@wzrdtech/zap · v5.0.1 · node 24.x

Agents need a computer.

Zap composes a CPU runtime on an isolated Zap sandbox VM by default, renders agents as code, and plans side-effecting tools before live execution.

safe first run — no sandbox acquired, nothing spends
plan-safe
npx @wzrdtech/[email protected] doctor --json

Plan-only by default

Side-effecting tools are planned, never executed, until you pass --live with a payer. Read-only work may run; model tokens meter under the payer.

Isolated sandbox VMs

Each runtime composes onto its own Zap sandbox VM. CPU work is sandbox.exec inside the tenant boundary.

Write-only secrets

Agent secrets resolve only inside declared HTTPS connections and never appear in bundles, events, or --json output.

Featured template · fo-guang robotics profile

A humanoid robotics workbench in one template.

zap-heavy-fo-guang overlays zap-heavywith the Unitree G1 sim2sim stack: MuJoCo Playground MJX/PPO training, ONNX policy playback, the God's Eye View telemetry bridge, and ABot-Recon reconstruction from the G1 head camera. GPU boxes train; CPU-only boxes replay and reconstruct. Telemetry is inbound-only and no secret is ever baked.

fork the robotics workbench
plan-safe
zap harness bake zap-heavy-fo-guang    # plan-only
zap harness doctor zap-heavy-fo-guang

Featured launch film

OpenIntuition × Stripe Link · 00:38

Intuition > Instinct.

A concept film for a simple interaction: ask in iMessage, let an agent do the legwork, then approve an exact total before the checkout happens.

INTUITION_OVER_INSTINCT.MP438 SEC

Execution trace

Every step is an event you can inspect before it becomes live.

A session turn renders instructions, plans side effects with quotes and caps, and waits. Nothing acquires or spends until you approve it.

Example trace — illustrative, not a live session.

zap session --agent transcode --json
plan
Runtime.md resolved                         med · sandbox: box
Zap sandbox acquisition                     planned
sandbox.exec ffmpeg -i takes.mov …          planned
Provider cost                               quoted — $0.42, cap $1.50
Live execution                              waiting for explicit approval

Why CPU

Most agent work is CPU work: files, ffmpeg, builds, HTTP, git.

Zap treats the CPU sandbox as the default substrate. Instructions render for free on CPU; model thinking and GPU lanes are plugins that attach only when a runtime declares them. Compose from Runtime.md or zap.config.ts, deploy immutably by SHA, and keep durable sessions pinned to the deployment they started on.

--weight light

Kernel, CLI surface, and plan pipeline on a minimal CPU footprint.

fast start · smallest surface

--weight med

Adds the memory service, media filesystem, and gateway connections.

default for durable sessions

--weight heavy

Hosts harness templates and optional GPU/model lanes beside CPU work.

full workbench

Agents as code

A synchronous render function. Hooks attach everything else.

useModel, useTool, and MCP hooks declare capabilities on every turn — conditionally, from empty. The runtime executes after render, inside the sandbox, under plan/live gating. Connect any MCP-capable coding agent with one command:

MCP — stdio
copy & connect
npx -y @wzrdtech/[email protected] mcp

Payer or it fails closed

Missing payer fails with PAYER_MISSING before the first model step. There is no silent downgrade.

plan · live gated

Declared egress only

Outbound HTTP goes through declared HTTPS connections with method and path-prefix policies.

write-only secrets

Immutable deployments

zap deploy content-addresses each bundle; aliases move, sessions stay pinned to their deployment.

sha-addressed

Providers · one contract, server-side keys

Every provider Zap composes with.

23 providers across sandboxes, LLM routes, media generation, and payment rails — plan-only runs quote against rate tables and never contact a provider; keys stay server-side.

Explore providers
Zap Sandbox logo

Zap Sandbox

default

box

Zap's default sandbox: full VMs on ascii.dev.

  • Snapshots + fork
  • Stop / resume
  • Hosted ports
  • Desktop streaming
  • Docker inside
Modal logo

Modal

GPU lane

modal

The GPU lane target — mounts only when a gpu lane is declared.

  • On-demand GPU functions
  • Declared gpu lanes only
OpenRouter logo

OpenRouter

default

openrouter

Default LLM route across hundreds of models.

  • Multi-model routing
  • BYOK or managed
Anthropic logo

Anthropic

anthropic

Claude model family, including Claude Code auth.

  • Claude models
  • Claude Code device-auth login
fal logo

fal

fal

Fast image and video model inference.

  • Image generation
  • Video generation
  • Webhook result delivery
Replicate logo

Replicate

replicate

Open-model marketplace for media generation.

  • Image / video / audio models
  • Open-weights catalog
thirdweb logo

thirdweb

Wallet auth for Studio and managed payment sessions.

  • SIWE wallet sign-in
  • Scoped session keys
  • Spend caps
Coinbase x402 logo

Coinbase x402

x402 v2 payment protocol through the Zap Cloud payment gate.

  • PAYMENT-SIGNATURE settlement
  • Replay-protected receipts
  • MPP also accepted

Start with zero side effects.

Run the doctor, read the docs, connect your agent. Nothing acquires a sandbox or spends until you say so.

safe first run
plan-safe
npx @wzrdtech/[email protected] doctor --json
Read the v5 docs