heyo gives you portable micro-VM sandboxes for AI agents. Spin up an isolated environment in milliseconds, run untrusted code or a full agent inside it, then fork, snapshot, or move it between machines. Run everything locally on your own hardware, or publish your sandboxes to the Heyo network.
The product is delivered as two binaries built from the mvm-ctrl crate:
heyvm— the user-facing CLI, TUI, and local HTTP API. It creates and runs sandboxes through a set of pluggable virtualization backends.heyvmd— a small always-on daemon that publishes your localheyvmAPI to the Heyo cloud over an iroh QUIC tunnel, so sandboxes on your machine are reachable from anywhere.
How the pieces fit together
heyvm CLI / TUI ──▶ local HTTP API ──▶ backend driver ──▶ micro-VM / sandbox
│ ▲
│ │ (publishes over iroh)
└── heyvmd ─────────┘ ──▶ Heyo cloud ◀── other machines
heyvmtalks to a backend driver (Firecracker, libvirt/KVM, Docker, Apple Virtualization, bubblewrap, WASM, and more) to actually boot and manage sandboxes.- The same operations are exposed over a local HTTP API so editors, scripts, and the desktop app can drive sandboxes programmatically.
heyvmdkeeps that API registered with the cloud control plane, which adds multi-machine networking and deployed sandboxes.
Heyo Web Services
Heyo Web Services (HWS) is the open-source stack that
builds a cloud on top of heyvm: a load balancer and autoscaler for microVM
deployments, secrets, observability, an artifact store, CI, Postgres, a queue
and an MCP server, all running on hosts you control. Start with the
HWS overview or go straight to
installation.
Where to go next
- Quickstart — install
heyvmand launch your first sandbox. - Virtualization Backends — pick the right isolation backend for your platform.
- CLI Commands — the full
heyvmcommand surface. - API Endpoints — drive sandboxes over HTTP.
- The Daemon — connect your machine to the cloud.
- Heyo Web Services — run your own cloud on your own metal.