Skip to content
Documentation

CodeSpace

CodeSpace is an MCP (Model Context Protocol) server. It gives an external coding agent a workspace it can inspect, edit, and run commands in through MCP. Your agent plans the work and interprets results; CodeSpace checks workspace permissions, performs operations, and keeps their execution state. It does not call a model or run an agent loop.

Start with a registered workspace

Follow installation and first connection to build the server and patch helper, register a project directory, and connect over stdio or Streamable HTTP. Starting the binary without a workspace registry leaves it with no accessible projects.

Then use the Agent Loop integration guide for the read → patch → run → inspect cycle, including cancellation and uncertain results. The documentation overview points to reference material.

Available tools

PurposeTools
Inspect the environment and filesworkspace_info, find, read
Apply a patch and retrieve its recorded stateapply_patch, operation_status
Run and control a processexec_command, read_process, process_status, process_resize, write_stdin, terminate_process
Track a logical job and queued user instructionswork_open, steer_status, steer_claim_next, steer_complete, work_finish

Both transports expose the same tools. The HTTP /inbox API lets a user-facing client manage instruction drafts; it is a JSON API, not a browser inbox application.

Execution and current limits

The default runner executes on the server host. An optional Unix-socket worker moves execution into a separate process on that same host. On Linux, a successful sandbox-helper probe enables command isolation and network enforcement. These are separate choices: UDS alone does not provide sandboxing. See runner isolation.

CodeSpace reuses pinned Codex execution libraries for patches, terminal sessions, filesystem operations, and Linux sandboxing. Codex reuse explains which components are connected and which responsibilities stay in CodeSpace.

For agent integrations, account for these limits:

  • Judge process exit with process_status. EOF from read_process is not success.
  • Process output is bounded. output_lost means the retained window is not the complete log.
  • Resize a running PTY with process_resize. Spawn size stays 24×80; tty_size is not an exec_command argument.
  • A live command blocks another command or patch in the same workspace. A development server cannot remain running while that workspace is patched.
  • Process handles do not survive server restart. HTTP/MCP client disconnect does not kill them. UDS worker loss and gateway shutdown do. Patch-operation records persist only when a database path is configured.
  • Container dispatch and a full OAuth server are not implemented. A live ChatGPT account connection remains unverified.

License

Apache License 2.0. See LICENSE and dependency attribution.