Container Use

Orchestrator · Last verified 2026-09-30

TL;DR

Container Use is an Apache-2.0 MCP server and CLI from Dagger that gives each coding agent its own container and git branch, so several agents (Claude Code, Codex, OpenCode, Cursor and other MCP clients) can work in parallel without touching your checkout. The README marks it experimental. It suits developers who review agent work before merging.

Key facts

Container Use key facts. Data as of 2026-09-30.
Type Orchestrator
Languages / SDKs Go
License Apache-2.0
Pricing model Open source, free
Orchestration pattern Other
GitHub stars 4,052 (as of 2026-09-30)
GitHub forks 208
Last push 2026-09-21
Latest release v0.4.2
Repository dagger/container-use
Website container-use.com
Documentation container-use.com
Last verified 2026-09-30

Key features

  • Runs as a stdio MCP server (container-use stdio), so any MCP-capable coding agent can create and use environments; the docs give setup for Claude Code, Codex, OpenCode, Cursor, Goose, Zed, Gemini CLI and others. (source)
  • Each environment pairs a dedicated git branch with a container and records every command and file change the agent made. (source)
  • CLI review commands: list, log, diff, checkout, terminal (a shell inside the container) and watch for live activity across environments. (source)
  • Finished work is accepted with merge (keeps the agent's commits) or apply (stages the changes for your own commit), or dropped with delete. (source)
  • A default environment config sets the base image, setup and install commands and environment variables; changes an agent makes can be imported with config import. (source)
  • Secrets are stored as references (1Password op://, environment variables, files) and resolved inside the container, so the model sees only the reference. (source)

Architecture and orchestration pattern

Pattern: Other

Container Use is a Go binary that the coding agent starts as a local MCP server. It uses Dagger to build and run containers and git worktrees for branching. When the agent calls its environment tools, Container Use creates an environment from the current branch: a container with the project's configured base image and dependencies, plus a dedicated branch that records the agent's file changes and command history.

It does not coordinate agents with each other. Parallelism comes from each agent session (in the same or different MCP clients) getting its own environment, and a new chat can resume an existing environment by naming its ID in the prompt. The user decides what happens to each environment.

State lives in git and in the container runtime: environment branches keep the work and history, and the project's default configuration is stored in the repository so new environments start from it. Configuration an agent changes stays inside its environment until imported.

Human in the loop

The agent's work stays out of your working tree until you act. You can inspect an environment without switching branches (log, diff), follow all environments live with watch, open a shell inside a running container with terminal to see its state or take over, or check it out locally. You then merge it, apply it as staged changes to commit yourself, keep iterating by prompting the agent in the same environment, or delete it. For Claude Code the quickstart also shows restricting the agent to Container Use tools with --allowedTools, so it cannot fall back to editing files directly.

Harnesses it can drive

Protocols

MCP, A2A and AG-UI support for Container Use. See the full matrix.
ProtocolSupportNote
MCP Yes evidence
checked 2026-09-30
Server: the README describes Container Use as an open-source MCP server; agents register container-use stdio as a stdio MCP server and call its environment tools.
A2A Unknown
checked 2026-09-30
No mention of A2A in the README or docs index (llms.txt) pages: introduction, quickstart, environment workflow, configuration, secrets, CLI reference, agent integrations.
AG-UI Unknown
checked 2026-09-30
No mention of AG-UI in the README or docs pages listed in llms.txt; not listed in the AG-UI README.

Best for

  • Letting several coding agents work on one repository at the same time without touching your local checkout. (shortlist)
  • Teams that use different MCP-capable agents (Claude Code, Codex, OpenCode, Cursor) and want one sandboxing layer for all of them. (shortlist)
  • Keeping credentials out of model context by passing secret references that resolve only inside the container.
  • Running agent work in local Docker containers rather than a hosted sandbox service. (shortlist)

Not for

  • Machines without Docker, which the quickstart requires.
  • Users who need a stable, regularly released tool: the README marks it experimental and the last tagged release is from August 2025.
  • Coordinating agents with each other; it isolates each agent but has no task routing or messaging.

Quickstart

brew install dagger/tap/container-use

Install not yet verified by this site. What this means

# Requires Docker and Git; the repository needs at least one commit
brew install dagger/tap/container-use
container-use version

cd /path/to/repository
claude mcp add container-use -- container-use stdio
curl https://raw.githubusercontent.com/dagger/container-use/main/rules/agent.md >> CLAUDE.md

# After prompting the agent, review its environments
container-use list
container-use log fancy-mallard
container-use diff fancy-mallard
container-use terminal fancy-mallard     # shell inside the container
container-use apply fancy-mallard        # stage the changes, then commit yourself
container-use delete fancy-mallard

# Codex instead: add to ~/.codex/config.toml
# [mcp_servers.container-use]
# command = "container-use"
# args = ["stdio"]

Common pitfalls

  • Docker and Git must be installed; the Homebrew tap is for macOS, and the install script covers other platforms.
  • An open issue reports that it does not work in a repository without an initial commit.
  • Agents only use environments when they call Container Use's tools; the docs recommend adding the agent rules file and, for Claude Code, optionally limiting tools with --allowedTools.
  • Default configuration changes apply only to new environments; changes an agent made need container-use config import <env>.
  • cu is an alias for container-use.
  • The latest tagged release is v0.4.2 (August 2025); later fixes on main, such as the August 2026 path-traversal fix, require building from source.

Official quickstart

Pros

  • Agents work in containers on their own branches, so your local files stay untouched until you merge or apply. (source)
  • One MCP command works across many agents, with setup notes for more than fifteen clients. (source)
  • Full command and file history per environment, plus a live shell into the container, make agent work auditable. (source)
  • Secret references keep API keys and passwords out of the model's context. (source)
  • Apache-2.0 licensed and backed by the Dagger organisation. (source)

Cons

  • The README carries an 'experimental' stability badge and says the project is in early development. (source)
  • No tagged release since v0.4.2 in August 2025, although maintenance commits reached main in August 2026. (source)
  • Requires a local Docker installation. (source)
  • A long-running open issue reports Claude Code failing to connect to the server. (source)
  • Repositories without an initial commit are not supported (open issue). (source)

Alternatives

FAQ

Does Container Use support MCP?

Yes. It is an MCP server: agents add container-use stdio as a stdio MCP server and call its environment tools.

Which coding agents can use it?

Any MCP-capable agent. The docs include setup for Claude Code, OpenAI Codex, OpenCode, Cursor, Windsurf, VS Code/Copilot, Zed, Goose, Amp, Cline, Kiro, Gemini CLI, JetBrains Junie and others.

Is Container Use free?

Yes. It is Apache-2.0 licensed and its docs describe no paid tier. It needs Docker to run containers.

How do I get an agent's work into my branch?

Use container-use merge <env> to keep the agent's commit history, or container-use apply <env> to stage the changes and write your own commit. delete discards the environment.

Is it stable?

The README labels it experimental and in early development, and the last tagged release is v0.4.2 from August 2025.

Sources

Unknown fields: protocols.a2a and protocols.agui: no mentions in the README or in the docs pages listed in llms.txt; not in the AG-UI README integration list. OpenClaw and Hermes are not among the documented agent integrations.

Something wrong or out of date, or do you maintain Container Use and want this page removed? Report a correction or request removal.