Daytona for AI agents
Daytona manages cloud-based development workspaces, letting a team spin up, configure, and tear down sandboxes for coding and testing through an API. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Daytona.
Create a new sandbox
Create a new sandbox environment ready for a developer or agent to work in.
Clone a repository into a sandbox
Clone a git repository into a sandbox before starting work on it.
Confirm before deleting a sandbox
Confirm before deleting a sandbox, since any uncommitted work inside it is lost.
114 Daytona actions, graded by risk.
Every Daytona action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
55Look things up. Allowed by default.
- daytona.get_userGet Authenticated User
- daytona.get_configGet Daytona Config
- daytona.get_healthGet Daytona Health Status
- daytona.get_volumeGet Volume
- daytona.get_api_keyGet API Key
- daytona.get_sandboxGet Sandbox
- daytona.get_windowsGet Windows
- daytona.get_registryGet Docker Registry
- daytona.get_snapshotGet Snapshot
- daytona.get_work_dirGet Working Directory
- daytona.list_volumesList Volumes
- daytona.search_filesSearch Files
- daytona.get_file_infoGet File Info (Deprecated)
- daytona.list_api_keysList API Keys
- daytona.list_sandboxesList Sandboxes
- daytona.list_snapshotsList Snapshots
write
39Create and change things. Allow, or ask the user first.
- daytona.create_backupCreate Sandbox Backup
- daytona.create_volumeCreate Volume
- daytona.create_api_keyCreate API Key
- daytona.create_sandboxCreate Sandbox
- daytona.create_registryCreate Docker Registry
- daytona.create_snapshotCreate Snapshot
- daytona.update_registryUpdate Docker Registry
- daytona.create_ssh_accessCreate SSH Access
- daytona.create_pty_sessionCreate PTY Session
- daytona.create_folder_filesCreate Folder in Sandbox
- daytona.create_organizationCreate Organization
- daytona.update_last_activityUpdate Last Activity
- daytona.update_public_statusUpdate Public Status
- daytona.create_process_sessionCreate Process Session
- daytona.create_organization_roleCreate Organization Role
- daytona.update_organization_roleUpdate Organization Role
destructive
20Delete, cancel or archive. Ask first, or deny outright.
- daytona.delete_filesDelete Sandbox File
- daytona.delete_volumeDelete Volume
- daytona.delete_api_keyDelete API Key
- daytona.delete_sandboxDelete Sandbox
- daytona.delete_sessionDelete Session
- daytona.archive_sandboxArchive Sandbox
- daytona.delete_registryDelete Docker Registry
- daytona.delete_snapshotDelete Snapshot
- daytona.delete_recordingDelete Recording
- daytona.delete_git_branchDelete Git Branch
- daytona.delete_pty_sessionDelete PTY Session
- daytona.delete_api_key_userDelete API Key for User
- daytona.delete_organizationDelete Organization
- daytona.delete_organization_roleDelete Organization Role
- daytona.cancel_organization_invitationCancel Organization Invitation
- daytona.delete_organization_otel_configDelete Organization OTEL Config
Daytona in three steps.
- 01Your users connect DaytonaThey sign in to Daytona on Arc0 Connect, under your brand, and approve the access you ask for.
- 02You set the rulesReads run, writes like “create Sandbox Backup” can wait for the user, and “delete Sandbox File” can be denied outright.
- 03Any agent can actYour agent calls Daytona through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('daytona', { read: 'allow', write: 'ask', // create_backup destructive: 'deny', // delete_files }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Daytona connects.
Users sign in to Daytona on Arc0 Connect and approve the scopes you request. Build with Arc0’s Daytona OAuth app, or bring your own so the Daytona consent screen names you. Tokens refresh automatically, and you can export them whenever you want.
The same Daytona connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key · OAuth 2.0
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Daytona from any agent.
Daytona and Arc0, answered.
Can I use Daytona with Claude, ChatGPT or Cursor?
Yes. Connect Daytona to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Daytona actions you allow.
How do users connect Daytona?
Users sign in to Daytona on Arc0 Connect and approve the scopes you request. Build with Arc0’s Daytona OAuth app, or bring your own so the Daytona consent screen names you. Tokens refresh automatically, and you can export them whenever you want.
Which Daytona actions can my agent take?
114 in total: 55 read, 39 write and 20 destructive, such as “create Sandbox Backup”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Daytona?
Yes. Actions like “delete Sandbox File” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Daytona too?
Yes. The same Daytona connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Daytona into your agent.
Your users connect Daytona once, under your brand. Your agent gets 114 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan