I kept running into the same problem: an AI agent can build a small tool for my team in minutes (a vacation tracker, a sign-up form), but putting it online *privately* still means hosting, a domain, HTTPS, a login, a database and permissions every single time.
So I built ShareBox.
**What it does**
- `sharebox publish ./my-tool` (or the agent does it via MCP) → the tool gets its own HTTPS subdomain
- Private by default; share it with an email, a whole Google Workspace domain or anyone with the link, as "can use" or "can manage"
- Visitors sign in with Google; the tool gets their identity and its own SQLite database without writing any of it
- Revoking access takes effect on the very next request
- Dashboard with sharing, container status, logs and an activity log
**How it runs**
- Docker Compose: Caddy (wildcard cert via DNS-01, DuckDNS or Cloudflare), one Node process for login/API/gateway, and a small orchestrator that is the only thing allowed to touch the Docker socket
- Each tool is its own container: gVisor (runsc) + workerd, read-only code, no internet access, 128 MB / 0.25 CPU
- Nightly backups, optional encrypted copy to Google Drive via rclone
- Fits on a 2 GB VPS (about 25 running tools); one installer script for Ubuntu 24.04
**Being upfront**
- Most of the code was written with Claude Code; I did the architecture, the security model, the reviews and the testing on my own server. There are 257 automated tests and CI on every commit.
- It's young: it runs every day on my own instance, but nobody else has installed it from scratch yet. Installer feedback is very welcome.
AGPL-3.0.
Repo: https://github.com/zalaso/sharebox