Managed Hermes Agent & OpenClaw hosting
Connect Telegram or Discord, paste your model API key, ship. Your agent answers messages around the clock from an isolated sandbox you never have to think about. Between messages it snapshots itself to disk and wakes back up in under a second when someone pings it — no always-on server to babysit.
beta · signup is invite-only for now
$ cagebox ps NAME STATUS VM IP hermes-concierge ● running 172.16.0.2 openclaw-coder ◐ provisioning 172.16.0.5 hermes-helpdesk ○ paused — openclaw-research ● running 172.16.0.9 4 agents · 2.0 GB reserved · 14.3 GB free
Your API keys, your chat history, your prompts — fenced off in a sandbox only your agent can see. If anything ever escapes another tenant, it still can't reach you.
Quiet inbox? Your agent gets snapshotted to disk and stops eating host RAM. The moment someone messages you, it wakes up and replies in under a second. No always-on server you forgot to turn off.
Pick Hermes Agent (Python, persistent memory) or OpenClaw (Node, plugin-based). Plug in your own OpenAI or Anthropic key and let your agent answer on the channels you already use.
Managed hosting for Hermes Agent — Python, persistent memory, a built-in browser tool. Connect Telegram or Discord, bring your model key, and your agent answers around the clock from its own Firecracker microVM. It snapshots to disk when idle and wakes in under a second, so you only pay while it works — no always-on VPS to babysit.
Explore Hermes hostingManaged hosting for OpenClaw — Node, plugin-based, with a real tmux-backed web shell. Kick off long-running work, close the laptop, and the VM keeps going. Each agent is hardware-isolated in its own microVM and scales to zero between messages, so an idle agent costs you nothing in host RAM.
Explore OpenClaw hostingFour screens. No Docker, no SSH, no Caddy snippet to copy. You bring the keys and the messages — Cagebox brings the microVM, the subdomain, and the webhook plumbing.
Hermes Agent (Python, persistent memory, browser tool) or OpenClaw (Node, plugin-based). One radio button, no Dockerfile.
Paste a Telegram bot token or sign in to Discord. We register the webhook against your private *.cagebox.dev subdomain automatically.
OpenAI, Anthropic, OpenRouter, Groq, Mistral, and 18 more — pick the provider, paste the key. Stored encrypted, decrypted only inside your VM.New to model APIs? OpenRouter has free-tier models to get started.
Hit create. ~45 seconds later your agent answers its first message. Snapshots, logs, web shell, and a file explorer for /data are wired in from the start.
Provision, operate, and debug your agents from one dashboard — logs, a real web shell, live resource monitoring, and snapshot controls, no SSH or extra tooling.

Cagebox doesn't care what your agent does — these are just patterns that work well with always-online, snapshot-paused agents that talk to a chat channel.
Drop questions, notes, links into a private Telegram bot. It remembers across conversations, browses when it needs to, and answers from the same chat thread you already check — no extra app to keep open.
Drop the bot into your team Discord. It picks up the questions nobody has time to answer, summarises long threads on demand, and keeps the channel useful when the regulars are asleep.
Kick off a long refactor in the in-browser shell, close the tab, get on a train. The VM keeps working; come back and pick up exactly where you left off. /data is persistent, the shell is a real tmux.
Text the bot from your phone: look at my repo, add the /metrics endpoint, open a PR. Walk into the meeting. When you walk out, the PR is waiting.
Agent type is about workload, not billing. Pick Nano for small responders, Standard for everyday assistants, or Browser when Chromium needs to live inside the VM.
Best for reminders, private chat helpers, webhooks, and simple LLM workflows that wake a few times a day.
Comfortably runs Hermes or OpenClaw with terminal, files, code execution, vision, and regular chat traffic.
Adds headroom for Browser Automation: navigate, click, type, screenshot, and work through real web pages.
Plans below bundle one or more of these agents. Starter can run two Standard agents, or trade that capacity for one Browser agent.
Cagebox is not just a VM rental. Each plan includes the control plane, chat gateways, lifecycle automation, and the operational tools that keep an agent usable after launch.
You bring the model API key (pay the provider directly). We give you the sandboxed VMs, scale-to-zero between messages, and the gateway plumbing — pay-as-you-go from day one.
One Standard agent — the right size for most personal projects.
Two agents — or one that browses the web with Chromium.
Card required · $0 today · $10/mo after 7 days · cancel anytime
Request inviteThree agents, any tier mix. For builders running multiple agents in parallel.
Model API costs (OpenAI / Anthropic / OpenRouter / etc.) are billed directly by the provider — Cagebox never touches the charge.