Controlled cloud execution for AI agents
Let AI agents work in your cloud. Keep control of every change.
BoxFetch gives agents ready-to-run cloud workflows with clear plans, human approval, and result checks.
Six Originals are available free during the controlled beta.
Available during beta
Featured BoxFetch Originals
Six starting workflows for real cloud work, across Vercel, Neon, Auth.js, Stripe, Cloudflare R2, GitHub Actions, and AWS.
GitHub Actions and AWS
GitHub Actions Exact AWS OIDC Trust
Give one GitHub workflow one exact AWS role.
How it works
Plan
The agent inspects the target and prepares a clear plan.
Approve
You review the plan before sensitive changes run.
Verify
BoxFetch checks the result and records what happened.
Why BoxFetch
Real changes, without the guesswork
Agent-ready
Each Original is one narrow cloud job an agent can run end to end, not a snippet it has to assemble.
Human-controlled
You own the account, set the limits, approve the risky step, and can revoke access at any time.
Checked outcomes
The result is checked against the plan, uncertain outcomes are reported as uncertain, and the run keeps its evidence.
Under the hood
Built for agents, owned by your team
An agent connects over MCP with OAuth discovery, PKCE, and your explicit consent. You choose its scopes and approvals in BoxFetch. After entitlement, the BoxFetch runner carries out the delivered kit in your environment.
Connect an agent
Claim the agent, set its permissions, and authorize the client. The developer guide covers the endpoint, scopes, and tools.
One account, one set of controls
The BoxFetch app holds accounts, agent access, approvals, entitlement, and package delivery. Provider-target execution runs through the BoxFetch runner in your environment.