Managoat is the hosted Fountain. The engine is open source and you can run it yourself.

Chat with Claude Code, Codex or Gemini CLI. Watch it work.

Open Conversations to give an agent a task, follow its tools and changes, and send a follow-up. Each conversation has a real computer that keeps its files between prompts.

Real app screens with a seeded local example.

$5.00 of credit to start, no card. Bring your own model key: you pay for agent time, never tokens.

Apps

Use an app. Or build your own on the same API.

12 open-source apps already run on the public API. Use one, fork its source, or point it at your own instance.

Browse all 12 apps

Run coding agents on ready machines. Pay only while they work.

Your repositories, packages and credentials arrive with the machine. It parks between prompts and wakes with its work intact. Run your own instance or use the hosted service.

Case study

The pager still rings. An agent starts working too.

When a workload breaks, this Kubernetes cluster pages an on-call engineer and starts an agent at the same time. The agent investigates the alert and, when it finds a repository fix, opens one focused pull request. It never holds cluster credentials. A person decides whether to merge.

7.5 min
median alert-to-verdict time
The longest investigation ran 50 minutes.
78
alerts investigated
12
fix pull requests opened
8
fix pull requests merged

Measured from 11 to 25 August 2026 on one Kubernetes cluster running live production workloads. Numbers reported by the cluster administrator (us).

Setup

You write this once. Everything after it is a prompt.

1 Describe the machine once. Repositories, packages, env vars, setup scripts. Write it in the console, or keep it in git.
2 Add credentials only when a run needs them. A Vault is an optional set of environment-variable overrides. Attach one in the API call; leave it off when a run needs no credentials.
3 Name the agent and its tools. Pick the runtime and model, add skills and MCP tools, and attach the Environment. The public DeepWiki server needs no credential.
# fountain.yml
apiVersion: fountain.dev/v1
kind: Environment
metadata:
  name: app
spec:
  repositories:
    - url: https://github.com/acme/app
      mount_path: /work/app
      secret_key: GITHUB_TOKEN
  setup_script: cd /work/app && npm install
---
apiVersion: fountain.dev/v1
kind: Vault
metadata:
  name: ci-bot
spec:
  secrets:
    GITHUB_TOKEN: op://Private/github/token # resolved from 1Password at apply time
---
apiVersion: fountain.dev/v1
kind: Agent
metadata:
  name: reviewer
spec:
  runtime: claude
  model: anthropic/claude-sonnet-5
  environment: app
  skills:
    - source: obra/superpowers
      ref: v2.1.0
  mcp_servers:
    deepwiki:
      type: http
      url: https://mcp.deepwiki.com/mcp
One file, three documents. Apply it once. It creates what is new and updates what changed.
fountain apply -f fountain.yml
4 Send a prompt. A sandbox spawns and the agent works, streaming as it goes. Send another prompt and the machine is still there with its work on it.
import { Fountain } from "@managoat/fountain-sdk";

const fountain = new Fountain(); // FOUNTAIN_API_KEY

const run = await fountain.run(
  "Fix the failing test and open a PR",
  { agent: "reviewer", vault: "ci-bot", channelId: ticket.id }
);

console.log(run.text);

What you get

You did not set out to run a sandbox platform. We did.

The agent is only the visible part.

Launch every run from the same reviewable setup.
An Environment defines repositories, packages, environment variables, setup scripts, and network policy. Keep it in git, review changes, and reuse it across runs.
Change a credential without a redeploy.
Here, a Vault is a per-run override, not a central secret store. Its values override the Environment, so the same setup can run as you, a bot, or your customer. Managoat scrubs secret values from stored output.
Let the agent open the pull request.
The sandbox already has the checkout and the credential you assigned. The agent can commit, push, and open the pull request without a patch handoff.
Build one interface for every runtime.
Managoat normalizes text, reasoning, tool calls, results, and approval requests into one block schema. Request it with ?blocks=true.
Keep the workspace. Release the capacity.
While a sandbox waits, its checkout and work in progress stay intact, but it uses none of your concurrency. The next message wakes it on the same files.
Trace what changed and who changed it.
The audit trail records who changed each resource and which fields changed, without storing their values. Each conversation also records the exact Agent version it ran under.

State

Use an id you already have. Managoat keeps the session.

Bind a conversation to a customer, ticket or Slack channel id. Send that id with the same Agent, Environment and Vault to resume the live conversation. You do not store or look up a Managoat conversation id.

Between prompts, the sandbox parks with its files intact. The next message or a scheduled run wakes it.

In the default mode, the disk belongs to that conversation. End the conversation and its workspace goes with it.

See the conversation API

Scale

A hundred tickets take a hundred calls, not a new architecture.

No queue to run, no worker pool to size, no image to bake per repository.

Give each job its own sandbox

In the default mode, one call starts one conversation on its own sandbox. A batch is a loop. Every sandbox carries the bundled skill, so an agent can start more work and collect the replies.

Or share one sandbox across conversations

Use persistent mode when many conversations need the same checkout. They keep separate transcripts and run up to the runtime's capacity. Work beyond that limit is refused, not queued.

Protocols

Put Managoat behind the stack you already use.

Your editor or chat surface keeps speaking ACP, and your agents keep speaking MCP. Everything else drives the roster through the API our own apps use.

Agent Client Protocol
Connect an ACP editor or chat surface to any agent on your roster with fountain acp.
MCP, both directions
Let agents use the servers you declare, then expose the roster so they can delegate to each other.
REST, SSE and webhooks
Start a conversation, stream its blocks and receive a signed webhook when the turn ends, from your own code, an SDK or the CLI.

See what connects today

Pricing

You pay only while an agent is working.

No plans, no seats, no subscription. Buy prepaid credit and spend it only while a prompt is in flight.

$0.25

per active agent hour

One agent hour is one hour with a prompt in flight. Two agents working for an hour use two agent hours. Parked and idle agents cost nothing.

$5.00

free credit to start

No card required. Starter credit expires after 14 days.

Start with $5.00 free

How billing works

Purchased credit never expires. Fountain uses your starter credit first. Add credit in packs of $10.00, $25.00, $100.00.

Bring your own model key. Fountain bills agent time, not inference. Your model provider bills its usage separately.

Teammate contacts come out of the same balance. A phone number is $5.00 a month and an email inbox is $2.00 a month, billed in advance. Messages are $0.01 an email and $0.02 a text, sent or received.

Your balance sets your concurrency. Each $2.00 in your balance supports one agent working at a time, with a minimum of 2 and a maximum of 20. An API start beyond your limit can ask to wait in a bounded queue, and a scheduled run waits by itself. The queue delays the cap; it never raises it.

At zero, new work pauses. You cannot start a conversation or send another prompt until you add credit. Work already in flight finishes, even if the balance goes negative.

Self-host

Own as much of the stack as you want.

Keep the same API, SDK and CLI. Run Fountain and Postgres in your account, or keep hosted Fountain and connect machines from your network.

Run the control plane yourself. Fountain is open source. Docker Compose brings up Fountain and Postgres, while plain Kubernetes manifests run the same release image as hosted Fountain.

Bring your own sandbox compute. A runner dials out from your network, opens no inbound port, and uses no Fountain credit for agent time.

By default, a runner uses trusted mode. The agent runs as you, with your network and tools and no container between. Use it where you would hand a colleague a shell, or use the Firecracker backend on Linux with KVM for a microVM boundary.

See what self-hosting takes

Questions

You do not have to take our word for it.

Read every limit and review the security model yourself. The answers tell you what the software enforces and where it stops.

Get the answers

Give your product a coding agent.

Sign up, paste a model key, configure your agent, and start each run with one API call.

Run your first agent free

Already have an account? Sign in.