Product
What an agent gets in Helios
A sandbox, the full API of each tool, shared context, and a permissions model that follows it into the CLI and your scripts.
- 5,000 free credits to start
- One sandbox per run
- Full run transcripts
A real computer per run
Every run gets its own sandbox with a shell, files, and code execution.
See the sandbox →The full API of each tool
Agents call the complete API of a connected tool, not a curated list of actions.
See integrations →One permissions model
Roles cover the dashboard, the CLI, and your scripts. The agent never holds a raw token.
See security →Workflows
Write the prompt once. Pick the trigger.
Four ways to start
Run it by hand, on a schedule, from a signed webhook, or on an event.
Events from three tools
GitHub fires 12 events, Slack 2, Plain 2. Filters run before the agent starts.
Model and identity per workflow
Each workflow names its model and runs as a service account you can disable.
Prompt
Plain language. Name the tools, the judgment calls, and the shape of the output.
Integrations
The agent may use the full API of each one.
- GitHub · helios/api
- Slack · #eng-daily
Triggers
New trigger
Write the schedule in words. Helios turns it into a cron expression you can check.
Active triggers
- Schedule · 0 9 * * 1-5
- Integration · github · pull_request.opened
Chat
Start in chat. See every step.
Every tool call is visible
The endpoint, the payload, and the timing appear as the agent works.
A sandbox behind the chat
When a step needs a script, the agent writes one and runs it.
Fork, stop, share
Branch a chat, stop a run mid-step, or share it up to a chosen message.
How can I help you?
Library
Shared context, reviewed by people.
Mounted in every sandbox
Agents read the Library at ~/context like any other folder.
Edits become a staged change
A run's file changes wait as one change set with a side-by-side diff.
A person approves each file
Nothing reaches the team until someone approves. A run cannot approve its own work.
Review inbox · 3 pending
organization/support/refund-policy.md
Proposed by the weekly support digest run. Modified.
# Refund policyRefunds are handled case by case.Refund within 14 days of purchase, no questions asked.After 14 days, escalate to a support lead.Source: support handbook, section 3.
Code
Your environment, your terminal, your agent.
Built from your Dockerfile
Helios builds the image and keeps every version with its build log.
Claude Code, already signed in
Connect your Claude account once. Every sandbox starts authorized.
Launch, watch, attach from the CLI
Run helios configure once, then drive agents from your own terminal.
The install command and supported platforms are in the docs. Install the CLI →
MCP
MCP, in both directions.
Remote servers over HTTPS
Point Helios at a Streamable HTTP server. Localhost and private ranges are rejected.
A tool allowlist per server
The proxy hides tools you did not list and rejects calls to them.
Helios as a server
Any MCP client can search the Helios API and call what it finds.
claude mcp add --transport http helios \ <helios-mcp-endpoint>/mcp \ --header "Authorization: Bearer ${HELIOS_API_KEY}"
Add Helios to Claude Code, an IDE, or any MCP client. Your client searches the Helios API, then calls what it finds.
Frequently asked questions
Keep going
Keep reading
Learn how to connect tools, manage access, and start from a template.
Integrations
Your tools are already here.
The full API of each service, three auth modes, and the trigger matrix.
Security
Every run is isolated. No agent holds a token.
Credential injection, encrypted secrets, roles with expiry, and spending limits.
Templates
Start from a template.
Ready-made prompts and triggers for support digests, CRM cleanup, and recurring reports.
Give your first agent a computer.
Start with 5,000 free credits. Connect one tool, describe one task, and read the transcript.