Proposal is open for comment until 9 October
We particularly want to hear from teams already running agents against internal APIs, and from Security on the credential model.
An isolated environment where agents can run code and call internal tools without holding standing credentials to production systems.
Next: in development on 16 November 2026, in 6 weeks. Each audience arrives on its own schedule, below.
Next up: Platform engineers building agents.
Platform engineers building agents
Phase 1 — agent builders
Teams already running agents against internal APIs
Phase 2 — existing internal-API agents
Any team, without asking us first
Phase 3 — self-serve
A sandbox with no standing access: an agent requests a short-lived, scoped credential per task, and everything it runs is recorded.
Proposed only. Scope and timing may change entirely, and it may not be built at all — the dates below are an estimate, not a commitment.
We particularly want to hear from teams already running agents against internal APIs, and from Security on the credential model.