# Container Use: features, protocols, quickstart

## TL;DR

Container Use is an Apache-2.0 MCP server and CLI from Dagger that gives each coding agent its own container and git branch, so several agents (Claude Code, Codex, OpenCode, Cursor and other MCP clients) can work in parallel without touching your checkout. The README marks it experimental. It suits developers who review agent work before merging.

## Key facts

| Field | Value |
| --- | --- |
| Type | Orchestrator |
| Languages / SDKs | Go |
| License | Apache-2.0 |
| Pricing model | Open source, free |
| Orchestration pattern | Other |
| GitHub stars | 4,052 (as of 2026-09-30) |
| GitHub forks | 208 |
| Last push | 2026-09-21 |
| Latest release | v0.4.2 |
| Repository | [dagger/container-use](https://github.com/dagger/container-use) |
| Website | [container-use.com](https://container-use.com) |
| Documentation | [container-use.com](https://container-use.com/introduction) |
| Last verified | 2026-09-30 |

## Key features

- Runs as a stdio MCP server (`container-use stdio`), so any MCP-capable coding agent can create and use environments; the docs give setup for Claude Code, Codex, OpenCode, Cursor, Goose, Zed, Gemini CLI and others. ([source](https://container-use.com/agent-integrations))
- Each environment pairs a dedicated git branch with a container and records every command and file change the agent made. ([source](https://container-use.com/environment-workflow))
- CLI review commands: `list`, `log`, `diff`, `checkout`, `terminal` (a shell inside the container) and `watch` for live activity across environments. ([source](https://container-use.com/cli-reference))
- Finished work is accepted with `merge` (keeps the agent's commits) or `apply` (stages the changes for your own commit), or dropped with `delete`. ([source](https://container-use.com/environment-workflow))
- A default environment config sets the base image, setup and install commands and environment variables; changes an agent makes can be imported with `config import`. ([source](https://container-use.com/environment-configuration))
- Secrets are stored as references (1Password `op://`, environment variables, files) and resolved inside the container, so the model sees only the reference. ([source](https://container-use.com/secrets))

## Architecture and orchestration pattern

Pattern: Other.

Container Use is a Go binary that the coding agent starts as a local MCP server. It uses Dagger to build and run containers and git worktrees for branching. When the agent calls its environment tools, Container Use creates an environment from the current branch: a container with the project's configured base image and dependencies, plus a dedicated branch that records the agent's file changes and command history.

It does not coordinate agents with each other. Parallelism comes from each agent session (in the same or different MCP clients) getting its own environment, and a new chat can resume an existing environment by naming its ID in the prompt. The user decides what happens to each environment.

State lives in git and in the container runtime: environment branches keep the work and history, and the project's default configuration is stored in the repository so new environments start from it. Configuration an agent changes stays inside its environment until imported.

### Human in the loop

The agent's work stays out of your working tree until you act. You can inspect an environment without switching branches (`log`, `diff`), follow all environments live with `watch`, open a shell inside a running container with `terminal` to see its state or take over, or check it out locally. You then `merge` it, `apply` it as staged changes to commit yourself, keep iterating by prompting the agent in the same environment, or `delete` it. For Claude Code the quickstart also shows restricting the agent to Container Use tools with `--allowedTools`, so it cannot fall back to editing files directly.

### Harnesses it can drive

- Claude Code ([evidence](https://github.com/dagger/container-use/blob/main/README.md))
- Codex ([evidence](https://container-use.com/agent-integrations))
- OpenCode ([evidence](https://container-use.com/agent-integrations))

## Protocols

| Protocol | Support | Evidence | Note |
| --- | --- | --- | --- |
| MCP | Yes (checked 2026-09-30) | [link](https://github.com/dagger/container-use/blob/main/README.md) | Server: the README describes Container Use as an open-source MCP server; agents register `container-use stdio` as a stdio MCP server and call its environment tools. |
| A2A | Unknown (checked 2026-09-30) | — | No mention of A2A in the README or docs index (llms.txt) pages: introduction, quickstart, environment workflow, configuration, secrets, CLI reference, agent integrations. |
| AG-UI | Unknown (checked 2026-09-30) | — | No mention of AG-UI in the README or docs pages listed in llms.txt; not listed in the AG-UI README. |

## Best for

- Letting several coding agents work on one repository at the same time without touching your local checkout. ([shortlist](https://multiagentguide.top/best/coding-agents.md))
- Teams that use different MCP-capable agents (Claude Code, Codex, OpenCode, Cursor) and want one sandboxing layer for all of them. ([shortlist](https://multiagentguide.top/best/coding-agents.md))
- Keeping credentials out of model context by passing secret references that resolve only inside the container.
- Running agent work in local Docker containers rather than a hosted sandbox service. ([shortlist](https://multiagentguide.top/best/self-hosted-local.md))

## Not for

- Machines without Docker, which the quickstart requires.
- Users who need a stable, regularly released tool: the README marks it experimental and the last tagged release is from August 2025.
- Coordinating agents with each other; it isolates each agent but has no task routing or messaging.

## Quickstart

```sh
brew install dagger/tap/container-use
```

Install not yet verified by this site.

```bash
# Requires Docker and Git; the repository needs at least one commit
brew install dagger/tap/container-use
container-use version

cd /path/to/repository
claude mcp add container-use -- container-use stdio
curl https://raw.githubusercontent.com/dagger/container-use/main/rules/agent.md >> CLAUDE.md

# After prompting the agent, review its environments
container-use list
container-use log fancy-mallard
container-use diff fancy-mallard
container-use terminal fancy-mallard     # shell inside the container
container-use apply fancy-mallard        # stage the changes, then commit yourself
container-use delete fancy-mallard

# Codex instead: add to ~/.codex/config.toml
# [mcp_servers.container-use]
# command = "container-use"
# args = ["stdio"]
```

### Common pitfalls

- Docker and Git must be installed; the Homebrew tap is for macOS, and the install script covers other platforms.
- An open issue reports that it does not work in a repository without an initial commit.
- Agents only use environments when they call Container Use's tools; the docs recommend adding the agent rules file and, for Claude Code, optionally limiting tools with `--allowedTools`.
- Default configuration changes apply only to new environments; changes an agent made need `container-use config import <env>`.
- `cu` is an alias for `container-use`.
- The latest tagged release is v0.4.2 (August 2025); later fixes on main, such as the August 2026 path-traversal fix, require building from source.

Official quickstart: https://container-use.com/quickstart

## Pros

- Agents work in containers on their own branches, so your local files stay untouched until you merge or apply. ([source](https://container-use.com/environment-workflow))
- One MCP command works across many agents, with setup notes for more than fifteen clients. ([source](https://container-use.com/agent-integrations))
- Full command and file history per environment, plus a live shell into the container, make agent work auditable. ([source](https://container-use.com/cli-reference))
- Secret references keep API keys and passwords out of the model's context. ([source](https://container-use.com/secrets))
- Apache-2.0 licensed and backed by the Dagger organisation. ([source](https://github.com/dagger/container-use))

## Cons

- The README carries an 'experimental' stability badge and says the project is in early development. ([source](https://github.com/dagger/container-use/blob/main/README.md))
- No tagged release since v0.4.2 in August 2025, although maintenance commits reached main in August 2026. ([source](https://github.com/dagger/container-use/releases))
- Requires a local Docker installation. ([source](https://container-use.com/quickstart))
- A long-running open issue reports Claude Code failing to connect to the server. ([source](https://github.com/dagger/container-use/issues/101))
- Repositories without an initial commit are not supported (open issue). ([source](https://github.com/dagger/container-use/issues/89))

## Alternatives

- [Claude Squad](https://multiagentguide.top/tools/claude-squad.md)
- [Vibe Kanban](https://multiagentguide.top/tools/vibe-kanban.md)
- [OpenHands](https://multiagentguide.top/tools/openhands.md)
- [HumanLayer](https://multiagentguide.top/tools/humanlayer.md)

## FAQ

### Does Container Use support MCP?

Yes. It is an MCP server: agents add `container-use stdio` as a stdio MCP server and call its environment tools.

### Which coding agents can use it?

Any MCP-capable agent. The docs include setup for Claude Code, OpenAI Codex, OpenCode, Cursor, Windsurf, VS Code/Copilot, Zed, Goose, Amp, Cline, Kiro, Gemini CLI, JetBrains Junie and others.

### Is Container Use free?

Yes. It is Apache-2.0 licensed and its docs describe no paid tier. It needs Docker to run containers.

### How do I get an agent's work into my branch?

Use `container-use merge <env>` to keep the agent's commit history, or `container-use apply <env>` to stage the changes and write your own commit. `delete` discards the environment.

### Is it stable?

The README labels it experimental and in early development, and the last tagged release is v0.4.2 from August 2025.

## Sources

- [container-use GitHub repository](https://github.com/dagger/container-use)
- [container-use README](https://github.com/dagger/container-use/blob/main/README.md)
- [Container Use homepage](https://container-use.com)
- [Introduction](https://container-use.com/introduction)
- [Quickstart](https://container-use.com/quickstart)
- [Agent integration](https://container-use.com/agent-integrations)
- [Environment workflow](https://container-use.com/environment-workflow)
- [Environment configuration](https://container-use.com/environment-configuration)
- [Secrets management](https://container-use.com/secrets)
- [CLI reference](https://container-use.com/cli-reference)
- [container-use releases](https://github.com/dagger/container-use/releases)
- [Issue #101: claude code fails to connect to container-use](https://github.com/dagger/container-use/issues/101)
- [Issue #89: Does not work without an initial commit](https://github.com/dagger/container-use/issues/89)

## Unknown fields

protocols.a2a and protocols.agui: no mentions in the README or in the docs pages listed in llms.txt; not in the AG-UI README integration list. OpenClaw and Hermes are not among the documented agent integrations.

Corrections or removal requests: support@multiagentguide.top

---

Data as of 2026-09-30. Not affiliated with listed projects. HTML version: https://multiagentguide.top/tools/container-use
