MCP Server
Reference for the hosted Tenki Sandbox MCP server covering setup, sign-in, available tools, and how to limit what an agent can do.
The Tenki MCP server lets an agent drive sandboxes over the Model Context Protocol — creating a session, running code in it, and tearing it down as ordinary tool calls. These are the same operations the CLI and SDKs offer, handed to the agent instead of to you.
The server is hosted at https://mcp.tenki.cloud/mcp and speaks MCP over HTTP, so there is nothing
to install or run locally — you add the URL and sign in.
Connect Claude Code
claude mcp add --transport http tenki https://mcp.tenki.cloud/mcp && claude mcp login tenkiclaude mcp login opens your browser to sign in. Over SSH or anywhere without a browser, add
--no-browser to print the authorization URL instead.
Claude Code is the supported client today.
Moving from the local server
If you set up the earlier locally run server (npx @tenkicloud/mcp), remove it first so Claude
Code doesn't load two sets of Tenki tools:
claude mcp remove tenki # if you added it with claude mcp add
claude plugin uninstall tenki@tenki # if you installed it as a pluginSign in
The hosted server uses OAuth, not an API key. claude mcp login tenki takes you through Tenki
sign-in and then asks which workspace to connect. Only the workspace's owner or an administrator
can connect it. The agent then acts in that workspace — its sandboxes run there and spend that
workspace's credits.
Claude Code stores the credential and refreshes it for you. Tenki keeps checking your access while the agent works, so if you lose owner or administrator access or the workspace is deleted, the agent loses access too.
To switch workspaces, sign out and sign in again:
claude mcp logout tenki
claude mcp login tenkiWhat the agent can do
The tools cover session lifecycle (create, pause, resume, terminate), command
execution, file read and write, git clone/checkout/diff/log, port exposure and preview URLs,
plus snapshots, volumes, and
templates. tenki_run_code covers the common one-shot case — boot a
session, run a script, and tear it down in one call.
For the current tool-by-tool list, see the server's README — it tracks the API directly.
Limit what it can do
The server runs arbitrary code in your workspace and spends its credits, so treat it as a
capability rather than a read-only integration. To block specific tools, add deny rules to your
Claude Code permissions. Tenki tools are named
mcp__tenki__<tool>:
{
"permissions": {
"deny": ["mcp__tenki__tenki_terminate_sandboxes", "mcp__tenki__tenki_delete_volume"]
}
}Output from tenki_run_code, tenki_exec, and tenki_read_file comes from code running inside
the sandbox. Treat it as data, not as instructions to act on.
Related
- CLI reference and SDK reference — the same operations, driven by you
- Concepts — sessions, snapshots, volumes, and templates
- tenki-mcp — source, tool list, and security model