Executor is an MCP gateway. Your agent points at one endpoint and reaches every tool you connect.
Claude Code, Cursor, Codex, or anything else that speaks MCP. Any tool from any protocol. One place to add it, authenticate it, and decide what it is allowed to do.
Hosted Executor. Sign in and point your agent at one URL. Free for up to three members and 100,000 executions a month.
Everything stays on your machine. A desktop app for Mac, Windows, and Linux, or a CLI that runs as a background service. Both expose the same local MCP endpoint.
npm i -g executorRun it on your own infrastructure as a Docker image. Same code paths as Cloud.
Works with Claude Code, Cursor, Codex, ChatGPT, and any MCP client.
What we think
Every agent client re-implements every integration. The same API gets wired up again for each new tool, with its own auth and its own failure modes. Credentials end up pasted in five places, and nothing shares an idea of what a tool is allowed to do.
We think tools should belong to you, not to one client or one model provider. So Executor gives every tool one shape: a name, an input schema, an output schema. An MCP server, an OpenAPI spec, and a GraphQL API all end up the same, and any agent calls any of them the same way.
We also think the safe path has to be the easy path. Executor keeps the semantics it imported, so a GET and a DELETE are not the same thing, and it runs every call in a sandbox where a raw token never reaches the model.
Thousands of tools, one in the prompt
Executor shows the model a single tool. It searches your catalog and loads a tool's schema only when the code calls it, so connecting more services does not grow the prompt. Toggle the services below to see the difference.
Without Executor: 1,640 tools, about 278,800 tokens. With Executor: 1 tool, about 1,044 tokens.
"You are a helpful assistant.
Your tools are:
createIssue()
listPullRequests()
mergePullRequest()
createRelease()
addLabels()
createBranch()
getCommit()
// + 713 more GitHub tools
createCharge()
createCustomer()
createRefund()
listInvoices()
createSubscription()
capturePaymentIntent()
listPayouts()
// + 503 more Stripe tools
createIssue()
transitionIssue()
addComment()
assignIssue()
listSprints()
createProject()
searchIssues()
// + 233 more Jira tools
listIssues()
resolveIssue()
listEvents()
getProject()
muteIssue()
createRelease()
listAlerts()
// + 163 more Sentry tools
..."// the only tool your client sees: "execute"
Execute TypeScript in a sandboxed runtime with access to
configured API tools.
## Workflow
1. const { items } = await tools.search({ query });
2. const path = items[0]?.path;
3. const details = await tools.describe.tool({ path });
4. const result = await tools[path](input);
## Available connection prefixes
- github.org.main: Production GitHub
- stripe.org.main: Live Stripe account
- jira.org.main: Team Jira
- sentry.org.main: Production Sentry
Safe by default
- Policies come from the source.
- GET versus DELETE for OpenAPI, destructiveHint for MCP, mutations for GraphQL. Agents run the safe calls on their own and ask before the rest. You can override any tool.
- Secrets never reach the model.
- Calls run in an isolated JavaScript sandbox. Credentials are attached host-side at call time and never enter the sandbox, the agent, or the model's context.
- Set up once, whole team has it.
- Per-user credentials and shared ones. New teammates get the catalog on day one, with the same policies.
Run it where you want
All forms expose the same tools, packaged differently.
- 01 Cloud. Hosted, free to start, nothing to install. executor.sh/cloud ↗
- 02 Desktop. A desktop app for Mac, Windows, and Linux. Everything stays on your machine. Latest release ↗
- 03 CLI. A background service for headless and server environments.
npm i -g executor - 04 Self-hosted. A Docker image. Docs ↗
Pricing
Cloud is free for up to three members and 100,000 executions a month. Team is $15 per member per month with unlimited executions. Enterprise adds self-hosted support, SSO and SCIM, and audit logs.
Writing
About
We are a small team backed by Y Combinator. We built Executor because we wanted our own agents to reach our company's resources in a way that was not scary. Most setups make you choose between locked down and useless, or wide open and risky. We wanted a third option.