring, and billing require the managed platform at caged.dev.
Requirements
- Linux server with KVM support (for Firecracker)
- Docker (for containerized deployment)
- 4+ CPU cores, 8+ GB RAM recommended
Quick Start with Docker Compose
docker-compose.yml
ws://localhost:9090.
Standalone Binary
Connecting AI Agents
Claude Code
Add to your MCP config (~/.config/claude/mcp.json):
Cursor
In Cursor settings, add an MCP server:WebSocket (Remote)
For remote agents connecting over the network:Security Considerations
Read-Only Mode
file_read, file_list, file_search, git_status, git_diff, git_log.
Command Allowlist
terminal_exec.