The work your backend does, done by an agent.

Builds, crawls, document pipelines, browser jobs — the minutes-to-hours tier every product needs and nobody wants to operate. One POST stands in for the queue, the workers and the sandbox, and everything the run did comes back as data your product can read.

Free to start. Bring a key from any provider — Gobare never resells model credits.

YouYour productSends work, reads what came backSends work,reads what came backGobareAgent API + sandboxpi on a real machine — workspace, shell, browserpi on a real machine —workspace, shell, browserYour providerAnthropicOpenAIGoogle GeminiYour modelAny provider, your key, your billAny provider,your key, your billWorkPOST /v1/sessionsEvents and artifactsGET /v1/sessions/:id/eventsGET …/eventsModel callsCompletionsrequired_actions — it asks your code, or a person, and waitsThe key never enters the sandbox

We run the machine and the agent loop. You keep the model, the key and the bill.

What you don't build

The tier this replaces.

Work that takes minutes rather than milliseconds needs somewhere to run, so every team ends up writing the same infrastructure underneath it. A session is that infrastructure — called, not operated.

What you would build

  • A job queue, and the workers that drain it
  • A container image per kind of task, and the registry it lives in
  • A headless browser fleet, and the crash loop that comes with it
  • The crawler you rewrite every time a page changes shape
  • A document pipeline, and a parser for each format that enters it
  • A build box with the whole toolchain installed on it
  • Artifact storage, and the signed URLs that hand things out
  • Retries, timeouts, and the state machine that remembers where a run got to

What you call

POST /v1/sessions

One call. The run comes back as events, artifacts and a URL.

What it does

What can your agent do?

The same machine researches, drives a browser, turns documents into data, or builds an application and serves it at an address. What changes between them is the request, not the runtime.

  • Read the web

    Search, fetch a page, search for images — web_search, web_fetch, image_search.

    Tools
  • Use a browser

    Open a page in a real browser, click, type, navigate, and screenshot what rendered.

    Tools
  • Turn documents into data

    A folder of PDFs, contracts or invoices in; validated JSON rows out.

    Guide
  • Build and run software

    A workspace, git, a shell, services it starts, and a public URL for what it built.

    Previews
  • Call your systems

    Your own functions, answered by your process, or an MCP server it connects to.

    required_actions

The call

Call it, await it, use the result.

No stream to subscribe to before you send, no cursor to resume from, no tool-call dispatch to hand-roll.

runSession() — typescriptQUICKSTART
const result = await runSession({
  baseUrl: "https://api.gobare.dev",
  token:   process.env.GOBARE_TOKEN!,
  input:   "Create /workspace/outputs/report.md about this repo.",
  session: { environment: { repo: "acme/site" } },
})

Or write none of it. AGENTS.md is the whole API as one page written to be executed, with no link a machine has to follow.

Paste this into any coding agent

Read https://docs.gobare.dev/AGENTS/ and build me a code-review agent.

Read AGENTS.md →

Known to work in
  • ClaudeClaude Code
  • CursorCursor
  • pi
  • OpenAICodex
  • TraeTrae
  • WindsurfWindsurf
  • ClineCline
  • Google GeminiGemini CLI
  • GitHubCopilot

The boundary

You bring the intelligence. We run the machine.

The line between the two is the API, and it is drawn in one place. Nothing on the left is ours to keep — the key lives in memory for the length of one call and never reaches the sandbox.

Your side — runs in your process

  • Your product, and the people using it
  • Your model, from any provider
  • Your API key
  • Your bill, paid to that provider
you call ↓the API↑ we answer

Our side — runs in our infrastructure

  • The agent loop
  • The sandboxed computer
  • The workspace, and the artifacts that outlive it
  • Tool dispatch, streaming and webhooks
  • Session lifecycle and recovery

Your model

Your key. Your bill. No markup.

Bring a key from any provider below, or any OpenAI- or Anthropic-compatible endpoint. It lives in memory for the length of one call — not in the sandbox’s environment, not on disk.

  • No token markup
  • No model lock-in
  • The key never enters the sandbox
your keysk-••••••••the model callin memory · one callyour providersandbox boundarystops herethe agent, inside$ env | grep -i key(no matches)

First-class connectors

MiniMaxMiniMax
DeepSeekDeepSeek
QwenQwen
Kimi / MoonshotKimi
Zhipu GLMGLM
AnthropicAnthropic
OpenAIOpenAI
xAI GrokxAI
OpenRouterOpenRouter

Where it doesn't go

What this is not for.

A boundary is worth more than another claim. These are the jobs a session is the wrong tool for — and publishing them is what makes the rest of this page checkable.

  • Plain text generation, classification, summarisation or extraction with no execution — call a model directly; a session would be slower and cost more for the same answer.
  • Sub-second interactive responses. A session boots a sandbox first, so the first turn is measured in seconds.
  • Running untrusted code you have not chosen to run. A session is isolated from other tenants, but it executes exactly what you or your agent tells it to.

Start

Build your agent product, not the infrastructure under it.

Free to start, and the first call takes a key and one POST. Nothing to provision.

How this differs from OpenAI’s Agents API →