THE BEST SELF-HOSTEDAI SOFTWARE ENGINEER
Orchestrate a fleet of cloud coding agents in all of the apps your team already lives in.
โกDeconstructed issue #15215: Booting isolated Sandbox microVM, applying patch to src/auth/handler.ts, delegating regression test sweep to Build Agent.
๐จTypecheck: clean ยท Vitest: 32 test files passed (397/397) ยท Egress Security: 0 secrets leaked ยท GitHub PR #546 ready to merge.
$ validate task
โ Task approved
$ run coding harness
โ Patch collected
$ run checks
โ Example run ready for reviewBUILT ON MODERN OPEN SOURCE & CLOUDFLARE RUNTIMES

USE CASES
From clearing hundreds of tickets at once to running security audits on a schedule.
E2E TESTING
Take your agent runs end to end with native computer use, browser use and annotated videos.
โ 32 test specs completed in 1.4s
โ Recorded DOM diff & visual artifacts

BUG TRIAGE AND FIX
Slack @mention to reproduced bug, fixed PR, and passing test suite.
@Coworker can you help me with this bug in sign-up form data?
Sniffing the air... SCO-15215 reproduced! Patch ready in PR #546.

CODE REVIEW
Automated diff critique, architectural sanity checks, and security scan before merge.
MIGRATION & REFACTOR
Burn down tech debt and run bulk refactors across multiple repositories in parallel.

BRING YOUR OWN KEY (BYOK)
Connect your own Anthropic, OpenAI, or Google API keys through Cloudflare AI Gateway with zero middleman markup.
AUTOMATIONS
Trigger on schedule or webhook. Nightly dependency updates, flaky test triage, and lint sweeps.
0 3 * * *ActiveNightly vulnerability sweep & package lock reconciliation across all worktrees.
FEATURES FOR A MODERN DEV TEAM
Plan and execute complex engineering tasks, from code migrations to on-call incident resolution.
WORLD CLASS HARNESS PERFORMANCE
Built for long-horizon tasks. Ephemeral microVMs boot in milliseconds with full shell, git, and language toolchains without host environment contamination.
01. Approval-Gated
Every tool execution, file modification, and egress communication passes through strict cryptographically verified approval gates. Zero unauthorized actions.
02. Micro-Containers
Cloudflare Sandbox microVMs boot in 340ms, providing pristine isolated environments with full Docker toolchains and egress secret masking.
03. Issue Triage
Automated bug reproduction from Slack alerts and GitHub issues. Reproduces bugs in sandbox, drafts verified patches, and opens clean pull requests.
"IT'S THE HOLY QUADRINITY... MY GOD... IT'S REAL!!!"
From Slack discussions to GitHub pull requests and isolated Cloudflare Sandboxes. Everything syncs in real-time.


SLACK
Chat directly with Shiba in channels. Trigger tasks, review diffs, and click Approve right in Slack threads.
GITHUB
Automated PR creation, branch management, commit hygiene, and webhook event processing.
CLOUDFLARE SANDBOX
Ephemeral micro-containers boot in milliseconds. Execute untrusted scripts with egress boundary proxies.
REST & CLI API
Headless triggers for CI/CD pipelines, custom GitHub actions, and automated scheduled workflows.
THE AGENT HARNESS
Built for multi-agent execution loops with zero risk of rogue commands reaching your local environment.
OPENCODE RUNNER
OpenCode binary runs natively inside the Cloudflare Sandbox container, executing edits and test suites in rootless isolation.
CLAUDE CODE ADAPTER
Direct compatibility with Claude Code CLI workflows, prompt contracts, and automated repository analysis tools.
CODEX ORCHESTRATOR
Coordinates task decomposition, approval gates, and multi-round code reviews across parallel agent threads.
API tokens and provider credentials live exclusively in Cloudflare Worker secrets. The egress proxy validates and signs outgoing calls while masking secrets in logs.
SECURITY ARCHITECTURE
Architected for containment, egress isolation, and explicit human sign-off.
GVISOR SANDBOX
Kernel-level syscall interception in Cloudflare Sandbox ensures untrusted code cannot compromise host runtimes.
DATA PROTECTION
Isolated environments. Encrypted at every layer. Your code never leaves your Cloudflare perimeter.
APPROVAL GATES
Cryptographically verified approval cards in Slack and the dashboard halt execution before shell commands run.
BYO KEY, BYO CLOUD
Bring your own API keys or host entirely on your own Cloudflare account with zero third-party data transit.
NO SUBSCRIPTION FEES. NO SEAT TAX.
Shiba is free open-source software under the MIT License. Deploy directly into your own Cloudflare account with zero vendor markups.
- โ100% Open Source: Permissive MIT license with zero commercial restrictions
- โUnlimited Team Seats: Add your whole engineering team without paying $20โ$50/user fees
- โModel Agnostic: Connect Claude 3.7, Gemini 2.5, OpenAI, or local weights with your own keys
- โExtensible Workflows: Customize approval policies, webhook handlers, and container images
- โAccount Owned: Runs inside your own Cloudflare perimeter; code never leaves your account
- โPer-Second Compute: Isolated Sandbox containers bill only for exact active execution time
- โZero Provider Markups: Tokens bill directly through your own AI Gateway stored keys
- โGranular Spend Limits: Enforce strict spend caps and rate limits in Cloudflare dashboard
Explore the guides
View allDeploy Shiba to your Cloudflare account
Configure your GitHub credentials, set up Cloudflare AI Gateway bindings, and deploy the orchestrator worker alongside isolated sandbox micro-containers in minutes.
Zero-Trust Ephemeral Sandboxes for Autonomous Coding
How Cloudflare Sandbox micro-containers isolate agent executions with egress proxy credentials, masking secrets while generating verified GitHub PRs.
Add Shiba to your team
The teammate you actually want to work with.
