Every agent gets its own

Composable, isolated desktop boxes for your agents. You can watch it work or take the controls when it needs you.

Quick start
Inside each box

A whole computer, not a browser tab.

Each box is a Linux desktop with its own screen, browser, apps, shell and disk. The agent uses all of it, the same way a person does.

https://shop.example/checkout
- snapshot
heading "Checkout"
textbox "Email" [focused]
textbox "Card number"
button "Pay now"

Browser

Chromium over CDP. Read the page as an accessibility snapshot, then click and fill by name, not by pixel.

gnome-calculator
1,280
7
8
9
÷
4
5
6
×
1
2
3
=

Native apps

Drive GTK and Qt windows by widget name through AT-SPI.

$ holm exec $BOX -- uname -sr
Linux 6.8.0
$ holm exec $BOX -- jq .ok out.json
true
$

Shell

Run commands with exit codes, timeouts and output.

PDFreport.pdf2.1 MB
CSVinvoice.csv18 KB
PNGscreen.png412 KB

Files

Move files in and out. Upload them to a page.

:0.0
:0.1

Screens

Mouse, keyboard, clipboard and screenshots on one or more screens.

Four ways in

Drive it from anything.

One server, one set of actions. Use the CLI in a script, the Rust crate in a program, REST from any language, or MCP from an agent host.

Every action is one command. Pipe the box ID between them.

terminal
BOX=$(holm new --url https://example.com)
holm screenshot $BOX screen.png
holm mouse $BOX click 640 81 left
holm keyboard $BOX type "driven from the CLI"
TAB=$(holm open $BOX https://example.com)
holm browser $BOX click "More information" --tab $TAB
holm rm $BOX
Human control

Watch it work.
Take the controls.

Every screen has a watch link that anyone can open in a browser. When the agent meets a login, a CAPTCHA or a payment, it hands the screen to a person, and its own input stops until the person gives it back.

  1. agent

    Fills the checkout form

  2. agent

    Hits a CAPTCHA. Calls hand_over

  3. person

    Opens the control link. Solves it

  4. person

    Releases the screen

  5. agent

    Picks up where it stopped

box-7f3a · screen 0
Release

Confirm you are human

Verify
you
agentinput refused until release
Trace and fork

Every step, on the record.

The server writes down what the agent, the person and the system did to each box. Read the trace to see what happened. Fork at any step to make a new box that does the same steps again.

holm trace box-7f3a7 events
  • 1systembox_created
  • 2agentacted
  • 3agentframe
  • 4agentacted
  • 5persontakeover_started
  • 6persontakeover_ended
  • 7agentacted
$ holm fork box-7f3a --up-to 4
Runtimes

Same box. Your choice of shore.

All desktop actions are the same on every runtime. Pick a container for speed, a microVM for its own kernel, or a cloud sandbox when the box must not run on your machine.

dockerThe default
Container
podmanContainers on the host
Container
nerdctlcontainerd
Container
smolvmlibkrun on macOS and Linux
MicroVM
microsandboxlibkrun through msb
MicroVM
e2bFirecracker in the cloud
MicroVM