
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@capsulate/sdk
Advanced tools
Official Capsulate SDK — launch and drive isolated cloud sandboxes (capsules) from JavaScript/TypeScript. Powers the cap CLI, the MCP server, and your own agents.
The official Capsulate SDK — launch and drive isolated cloud
sandboxes ("capsules") from JavaScript / TypeScript. This one client powers the cap
CLI, the Capsulate MCP server, and your own agents. Everything you can do in the
Capsulate dashboard, you can do here (API/UI parity is a platform law).
npm install @capsulate/sdk
import { Capsulate } from "@capsulate/sdk";
const cap = new Capsulate({ apiKey: process.env.CAPSULATE_API_KEY });
// Launch a capsule and wait until it is ready.
const c = await cap.capsules.launch({
template: "ubuntu-22.04-headless",
size: "2c4g",
});
// Run code inside it.
const out = await c.exec(["python3", "-c", "print(40 + 2)"]);
console.log(out.stdout); // "42\n"
// Read & write files.
await c.writeFile("/workspace/app.py", "print('hi from the capsule')");
console.log(await c.readFileText("/workspace/app.py"));
// Clean up.
await c.destroy();
| Credential | How to get it | Good for |
|---|---|---|
API key (cap_live_…) | Dashboard → Settings → API & Keys, or cap apikey create | Agents, CI, the MCP server |
| Access token (JWT) | An interactive login (cap login) | Team / billing administration |
new Capsulate({ apiKey: "cap_live_…" }); // recommended
new Capsulate({ token: "<jwt>", baseUrl: "…" }); // interactive
Environment fallbacks: CAPSULATE_API_KEY, CAPSULATE_TOKEN, CAPSULATE_BASE_URL,
CAPSULATE_TEAM_ID.
create / launch / list / history / get / destroy / suspend / resumeexec, run, readFile, writeFile, setEnvscreenshot, click, move, scroll, drag, type, keyrecordings.{list,start,stop,status,download}snapshots.{list,create,delete} (+ restore via capsules.create({ snapshot }))volumes.{create,list,get,delete,attach,detach}templates.list, bundles.list, catalog.listsharing.{share,guests,setGuestPermission,removeGuest}, ports.{forward,remove}teams.list, billing.balance, apiKeys.{list,create,revoke}Errors are thrown as CapsulateError (.status, .body, .isAuthError, …).
Types mirror the platform's authoritative Go contracts; see the in-dashboard Docs section or the OpenAPI spec at
docs/api/openapi.yaml.
FAQs
Official Capsulate SDK — launch and drive isolated cloud sandboxes (capsules) from JavaScript/TypeScript. Powers the cap CLI, the MCP server, and your own agents.
The npm package @capsulate/sdk receives a total of 16 weekly downloads. As such, @capsulate/sdk popularity was classified as not popular.
We found that @capsulate/sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.