Related posts
David Crawshaw
x.com
This is @exedev. Come get a durable sandbox, with a URL, with auth, with sharing. Keep it private or make it public. Run any database you like. Run as many as you like. The world of small software awaits.
exedev auth sandbox
The the words it uses that this site has seen
least often elsewhere. Posts are matched on those words alone —
nothing here is a summary of this one.
Sources
All
Writing
Blog GitHub Recommends x.com Korrents
Top people
David Crawshaw
Guillermo Rauch
Simon Willison
Kaspars Dambis
Praveen Kumar Purushothaman
Gergely Orosz
Nelson Elhage
Sriram Krishnan
Jason Liu
Duncan McClean
Kun Chen
Zvi Mowshowitz
Showing
Profile →
Show everything
Hiding
Show them again
Show them again
Further back ↓
Hiding
Show them again
19 September
Co-creator of Django and creator of Datasette; writes daily at simonwillison.net.
17 September
London-based front-end architect, web developer evangelist and cloud consultant; Microsoft MVP. Writes at praveen.science and answers on Stack Overflow.
Writes The Pragmatic Engineer, the software-engineering newsletter, and wrote The Software Engineer's Guidebook. Formerly an engineering manager at Uber, and at Microsoft/Skype and Skyscanner before that.
Recommends sponsored rcmnd.app
WorkOS
Their words
@WorkOS – The fastest AI-native teams have to slow down for the hard problems. WorkOS makes sure auth, for your app and your agents, is never one of them. https://t.co/aiAee0oF5h
Show the whole quote
x.com
15 September
Software engineer who writes the blog Made of Bugs about performance, debugging and understanding computer systems. Previously worked at Anthropic on interpretability, at Stripe on Sorbet, and at Ksplice.
14 September
CEO of Vercel; creator of Next.js and Socket.IO. Writes at rauchg.com.
Welcoming Steren, creator of Google Cloud Run, to Vercel. He will lead the Fluid family of compute products (Functions, Containers, Sandbox, Builds). Serverless was the last chapter of the cloud, and Steren helped define the paradigm at Google. Agents are the next frontier, and they require new compute primitives designed for them. Excited for Steren to lead this transition once again. Quoting @steren Today is my first day at Vercel the cloud Google Related
12 September
Investor and writer. Previously a partner at Andreessen Horowitz and a product leader at Twitter, Facebook, Snap and Microsoft. Writes essays and memos at sriramk.com.
there's a lot of product magic in agents like muse or instinct in making auth into websites work. however, there still seems to be some ways to go given the various login systems you run into (passkeys, OTP via text or email, 2fa, "auth on other device"). Related
Machine learning engineer and consultant focused on RAG and retrieval systems. He writes about applied AI engineering at jxnl.co and is the author of the instructor library.
mf be like "it came to me in a dream" and its actually just 10 000 agent swarms writing markdown files on a sandbox and some python code Related
10 September
Latvian full-stack WordPress developer and course creator at WPElevator; blogs since 2007 about the open web, electronics, home automation and sustainable living.
Today I learned that @OpenAIDevs MCP client https://t.co/nhRPF6KVEf lists private_key_jwt for the token endpoint auth while the CIMD endpoint is actually public (auth=none). So your MCP OAuth must be able to skip private_key_jwt, if unsupported. MCP Related
7 September
Latvian full-stack WordPress developer and course creator at WPElevator; blogs since 2007 about the open web, electronics, home automation and sustainable living.
Pretty cool to see your WordPress site as a connector in the Claude mobile app. It is a streamable-http MCP server by Agent Pilot plugin combined with OAuth Pilot for seamless auth. Also works with the official MCP-adapter feature plugin. MCP Anthropic Related
5 September
Scottish software developer on the Statamic core team; runs a one-person business maintaining Statamic addons such as Runway and writes at duncanmcclean.com.
4 September
Co-creator of Django and creator of Datasette; writes daily at simonwillison.net.
OpenAI
Their words
It looks to me like OpenAI’s sandbox for this agent suffered from the (quite naïve) assumption that GET requests cannot be used to update data. That’s certainly how the web is supposed to work, but clearly there are applications that don’t hold to that contract.
Show the whole quote
simonwillison.net
2 September
Former L8 engineer at Meta, Microsoft and Atlassian, now writing and building solo on agentic engineering. Writes Kun's Field Notes and posts a lot about AI coding agents on X.
Software engineer; co-founder and former CTO of Tailscale, previously on the Go team at Google.
Finally got sick of all the Reddit UI changes, so started an @exedev VM and asked it to create an account and make a scraper for the content I check. Now I have an ultra lightweight, dense, mobile UI. Related
Writes Don't Worry About the Vase, a near-daily account of what is happening in AI and what they think it means. Former Magic: the Gathering pro and trader; unusually willing to put a number on a belief and to grade their own past calls.
28 August
CEO of Vercel; creator of Next.js and Socket.IO. Writes at rauchg.com.
Recommends their own rcmnd.app
eve
Their words
But how many that give you a Git repo where you actually *own* the entire intelligence stack? Runtime, model choice, skills, tools, connectivity, sandbox…
Show the whole quote
x.com
25 August
CEO of Vercel; creator of Next.js and Socket.IO. Writes at rauchg.com.
Recommends their own rcmnd.app
Run SDK
Their words
When agents write code, you don't always need a full sandbox. You can 𝚛𝚞𝚗 their code in a lightweight QuickJS secure context. Faster and more cost-efficient.
Show the whole quote
x.com
24 August
Software engineer; co-founder and former CTO of Tailscale, previously on the Go team at Google.
this old tweet is getting some likes (why? mysterious), so I re-read it, and still like it. it also applies really well to what I am working on now: I need lots of VMs for agents, but I don't need lots of CPU/RAM. hence @exedev Quoting @davidcrawshaw @danluu one of the big early ideas behind tailscale was a single computer is powerful enough to solve almost every problem, and that this is not widely understood. we need fewer distributed systems and more spreadsheet implementations. Related
Engineer at Vercel Labs as of 2026. Ships a steady stream of small developer tools — agent-browser, portless, json-render, native-sdk, the v0 SDK — and lists every one of them at ctate.dev.
Recommends their own rcmnd.app
emulate
Their words
New: emulate a GitHub App in a few lines of TypeScript Generated App keys, installation auth and stateful repository APIs Develop locally, test in CI or give sandboxed agents their own isolated GitHub environment
Show the whole quote
x.com
31 July
Indian software engineer and co-founder of Skcript; builds web apps and writes at varunraj.in.
28 July
Software engineer; co-founder and former CTO of Tailscale, previously on the Go team at Google.
Co-founder and CEO of OpenAI; previously president of Y Combinator.
AI alignment OpenAI
Their words
Um so I think it's an alignment failure. I think it's a security failure. I think it's like a very serious thing even though it's you know not not the biggest example of consequence.
Show the whole quote
youtube.com
23 July
Software engineer; co-founder and former CTO of Tailscale, previously on the Go team at Google.
Yeah this is @exedev. Quoting @ycombinator A Cloud for Small Software @koomen Agents make it easy to build personal tools for yourself or your team. But deploying, securing, and sharing that software is still far more complicated than creating it. A cloud built for small software could remove that complexity and make bespoke tools as easy t… Related
22 July
Security engineer; founder of Matasano Security and Latacora.
OpenAI
Their words
I genuinely believe that if you took an open weights model from 2025 and built a pentest harness for it, it could do this kind of sandbox escape and scan/hack in most networks. This is only surprising because you assume OpenAI has sounder sandboxes.
Show the whole quote
@tqbf on X x.com
17 July
Moroccan senior frontend developer writing at smakosh.com; builds side projects and client work under Smakosh LLC.
15 April
Software engineer and educator; creator of Testing Library and of the EpicWeb.dev and EpicReact.dev courses.
2 April
Co-founder of Ethereum. Publishes long essays on mechanism design, governance and what cryptography is for, and returns to earlier positions to say which parts they no longer hold.
Their words
Sandboxing To keep my LLMs in check, I do most of my LLM usage from inside of a sandbox. I use bubblewrap for this.
Show the whole quote
vitalik.eth.limo
26 March
Founding member of OpenAI and former director of AI at Tesla; creator of nanoGPT and the term "vibe coding".
When I built menugen ~1 year ago, I observed that the hardest part by far was not the code itself, it was the plethora of services you have to assemble like IKEA furniture to make it real, the DevOps: services, payments, auth, database, security, domain names, etc... I am really looking forward to a day where I could simply tell my agent: "build menugen" (referencing the post) and it would just work. The whole thing up to the deployed web page. The agent would have to browse a number of services, read the docs, get all the api keys, make everything work, debug it in dev, and deploy to prod. T… Quoting @patrickc When @karpathy built MenuGen (https://t.co/2OjrUJ3aLS), he said: "Vibe coding menugen was exhilarating and fun escapade as a local demo, but a bit of a painful slog as a deployed, real app. Building a modern app is a bit like assembling IKEA future. There are all these services, docs, API keys, con… Related
Nothing matches. Show everything
What is a korrent?
A korrent is a belief a person has stated in their own words: one
sentence stating the claim, backed by a quote and a source, kept at
korrents.com .
Under a name here, the quoted block is what they actually said.
The korrent beneath it is the claim those words support, in
korrents' wording — tap it to see the record, its source, and who
else holds it.
Nobody here wrote their own korrents. They are compiled from public
statements, and a person can change their mind, which is recorded too.
Got it
About the English under a post
Some people here publish in a language other than English. Where they
do, this site shows a machine translation beneath the post, in
this typeface — the site's own, not theirs.
The post itself is never changed, moved or hidden: what is set in the
serif above is exactly what the person published, and it is what to
quote them on. A translation can be wrong in ways that matter,
especially about tone.
Only the post's own words are translated. A quoted post, a linked
article and a belief on korrents.com
are left in their original language.
Got it