Every agent gets its own
Composable, isolated desktop boxes for your agents. You can watch it work or take the controls when it needs you.
A whole computer,
not a browser tab.
Each box is a Linux desktop with its own screen, browser, apps, shell and disk. The agent uses all of it, the same way a person does.
Browser
Chromium over CDP. Read the page as an accessibility snapshot, then click and fill by name, not by pixel.
Native apps
Drive GTK and Qt windows by widget name through AT-SPI.
Shell
Run commands with exit codes, timeouts and output.
Files
Move files in and out. Upload them to a page.
Screens
Mouse, keyboard, clipboard and screenshots on one or more screens.
Drive it from anything.
One server, one set of actions. Use the CLI in a script, the Rust crate in a program, REST from any language, or MCP from an agent host.
Every action is one command. Pipe the box ID between them.
BOX=$(holm new --url https://example.com) holm screenshot $BOX screen.pngholm mouse $BOX click 640 81 leftholm keyboard $BOX type "driven from the CLI" TAB=$(holm open $BOX https://example.com)holm browser $BOX click "More information" --tab $TAB holm rm $BOXWatch it work.
Take the controls.
Every screen has a watch link that anyone can open in a browser. When the agent meets a login, a CAPTCHA or a payment, it hands the screen to a person, and its own input stops until the person gives it back.
- agent
Fills the checkout form
- agent
Hits a CAPTCHA. Calls hand_over
- person
Opens the control link. Solves it
- person
Releases the screen
- agent
Picks up where it stopped
Confirm you are human
Every step, on the record.
The server writes down what the agent, the person and the system did to each box. Read the trace to see what happened. Fork at any step to make a new box that does the same steps again.
- 1systembox_created1280x800 · docker
- 2agentactedopen_url shop.example
- 3agentframea91f…
- 4agentactedfill Email
- 5persontakeover_startedscreen 0
- 6persontakeover_endedscreen 0
- 7agentactedclick Pay now
Same box. Your choice of shore.
All desktop actions are the same on every runtime. Pick a container for speed, a microVM for its own kernel, or a cloud sandbox when the box must not run on your machine.