The agent knows where it is
Every box has a second built-in MCP server next to desktop: sessionboxer. The agent's briefing opens with the session's name and environment, .sessionboxer/session.json in the workspace has the id, agent, model, branch and parent, and whoami and docs answer "where are you?" and "how do I turn on Docker in the box?" from the guide shipped in the box rather than from memory. With the same server the agent acts on its session the way you would from the UI, and, if you allow it, on other sessions: create one with a first prompt, fork itself with a handoff it writes, message another session's agent, wait for its turn, schedule prompts. Every action leaves a marker in the chat.
Things you can do with it
Ask the session about itself
"Which model are you on, how full is the context, what is in the queue?" — answered from whoami, exact, no guessing.
Let it attach the PR it opened
After gh pr create the agent calls pr_attach; the PRs pane starts following comments and checks without you pasting the URL.
Split work across sessions
"Create a session for the backend tests and message me the result." A card asks Allow / Deny; the child appears in the sidebar as child of this one and its reply lands in this chat marked from Session X.
Have it show you something
ui_open switches your page to Terminal, Code, PRs or Verification, or opens a Terminal running a command visibly, only while you are looking at that session and not typing.
How it works
The box has no route to Sessionboxer's API and no token: the MCP talks to the box's own daemon, which forwards over the connection the Control Plane already holds to it, so a box can only ever speak for its own session. Policy is Off, This Session only or All Sessions (the default since 1.4.1), per session or globally; creating a session shows an Allow / Deny card by default, expiring in 10 minutes. Limits hold a runaway or prompt-injected agent: 3 alive children per agent, a global cap on agent-created sessions, 4 hops in a chain of agents prompting agents, one message in flight per target. Windows and macOS guests get the server through the same bridge as desktop. Every tool of both servers, with parameters, limits and returns, is in the MCP tools reference.
Compared with other products
| Sessionboxer | Devin | Cursor Cloud Agents | Codex cloud | Claude Code on the web | OpenHands | T3 Code | |
|---|---|---|---|---|---|---|---|
| MCP servers | ✓, switched per session | ✓ | ✓ | — | — | ✓ | via the agent |
| Hand a session over to a different agent | ✓ | ✗ | ✗ | ✗ | ✗ | — | — |
| Runs on your machine or your server | ✓ | ✗ | ✗ | ✗ | ✗ | ✓ | ✓ |
Devin has an MCP server and an API for creating and messaging sessions from outside; whether a session can call them on itself is not described. The other hosted products document MCP for their agents but no self-knowledge or session-to-session tools. Sessionboxer gives the agent both, scoped to the session it runs in unless you widen it.
Based on each product's public documentation, September 2026; ✓ = offered, ✗ = not offered, — = not found in the docs. Corrections welcome as an issue.