Pick an agent.
Choose a pre-loaded template. OpenClaw is live now. SWE-Agent and OpenHands are coming next. No install. No config.
A hijacked agent reaches nothing it shouldn't. OpenClaw runs in a disposable cloud sandbox. It never sees your credentials, cookies, or machine. One click to start. One click to destroy.
no cli. no docker. no api keys.
[ HOW IT WORKS ]
Spawn the sandbox, run the agent, burn it on close. The whole lifecycle takes about as long as opening your IDE.
Choose a pre-loaded template. OpenClaw is live now. SWE-Agent and OpenHands are coming next. No install. No config.
The agent gets full access inside an isolated sandbox. It never sees your credentials, cookies, or machine. A prompt injection has nowhere to go.
When you're done, destroy it. One click and the whole environment is gone. No lingering data. No cleanup. No trail.
[ WHY CONTAINMENT ]
Infra tools sell you scale. Legba contains the agent. One column is the setup you already run. One is the isolated browser for AI agents that Legba ships.
[ OPENCLAW SANDBOX ]
Full system access. Total isolation. Gone on close.

Run Claude computer use safely. The agent gets full system access inside the sandbox. It can write code, run scripts, and install packages. It cannot touch your machine, your credentials, or your cookies. One click destroys the session. No artifacts. No residue.
[ PRICING ]
No hidden fees. Every plan runs in full isolation, with one-click teardown and no persistence.
Run an agent in a disposable sandbox. See what it can do.
For builders who run agents every day.
Related surfaces
OpenClaw is the contained-agent surface inside the larger Legba product family. Use the related pages below to evaluate browser isolation, MSP rollout, and the research behind agent containment.
A hijacked computer-use agent reaches no credentials, cookies, or files. The disposable sandbox is the boundary.
ExploreFull access inside the sandbox, zero access to your real machine, destroyed on close. The containment layer for autonomous agents.
ExploreRead the practical decision framework for when to run OpenClaw locally, when to contain it, and what to inspect first.
ExploreOpenClaw runs on the same containment model as the main product. Keep risky web execution off the endpoint by default.
ExploreIf you manage multiple clients, the MSP page shows how the same isolation layer extends beyond one-off OpenClaw runs.
ExploreAdversary uses the same engine to validate real exposures and return a client-ready report in minutes, not weeks.
ExploreLegba is a disposable real browser: it spawns a clean session, does the work, and destroys itself on close.
chromium / real fingerprint · residential ip · burn on close
Real browser. Real IP. Real page. Spawn a session. Do the work. Destroy it. Off your device. Off your stack. Gone on close.